MaxtDesign MFA
MaxtDesign MFA: zero-footprint multi-factor authentication and login-location protection for WordPress and WooCommerce (TOTP, passkeys, recovery codes).
by MaxtDesign · github.com/maxtdesign/maxtdesign-mfa · website
Install
No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:
wp plugin install https://github.com/maxtdesign/maxtdesign-mfa/archive/refs/heads/chore%2Fp1-ci-check.zipMulti-factor authentication and a moved login address for WordPress and WooCommerce: TOTP, passkeys (second factor and passwordless), recovery codes, an optional email code, and per-role Off / Optional / Required policy for staff and customers. Free, on WordPress.org, with no outbound HTTP and no front-end weight on normal pages.
Status: development (0.1.0 scaffold). It does not change login behaviour yet.
- WordPress.org readme: readme.txt
- Security policy and private reporting: SECURITY.md (security@maxtdesign.com)
- Build plan: docs/plan-maxtdesign-mfa.md
- Current state: docs/STATE.md
Development
Requires PHP 8.3+ and Composer. The plugin itself has no Composer runtime dependencies; vendor/
holds dev tools only and never ships.
composer install
composer lint # WordPress Coding Standards
composer analyse # PHPStan level 8
composer test # PHPUnit
composer size-check # byte budgets for shipped CSS/JS
CI runs all of these on PHP 8.3, 8.4 and 8.5, plus an activation and uninstall smoke test against
WordPress and MySQL (tests/smoke/run.sh).
License: GPL-2.0-or-later.