Title: Gupti 2FA
Author: plexomedia
Published: <strong>2026 年 8 月 22 日</strong>
Last modified: 2026 年 8 月 22 日

---

搜尋外掛

![](https://s.w.org/plugins/geopattern-icon/gupti-2fa.svg)

# Gupti 2FA

 由 [plexomedia](https://profiles.wordpress.org/plexomedia/) 開發

[下載](https://downloads.wordpress.org/plugin/gupti-2fa.1.0.0.zip)

 * [詳細資料](https://tw.wordpress.org/plugins/gupti-2fa/#description)
 * [使用者評論](https://tw.wordpress.org/plugins/gupti-2fa/#reviews)
 *  [安裝方式](https://tw.wordpress.org/plugins/gupti-2fa/#installation)
 * [開發資訊](https://tw.wordpress.org/plugins/gupti-2fa/#developers)

 [技術支援](https://wordpress.org/support/plugin/gupti-2fa/)

## 外掛說明

Gupti 2FA adds an extra layer of security to your WordPress site by requiring a 
time-based one-time password (TOTP) from Google Authenticator (or any compatible
app) at login. Everything runs locally on your server — no third-party APIs, no 
account signup, no data leaves your site.

**For users:**

 * Easy setup via QR code — scan and go, or enter the secret key manually.
 * Works with Google Authenticator, Authy, Microsoft Authenticator, 1Password, and
   any TOTP app.
 * 8 one-time recovery codes in case you lose your device.
 * Verification code required when enabling, so you can never lock yourself out 
   by mistake.
 * Clean, distraction-free verification page at login.

**For admins:**

 * Modern dashboard with 2FA coverage stats across your site.
 * Role-based enforcement — require 2FA for administrators, editors, or any role.
 * Optional grace period so enforced users get time to set up.
 * Choose where users complete setup: right after login, or inside the dashboard.
 * 2FA Status Report — see who has 2FA enabled and reset a user’s 2FA in one click.
 * Login page branding — add your own logo to the verification pages.

**Security hardening built in:**

 * TOTP secrets are encrypted at rest (AES-256-GCM keyed from your site’s salts).
 * Rate limiting on all verification steps — codes can’t be brute-forced.
 * Replay protection — a used code is never accepted twice.
 * Recovery codes are stored hashed and each works only once.
 * QR codes are generated locally in pure PHP — nothing is sent to external services.
 * No external fonts, scripts, or API calls anywhere.

### Development

The admin dashboard is built with React and Vite. The uncompiled, human-readable
source is included in the plugin’s `app/` directory. To rebuild the compiled files
in `assets/dist/`, run `npm install` followed by `npm run build` inside the `app/`
directory.

## 安裝方式

 1. Upload the `gupti-2fa` folder to `/wp-content/plugins/`, or install via **Plugins
    Add New**.
 2. Activate the plugin through the **Plugins** menu in WordPress.
 3. To enable 2FA for yourself: go to your **Profile** page, scan the QR code with 
    your authenticator app, and enter the 6-digit code to verify.
 4. To enforce 2FA for user roles: go to **Gupti 2FA  Configuration**, select the roles,
    and save.

## 常見問題集

### What if I lose my phone?

Use one of your 8 recovery codes on the login screen to complete verification, then
reconfigure 2FA from your profile. If you have lost the recovery codes too, a site
administrator can reset your 2FA from the 2FA Status Report.

### Can I require 2FA only for administrators?

Yes. Go to Gupti 2FA  Configuration and select only the roles you want to enforce—
for example, just Administrators. Other users can still enable 2FA voluntarily from
their profile page.

### Will this plugin slow down my site?

No. The plugin makes no external API calls and loads its scripts and styles only
on the login page and its own admin pages. Your site’s front end is completely unaffected.

### Does this work with custom login pages?

It hooks into WordPress core authentication, so it works with any theme or plugin
that uses the standard `wp_authenticate` / `wp_login_url` flow.

### Does it send my data anywhere?

No. Secrets are generated, stored (encrypted), and verified entirely on your own
server. QR codes are rendered locally in PHP. The plugin makes no external requests.

### Will REST API or XML-RPC logins bypass 2FA?

No. Password-based programmatic logins are blocked for 2FA-enabled accounts. Use
WordPress application passwords for API access — they are unaffected.

### Where can I get support?

Use the plugin support forum on WordPress.org, or email us at hello@plexomedia.com.

## 使用者評論

這個外掛目前沒有任何使用者評論。

## 參與者及開發者

以下人員參與了開源軟體〈Gupti 2FA〉的開發相關工作。

參與者

 *   [ plexomedia ](https://profiles.wordpress.org/plexomedia/)

[將〈Gupti 2FA〉外掛本地化為台灣繁體中文版](https://translate.wordpress.org/projects/wp-plugins/gupti-2fa)

### 對開發相關資訊感興趣？

任何人均可[瀏覽程式碼](https://plugins.trac.wordpress.org/browser/gupti-2fa/)、查看
[SVN 存放庫](https://plugins.svn.wordpress.org/gupti-2fa/)，或透過 [RSS](https://plugins.trac.wordpress.org/log/gupti-2fa/?limit=100&mode=stop_on_copy&format=rss)
訂閱[開發記錄](https://plugins.trac.wordpress.org/log/gupti-2fa/)。

## 變更記錄

#### 1.0.0

 * Initial release.

## 中繼資料

 *  版本 **1.0.0**
 *  最後更新 **2 個月前**
 *  啟用安裝數 **少於 10 次**
 *  WordPress 版本需求 ** 6.0 或更新版本 **
 *  已測試相容的 WordPress 版本 **7.0.7**
 *  PHP 版本需求 ** 7.4 或更新版本 **
 *  語言
 * [English (US)](https://wordpress.org/plugins/gupti-2fa/)
 * 標籤:
 * [2FA](https://tw.wordpress.org/plugins/tags/2fa/)[google authenticator](https://tw.wordpress.org/plugins/tags/google-authenticator/)
   [login security](https://tw.wordpress.org/plugins/tags/login-security/)[totp](https://tw.wordpress.org/plugins/tags/totp/)
   [two factor](https://tw.wordpress.org/plugins/tags/two-factor/)
 *  [進階檢視](https://tw.wordpress.org/plugins/gupti-2fa/advanced/)

## 評分

這個項目尚無任何評論記錄。

[撰寫評分](https://wordpress.org/support/plugin/gupti-2fa/reviews/#new-post)

[查看全部使用者評論](https://wordpress.org/support/plugin/gupti-2fa/reviews/)

## 參與者

 *   [ plexomedia ](https://profiles.wordpress.org/plexomedia/)

## 技術支援

使用者可在技術支援論壇提出意見反應或使用問題。

 [檢視技術支援論壇](https://wordpress.org/support/plugin/gupti-2fa/)