JAY Login & Register
Developed with ❤️ in Iran. 🇮🇷 JAY Login & Register is not just a login plugin; it is a complete authentication, access control, and user management ecosystem for WordPress. While it creates a seamless Mobile OTP (One-Time Password) login and registration flow compatible with Digits, its true power lies in its Advanced Content Restriction and Granular Role Management capabilities. 🛡️ NEW: Advanced Role & Capability Management Take granular control over user permissions without extra plugins: * Visual Role Manager: Easily create, edit, and delete custom user roles with a clean, tabbed interface. * Granular Capability Assignment: Assign specific WordPress capabilities (Posts, Pages, Media, Comments, Categories, Tags, and 3rd-party plugin caps) to any role. * User-Specific Overrides: Grant or revoke specific capabilities for individual users directly from their profile page, independent of their assigned role. 🌟 NEW: Advanced User Panel & Profile Builder Transform user profiles with a powerful, drag-and-drop form builder: * Unlimited Custom Fields: Text, Select, Radio, Checkbox, and Jalali Date Picker. * Smart Conditional Logic: Show/hide fields dynamically based on User Meta (Server-side) or other field values (Client-side) with complex AND/OR rules. * Native Media Integration: Direct avatar uploads to the WordPress Media Library. * Bulletproof Security: All conditional logic is strictly re-validated on the server to prevent tampering. 🚀 NEW: Native Gravity Forms OTP Add-on Verify phone numbers directly inside any Gravity Form before submission: * Seamless Integration: Dedicated “JAY Mobile Verification” field in the GF editor. * AJAX Validation & Auto-Login: Verify OTPs without page reloads and optionally log in/register users instantly. * Built-in Anti-Fraud: Fully protected by JAY’s global IP/Phone Lockout system to prevent SMS bombing. Key Features Core Login & Registration * Smart Detection: Automatically routes new numbers to registration and existing numbers to login. * Multi-Method Login: Users can log in seamlessly using Mobile Number, Email, or Username. * Digits Compatibility: Seamlessly recognizes and logs in users previously registered with the Digits plugin. * Optional Identity Verification: Built-in duplicate prevention for National ID or Passport numbers. Powerful Content & Access Control * Inline & Redirect Locking: Use the [jay_content_lock] shortcode or Gutenberg Block to restrict content. Choose between a blurred preview with redirect, or an inline AJAX form that unlocks content instantly. * Post/Page Meta Box: Restrict entire posts or pages based on login status, specific user roles, or custom user meta keys. Advanced Security & Anti-Fraud * Multiple CAPTCHA Options: Disabled, Simple Math, Invisible Honeypot (with time-trap), or Google reCAPTCHA v3. * Brute-Force Protection: Configurable lockouts based on max failed attempts, duration, and blocking method (Phone, IP, or both). * Hide wp-login.php: Secure your site by completely hiding the default WordPress login page. Seamless User Experience (UX) * Smart Redirects: Automatically returns users to the page they were trying to access after login. * Modern Customizable Forms: Beautifully designed forms with optional logo upload and custom color styling. * Custom Logout URL: Create a user-friendly logout link (e.g., yoursite.com/logout). Powerful Admin Management * Admin Area Access Control: Restrict access to the WordPress dashboard (/wp-admin) based on specific user roles. * User Switching: Easily switch to any user’s account to view the site from their perspective. * Customizable User Columns: Adds sortable “Mobile Number” and “Jalali Registration Date” columns, and allows creating custom columns based on any user meta key. External Services This plugin connects to third-party services to provide its full range of features. These are optional and only active when configured by the site administrator. SMS Gateways (iPPanel, FarazSMS, Kavenegar, SMS.ir, MeliPayamak, RayganSMS): Sends the user’s mobile number to deliver SMS OTP codes. Privacy Policies Bale Messenger (Safir OTP): Sends the user’s mobile number to deliver app-based OTP codes as a cost-effective SMS alternative. Bale Developer Docs Google (reCAPTCHA v3 & OAuth): Processes IP and device data for bot protection and secure one-click authentication. Google Privacy Policy Eitaa (WebApp API): Secure data exchange with Eitaa servers for Mini App authentication. Eitaa Developer Docs
Top keywords
- user16×2.54%
- login9×1.43%
- custom6×0.95%
- mobile6×0.95%
- access5×0.79%
- content5×0.79%
- otp5×0.79%
- page5×0.79%
- role5×0.79%
- sms5×0.79%
- users5×0.79%
- wordpress5×0.79%
WP-OTP
With WP-OTP you can easily set up 2 Factor Authentication with One Time Passwords for your WordPress login. This extra layer makes your WordPress site a lot more secure. The new stealth mode allows for invisible OTP code entry, making your login screen look like any other, no extra OTP code input field. Getting started After installing and activating the plugin, every user can enable WP-OTP on their profile page. It’s as easy as scanning the provided QR Code or entering the OTP secret to any OTP generator app. Then just activate it by entering the generated OTP and voilà, all set up. Now, the login requires an OTP code to succeed. Each user gets their own secret key to authenticate with, giving them control over their login security. Development This plugin is completely open source and a work of passion. If you would like to be part of it and join in, make your way over to the project page now. Also, if you have an idea you would like to see in this plugin or if you’ve found a bug, please let me know. Configuration WP_OTP_STEALTH: Set this to true to enable stealth OTP mode. Filters There are a multitude of filters to be adjusted. wp_otp_qr_code_provisioning_uri: URI for online QR Code rendering (must contain {PROVISIONING_URI} placeholder for QR Code data). wp_otp_login_form_text: Text for input field on the login screen. wp_otp_login_form_text_sub: Subtext for the input field on the login screen. wp_otp_login_form_invalid_code_text: Error text for an invalid code input on the login screen. wp_otp_code_expiration_window: Set the window of code verification expiration. wp_otp_recovery_codes_count: Number of recovery codes to generate. wp_otp_recovery_codes_length: Length of the recovery codes. wp_otp_secret_length: Length of the secret key. Minimum requirements WordPress 4.6, PHP 7.4. Donate / Support All donations are much appreciated, thank you 🙏 Get professional support for this plugin with a Tidelift subscription Tidelift helps make open source sustainable for maintainers while giving companies assurances about security, maintenance, and licensing for their dependencies. Security To report a security vulnerability, please use the Tidelift security contact. Tidelift will coordinate the fix and disclosure.
Top keywords
- otp16×4.15%
- code11×2.85%
- login10×2.59%
- wp9×