WP Biometric Auth
WP Biometric Auth plugin to register biometric credentials (WebAuthn) and login using navigator.credentials.
Install
No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:
wp plugin install https://github.com/sknetking/wp-biometric-auth/archive/refs/heads/main.zipA production-ready WordPress plugin that enables secure biometric authentication using the WebAuthn API (navigator.credentials.create() and navigator.credentials.get()).
It allows users to register and authenticate via platform authenticators (e.g., Touch ID, Windows Hello, Face ID, Android Biometrics, or Security Keys).
🔐 Features
- Full WebAuthn-based biometric login flow — no username required.
- User credentials securely stored in user meta.
- Compatible with all major browsers supporting WebAuthn.
- Secure challenge-based authentication and credential matching.
- Works with both platform and roaming authenticators (USB, NFC, Bluetooth).
- Designed with extensibility for enterprise SSO or multi-factor integration.
🚀 How to Install
- Upload the ZIP file via the WordPress Admin → Plugins → Add New → Upload Plugin.
(Or unzip manually into
wp-content/plugins/wp-biometric-auth/.) - Activate the plugin.
- Log in as any registered user.
- Go to your Profile Page → Click “Add Biometric” to register a biometric credential using your browser’s native prompt.
- Log out.
- On the WordPress Login page, click “Login with Biometric” — authenticate using your device’s biometric method.
⚙️ Technical Overview
-
Uses the WebAuthn API for registration and authentication:
- Registration:
navigator.credentials.create() - Authentication:
navigator.credentials.get()
- Registration:
-
Credentials are stored in the user’s metadata (
wpba_credentials). -
Server-side code manages challenges, verifies credentials, and logs users in securely.
-
No manual username input is required during authentication.
🧠 Architecture
| Component | Purpose |
|---|---|
wp-biometric-auth.php |
Main plugin logic, hooks, AJAX handlers |
assets/wpba.js |
Registration & biometric enrollment logic |
assets/wpba-login.js |
Login page biometric authentication |
assets/wpba.css |
Styling for buttons and UI elements |
✅ Requirements
- WordPress 6.0+
- PHP 7.4+
- HTTPS (required by WebAuthn)
- Browser with WebAuthn support (Chrome, Edge, Firefox, Safari)
🧩 Developer Notes
- This version removes username dependency — authentication is done purely by matching stored credentials.
- Each credential is mapped to the correct user based on the credential ID.
- Supports multiple credentials per user.
- Designed to integrate seamlessly with the WordPress login system via
wp_signon().
⚠️ Security Notes
- Built for production — all inputs sanitized, challenges validated, and transient-based anti-replay protection implemented.
- Use only on HTTPS-enabled domains.
- Always keep WordPress core and this plugin updated.
📘 License
Released under the GPL v2 or later license. You are free to modify, extend, or redistribute it under the same license.