| 开发者 | dasecure |
|---|---|
| 更新时间 | 2026年8月31日 22:18 |
| 捐献地址: | 去捐款 |
| PHP版本: | 7.4 及以上 |
| WordPress版本: | 7.0 |
| 版权: | GPL-2.0-or-later |
| 版权网址: | 版权信息 |
Only a verified email address and a stable account identifier, delivered in a cryptographically signed token that the plugin verifies against the provider's published keys. No passwords, no passkeys, no profile data.
No. Linking to an existing WordPress user happens only when the ZapQR identity provider asserts the email is verified; unverified emails are rejected outright. You can also disable linking entirely, and new users always get the low-privilege role you configure.
With the visitor and the ZapQR identity provider — never on your WordPress site. Your site only consumes the signed sign-in assertion.
Yes, unchanged. It is a separate, coexisting mode: the ZapQR app stores per-site WordPress credentials locally on the phone (Face ID / Touch ID protected) and relays them to the browser at login.
Yes.
window.ZapQR.refresh() lets themes/plugins request a fresh QR programmatically.