Compatible with WordPress 5.8 and later. The minimum PHP version remains 7.4 to preserve secure, predictable authentication behavior across supported installations.
Tomevexa Secure Login is distinguished by its privacy-preserving adaptive security model. It can require an additional email OTP after a correct password when a non-administrator signs in from a network that has not yet been trusted.
The plugin also provides a front-end login form that can authenticate eligible WordPress users with a one-time numeric code sent to their account email address.
The plugin also provides optional password login, configurable password-expiry enforcement, and a local adaptive step-up mode for non-administrator accounts. When adaptive step-up is enabled, a correct password from a network that has not yet been trusted requires an email OTP before access is granted. Administrator accounts remain excluded from the plugin OTP path and password-expiry enforcement.
Main features:
random_int() and stored only as WordPress password hashes in temporary transients.Use the [tomevexa_secure_login] shortcode on a page. You can optionally set a redirect destination:
[tomevexa_secure_login redirect_url="https://example.com/account/"]
The redirect is validated with WordPress redirect-safety functions. If a redirect_to parameter is supplied by WordPress, the plugin can also honor that safe destination.
OTP messages are sent with the standard WordPress wp_mail() function. Actual delivery therefore depends on the site’s WordPress mail configuration and hosting environment. The plugin does not connect directly to an external email service.
Profile Builder is not required. When Profile Builder Pro is active and its Custom Redirects module is enabled, Tomevexa Secure Login preserves the configured after-login redirect.
The login form uses semantic labels and buttons, keyboard-operable controls, visible focus indicators, polite and assertive live regions for status and errors, a single numeric OTP field compatible with paste and autocomplete="one-time-code", and reduced-motion support.
Accessibility also depends on the active theme and surrounding page content. Site owners should test the completed page with keyboard navigation and their preferred assistive technologies.
Tomevexa Secure Login does not include analytics, telemetry, advertising, or direct third-party API requests. Passkey registration and verification are performed locally between the browser/authenticator and the WordPress site using WebAuthn; no external authentication service is required. OTP emails are sent through the site’s configured WordPress mail system. Temporary OTP data is stored in WordPress transients and contains a password hash of the OTP, the user ID, expiry time, and attempt count. The OTP itself is not stored in plaintext. When adaptive step-up is enabled, trusted-network recognition stores only salted HMAC hashes derived from reduced network prefixes plus their expiry times in user metadata; the trusted-network list does not store raw IP addresses.