=== OTP Shield ===
Contributors: yodsira
Tags: security, two factor, totp, 2fa, login
Requires at least: 6.5
Tested up to: 7.1
Requires PHP: 8.0
Stable tag: 1.1.0
License: GPL-2.0-or-later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Two-factor authentication for WordPress: TOTP codes from any authenticator app, brute-force lockout, per-role enforcement. Pure local.

== Description ==

After the password, a second key. OTP Shield adds TOTP two-factor
authentication - the same 6-digit codes Google Authenticator, Aegis,
1Password and every other app generate - without clouds or external
services.

= What it does =

* Enable TOTP in your profile: a secret, an otpauth:// URI for your
  authenticator app, and a 6-digit code check at every login.
* Wrong-code lockout: 5 invalid attempts block verification for 15
  minutes.
* Role enforcement: admins can require 2FA for chosen roles.
* 100% local: codes are generated and verified on your site. Nothing
  is sent anywhere.

= OTP Shield Pro =

The Pro companion adds e-mail fallback codes, device memory ("trust
this browser for 30 days"), a deadline for role enforcement and a
coverage report. Learn more: https://yodsira.com/en/product/otp-shield/

== Installation ==

1. Install the plugin through the WordPress plugins screen (Plugins ->
   Add New -> Upload Plugin) and activate it.
2. Open your profile, tick "Enable TOTP two-factor auth" and save.
3. Add the shown secret to your authenticator app.

== Frequently Asked Questions ==

= Which apps work with it? =

Any TOTP app: Google Authenticator, Aegis, Authy, 1Password, KeePassXC
and all RFC 6238 implementations.

= I lost my phone. How do I get in? =

Another admin can disable 2FA for your account from their profile
screen, or remove the plugin folder via FTP - the login then works
with the password alone.

= Does it support XML-RPC or application passwords? =

Application passwords are not affected. XML-RPC logins without a TOTP
code are rejected for users with 2FA enabled.

= Is anything sent to third parties? =

No. Everything is generated and verified on your site.

== Changelog ==

= 1.0.0 =
* First release: TOTP engine (RFC 6238), profile setup with secret and
  otpauth URI, login second step, brute-force lockout, per-role
  enforcement.

== Privacy & Data ==

OTP Shield stores secrets in your own WordPress database and verifies
codes locally. Nothing is sent to any external service.
