plugin-icon

Logliy – Login Protect (Passkey, Email Code)

Passwordless WordPress login with Passkeys and Email OTP by FloBa Media. Complements Wordfence — does not replace it.
Version
0.0.9
Active installations
10
Last updated
Aug 24, 2026
Logliy – Login Protect (Passkey, Email Code)

Logliy – Login Protect controls how users sign in: Passkeys (WebAuthn) first, with Email one-time codes and Magic Links as fallback, plus an optional password path.

It is not a security suite and not a generic OTP plugin. Keep Wordfence (or similar) for WAF, brute-force lockouts, CAPTCHA, malware scanning, and classic TOTP 2FA. Logliy is the login-method layer on top.

Features

  • Passkey login and registration (discoverable credentials, Conditional UI where available)
  • Email OTP login via wp_mail
  • Magic link (one-click email) login
  • Password login off by default, re-enable site-wide and/or per role / per user
  • Role-based login/logout redirects
  • Optional custom login URL (auto-disabled if WPS Hide Login or similar is active)
  • Session length, Remember-me duration, admin idle timeout, logout everywhere
  • Users overview (Passkeys + last login)
  • Optional custom login logo, brand, background, and footer
  • Modern login UI on wp-login.php
  • WooCommerce classic + Blocks My Account/Checkout login forms
  • Cloudflare Turnstile compatible (verifies tokens on Passkey / Email OTP / Magic Link REST login)
  • REST API namespace logliy/v1
  • Rate limits for OTP and Passkey auth
  • Wordfence-friendly: fires wp_login_failed / wp_login and uses normal auth cookies
  • Emergency override: define( 'LOGLIY_ALLOW_PASSWORD', true ); in wp-config.php

Wordfence compatibility

  • Failed Logliy attempts trigger wp_login_failed so Wordfence lockouts still apply
  • Successful Logliy logins use wp_set_auth_cookie + wp_login like a normal wp_signon
  • Wordfence IP lockouts still run during passwordless login; Wordfence Login Security 2FA is skipped for Passkey / Email OTP / Magic Link (those methods already replace the password)
  • Wordfence TOTP 2FA continues to apply on the classic password path
  • Logliy does not remove Wordfence hooks globally — only suspends LS 2FA for the passwordless completion step

Cloudflare Turnstile

When Simple CAPTCHA with Cloudflare Turnstile (or equivalent) is enabled on the WordPress login form, Logliy requires a valid Turnstile token for Email OTP and Passkey REST authentication. The password path continues to use the Turnstile plugin’s own authenticate check.

WooCommerce

  • Classic My Account and Checkout login templates
  • Guest checkout unchanged
  • Does not block WooCommerce REST / Store API authentication
  • Optional panel above Checkout and Customer Account blocks for guests

Requirements

  • PHP 8.1+
  • WordPress 6.4+
  • HTTPS for Passkeys (localhost allowed for development)
  • Composer production dependencies are vendored in release builds (vendor-prefixed/)

External services

This plugin can contact Cloudflare Turnstile only when a compatible Turnstile plugin is active and configured for the WordPress login form. Logliy does not load Turnstile by itself.

When a visitor completes passwordless login (Passkey, Email OTP, or Magic Link) while Turnstile is required, Logliy sends the Turnstile response token and the visitor IP to Cloudflare’s siteverify API so the challenge can be validated. No other personal data is sent to Cloudflare by Logliy.

This service is provided by Cloudflare: Terms of Use and Privacy Policy.

Freeon paid plans
Tested up to
WordPress 7.1
This plugin is available for download for your site.