OTP Shield Pro
A second key to the admin panel — TOTP, QR generated locally, zero clouds.
Instant delivery: license key + download right after payment.
Version 1.1.0 · updates delivered automatically
About
After brute-force waves, 2FA is the first thing an admin should switch on. OTP Shield adds a TOTP second step to login: the QR code is generated on your own server, the secret never leaves the database, and there's no account on anyone's cloud.
Pro adds policy: an enforcement deadline after which logins without 2FA are blocked for chosen roles, Telegram alerts for logins from new devices, an IP allowlist for the office, and a 30-day coverage report with CSV export.
What it does
- TOTP two-factor with locally generated QR (RFC 6238)
- Enforcement per role — free
- Pro: enforcement deadline with a countdown banner
- Pro: Telegram alert on logins from a new device
- Pro: IP allowlist (CIDR) skips the second step
- Pro: 30-day coverage report + CSV export
- One license = one site, 12 months of updates
Free vs Pro
| Free | Pro | |
|---|---|---|
| TOTP & QR | Yes | Yes |
| Enforcement by role | Yes | Yes + deadline |
| New-device Telegram alerts | — | Included |
| IP allowlist & coverage report | — | Included |
FAQ
What if I lose my phone?
An administrator can disable 2FA for your user in the profile screen; office IPs on the allowlist don't need the code at all.
Does it work with the WordPress mobile app?
The app uses application passwords, which bypass the login form — they are unaffected.
Is the secret stored encrypted?
The secret lives in your user meta in your database. Nothing is sent to us — there is no external service.
You may also need
Margin Lens Pro
Cost of goods on each product, a frozen cost snapshot in every order, profit reports and margin alerts for Woo
Return Manager Pro
Customer-facing return requests, a manager queue with statuses, reason statistics, and in Pro: exchanges, cred
Ship Tracker Pro
Tracking numbers on WooCommerce orders, a customer-facing status page, shipped notifications, and in Pro: a RU
Installation & uninstall
Free version
- Download the zip archive with the "Download free" button above.
- In your WordPress admin: Plugins → Add New → Upload Plugin.
- Pick the downloaded zip, click "Install Now", then "Activate".
- The plugin's menu appears in wp-admin — configure it to your liking.
Pro version
- After payment, download the Pro archive from your order page (the link is also emailed).
- Install Pro like any plugin: Plugins → Add New → Upload Plugin → Activate.
- The free version must be installed and active — Pro sits on top as a companion.
- Enter the license key on the plugin's Pro settings page.
Uninstall
- Plugins → find the plugin in the list → click "Deactivate".
- Then click "Delete" — the plugin and all its data (tables, settings, logs) are removed completely.
- The Pro companion uninstalls the same way, independently; the free version keeps working.
Every plugin we ship passes a clean-uninstall test: after "Delete" no tables or leftover settings remain in the database.
Reviews
No reviews yet — be the first.