跳至主要內容
WordPress.org

Taiwan 正體中文

  • 佈景主題目錄
  • 外掛目錄
  • 最新消息
  • 技術支援
  • 關於我們
  • 團隊
  • 取得 WordPress
取得 WordPress
WordPress.org

Plugin Directory

Riverbox Passwordless Login

  • 提交外掛
  • 我的最愛
  • 登入
  • 提交外掛
  • 我的最愛
  • 登入

Riverbox Passwordless Login

由 riverbox 開發
下載
  • 詳細資料
  • 使用者評論
  • 安裝方式
  • 開發資訊
技術支援

外掛說明

Riverbox replaces passwords with modern, frictionless login. Users sign in with a one-time code, a magic link, a passkey, or their phone number — and new visitors can get an account automatically.

Login methods

  • Email one-time codes — type your address, get a short code, you’re in.
  • Magic links — one-click login links by email; single-use and expiring.
  • Passkeys (WebAuthn) — sign in with a fingerprint, face, or security key. Includes an account page ([riverbox-account]) where users manage their devices. No external services; the WebAuthn ceremony is verified on your own server.
  • Phone one-time codes — SMS login through your own HTTP SMS gateway ({{to}}/{{message}} placeholder templates).
  • Password — classic login can stay available alongside the passwordless methods.

Security

  • Codes stored only as hashes, with expiry, attempt caps, and resend cooldowns.
  • Per-IP and per-identifier rate limiting; responses never reveal whether an account exists.
  • Magic links are single-use and blocked for accounts that require multi-factor login.
  • A delivery log records every code dispatch with the raw gateway response.

Developer friendly

  • REST API under riverbox/v1 (/begin, /verify, passkey endpoints) built on an extensible authentication-factor architecture — every method is a “factor”, and login flows are factor chains.
  • Documented hooks: riverbox_register_factors, riverbox_login_chain, riverbox_otp_sent, riverbox_logged_in, riverbox_login_redirect, riverbox_user_created, plus settings extension points.

Riverbox Pro (sold separately at dontworry2much.com) adds Twilio and WhatsApp Cloud API gateways, social login (Google, Microsoft, Facebook, GitHub, LinkedIn, Discord), and role-based 2FA/3FA login flows.

Privacy

The free plugin does not connect to any external service. Emails go through your site’s own mail system, SMS goes through the gateway you configure, and all data stays in your WordPress database.

螢幕擷圖

The login form with every method enabled: one-time codes (email or phone), magic links, password, passkeys, and social login (Pro).
The login form with every method enabled: one-time codes (email or phone), magic links, password, passkeys, and social login (Pro).
The one-time code verification step after a code has been sent.
The one-time code verification step after a code has been sent.

安裝方式

  1. Install and activate the plugin.
  2. Add [riverbox-login] to any page; optionally add [riverbox-account] to a members page for passkey management.
  3. Configure methods, codes, signup behavior, and gateways under Settings → Riverbox.

常見問題集

Does this replace my normal WordPress login?

No. Riverbox adds passwordless login wherever you place the shortcode. The standard wp-login.php form keeps working, so you can never lock yourself out.

Can new visitors register through the form?

Yes — enable automatic account creation in settings and choose the role new users receive. Signup works with email and phone codes.

Do passkeys need a third-party service?

No. Registration and verification happen entirely on your server using the WebAuthn standard. Passkeys require HTTPS in production (browsers allow localhost for testing).

How does phone login send SMS?

The free plugin includes a generic HTTP gateway you can point at any SMS provider’s API. Riverbox Pro adds ready-made Twilio and WhatsApp Cloud API integrations.

The code email doesn’t arrive — what do I check?

Email delivery depends on your site’s mail configuration. Check the Riverbox delivery log and consider an SMTP plugin if your host’s default mail is unreliable.

使用者評論

這個外掛目前沒有任何使用者評論。

參與者及開發者

以下人員參與了開源軟體〈Riverbox Passwordless Login〉的開發相關工作。

參與者
  • riverbox

將〈Riverbox Passwordless Login〉外掛本地化為台灣繁體中文版

對開發相關資訊感興趣?

任何人均可瀏覽程式碼、查看 SVN 存放庫,或透過 RSS 訂閱開發記錄。

變更記錄

1.1.1

  • Security: rate limiting is now atomic (single-statement counter on a dedicated table), so concurrent requests can no longer race past the limit.
  • Security: a code’s expiry is fixed at issue time — failed verification attempts can no longer extend its lifetime.

1.1.0

  • New: magic link login (single-use, expiring, blocked for MFA accounts).
  • New: passkey (WebAuthn) login and registration with an account security page.
  • New: phone one-time-code login via a configurable HTTP SMS gateway.
  • New: password as an optional method alongside passwordless login.
  • New: multi-step login chains (foundation for role-based 2FA/3FA in Pro).
  • New: extension hooks for gateways, factors, and settings.

1.0.0

  • Initial release: email one-time-code login and signup, [riverbox-login] shortcode, REST API, delivery log, rate limiting.

中繼資料

  • 版本 1.1.1
  • 最後更新 1 個月前
  • 啟用安裝數 少於 10 次
  • WordPress 版本需求 6.4 或更新版本
  • 已測試相容的 WordPress 版本 7.0.4
  • PHP 版本需求 8.1 或更新版本
  • 語言
    English (US)
  • 標籤:
    authenticationloginotppasskeyspasswordless
  • 進階檢視

評分

這個項目尚無任何評論記錄。

撰寫評分

查看全部使用者評論

參與者

  • riverbox

技術支援

使用者可在技術支援論壇提出意見反應或使用問題。

檢視技術支援論壇

  • 關於我們
  • 最新消息
  • 主機代管
  • 隱私權
  • 展示網站
  • 佈景主題目錄
  • 外掛目錄
  • 區塊版面配置目錄
  • Learn
  • 技術支援
  • 開發者資源
  • WordPress.tv ↗
  • 共同參與
  • 活動
  • 贊助基金會 ↗
  • Swag ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org

Taiwan 正體中文

  • 查看我們的 X (之前的 Twitter) 帳號
  • 造訪我們的 Bluesky 帳號
  • 造訪我們的 Mastodon 帳號
  • 造訪我們的 Threads 帳號
  • 造訪我們的 Facebook 粉絲專頁
  • Visit our Instagram account
  • Visit our LinkedIn account
  • 造訪我們的 TikTok 帳號
  • Visit our YouTube channel
  • 造訪我們的 Tumblr 帳號
程式碼,如詩
The WordPress® trademark is the intellectual property of the WordPress Foundation.