Store launch: promo code LAUNCH20 — 20% off everything until the end of September

OTP Shield Pro

A second key to the admin panel — TOTP, QR generated locally, zero clouds.

WordPress 6.5+PHP 7.4+License: 1 site, 1 year
Download free free forever, no feature timers
$49
Version 1.1.0
Buy Pro

Instant delivery: license key + download right after payment.

Version 1.1.0 · updates delivered automatically

About

After brute-force waves, 2FA is the first thing an admin should switch on. OTP Shield adds a TOTP second step to login: the QR code is generated on your own server, the secret never leaves the database, and there's no account on anyone's cloud.

Pro adds policy: an enforcement deadline after which logins without 2FA are blocked for chosen roles, Telegram alerts for logins from new devices, an IP allowlist for the office, and a 30-day coverage report with CSV export.

What it does

  • TOTP two-factor with locally generated QR (RFC 6238)
  • Enforcement per role — free
  • Pro: enforcement deadline with a countdown banner
  • Pro: Telegram alert on logins from a new device
  • Pro: IP allowlist (CIDR) skips the second step
  • Pro: 30-day coverage report + CSV export
  • One license = one site, 12 months of updates

Free vs Pro

FreePro
TOTP & QRYesYes
Enforcement by roleYesYes + deadline
New-device Telegram alerts—Included
IP allowlist & coverage report—Included

FAQ

What if I lose my phone?

An administrator can disable 2FA for your user in the profile screen; office IPs on the allowlist don't need the code at all.

Does it work with the WordPress mobile app?

The app uses application passwords, which bypass the login form — they are unaffected.

Is the secret stored encrypted?

The secret lives in your user meta in your database. Nothing is sent to us — there is no external service.

You may also need

Installation & uninstall

Free version

  1. Download the zip archive with the "Download free" button above.
  2. In your WordPress admin: Plugins → Add New → Upload Plugin.
  3. Pick the downloaded zip, click "Install Now", then "Activate".
  4. The plugin's menu appears in wp-admin — configure it to your liking.

Pro version

  1. After payment, download the Pro archive from your order page (the link is also emailed).
  2. Install Pro like any plugin: Plugins → Add New → Upload Plugin → Activate.
  3. The free version must be installed and active — Pro sits on top as a companion.
  4. Enter the license key on the plugin's Pro settings page.

Uninstall

  1. Plugins → find the plugin in the list → click "Deactivate".
  2. Then click "Delete" — the plugin and all its data (tables, settings, logs) are removed completely.
  3. The Pro companion uninstalls the same way, independently; the free version keeps working.

Every plugin we ship passes a clean-uninstall test: after "Delete" no tables or leftover settings remain in the database.

Reviews

No reviews yet — be the first.

Write a review

Reviews are published after moderation.