به محتویات بروید
WordPress.org

فارسی (افغانستان)

  • پوسته‌ها
  • افزونه‌ها
  • اخبار
  • درباره
  • Contact
  • دریافت وردپرس
دریافت وردپرس
WordPress.org

Plugin Directory

ZapQR Login

  • Submit a plugin
  • My favorites
  • Log in
  • Submit a plugin
  • My favorites
  • Log in

ZapQR Login

توسط dasecure
دانلود
  • جزئیات
  • نقد و بررسی‌ها
  • نصب
  • توسعه
پشتیبانی

توضیحات

ZapQR Login gives your WordPress site passwordless sign-in, two ways:

Sign in with ZapQR (SSO) — recommended

A “Sign in with ZapQR” button on your login page. Visitors sign in with their ZapQR account — passkey-first (Face ID / Touch ID / security key), with an email link as fallback — via standards-based OpenID Connect single sign-on. One ZapQR account works across every site that offers it.

  • Passkey-first: phishing-resistant WebAuthn sign-in, no passwords anywhere
  • Standards-based: OAuth 2.0 authorization-code flow with PKCE; ID tokens verified in the plugin (RS256, JWKS)
  • Links existing WordPress users by their verified email — admins keep their role
  • New visitors are created with a low-privilege role you choose (Subscriber by default)
  • Single logout: logging out of WordPress also ends the ZapQR session
  • No external code: the whole flow is server-side redirects and server-to-server calls

QR credential fill (classic)

Users save their WordPress credentials in the ZapQR app; on the login page they scan a QR code and the login form fills and submits itself. Credentials travel phone → browser over an encrypted WebSocket relay and are never stored on external servers.

External services

This plugin talks to the following services. No data is sent anywhere until a site administrator enables the relevant mode.

ZapQR identity provider (SSO mode) — auth.zapqr.ai by default, or a self-hosted issuer the admin configures. When a visitor clicks “Sign in with ZapQR” their browser is redirected there to authenticate; your server then exchanges an authorization code (server-to-server) and receives the visitor’s email address and its verified status — nothing else. Provider: DaSecure (zapqr.ai, terms and privacy linked there).

ZapQR relay (QR mode) — wss://relay.zapqr.ai, a WebSocket relay that pairs the login page with the visitor’s phone using a random session identifier. Credentials pass through end-to-end encrypted and are not stored. Provider: DaSecure (zapqr.ai).

QR image service (QR mode) — api.qrserver.com renders the QR image. It receives only the random session identifier and your site’s hostname — never credentials. Provider: goqr.me (privacy).

عکس‌های صفحه

Login page with "Sign in with ZapQR" and the QR widget
Login page with “Sign in with ZapQR” and the QR widget
Settings page: SSO configuration with the URIs to register
Settings page: SSO configuration with the URIs to register

نصب

  1. Install and activate the plugin.
  2. For SSO: go to Settings > ZapQR Login, copy the Redirect URI and Post-logout URI shown there, register your site at the ZapQR identity provider to get a Client ID and Secret, paste them in, tick Enable, save.
  3. For QR fill: nothing to configure — the widget appears on wp-login.php. Customize theme and accent color in Settings > ZapQR Login.

سوالات متداول

What does the site receive about the visitor in SSO mode?

Only a verified email address and a stable account identifier, delivered in a cryptographically signed token that the plugin verifies against the provider’s published keys. No passwords, no passkeys, no profile data.

Can someone take over an existing account?

No. Linking to an existing WordPress user happens only when the ZapQR identity provider asserts the email is verified; unverified emails are rejected outright. You can also disable linking entirely, and new users always get the low-privilege role you configure.

Where do passkeys live?

With the visitor and the ZapQR identity provider — never on your WordPress site. Your site only consumes the signed sign-in assertion.

Does the QR credential mode still work?

Yes, unchanged. It is a separate, coexisting mode: the ZapQR app stores per-site WordPress credentials locally on the phone (Face ID / Touch ID protected) and relays them to the browser at login.

Does this work with multisite?

Yes.

نقد و بررسی‌ها

نقد و بررسی‌ای برای این افزونه یافت نشد.

توسعه دهندگان و همکاران

“ZapQR Login” نرم افزار متن باز است. افراد زیر در این افزونه مشارکت کرده‌اند.

مشارکت کنندگان
  • dasecure

ترجمه “ZapQR Login” به زبان شما.

علاقه‌ مند به توسعه هستید؟

کد را مرور کنید, را بررسی کنید مخزن SVN, یا مشترک شوید گزارش توسعه توسط RSS.

گزارش تغییرات

1.1.0

  • New: “Sign in with ZapQR” single sign-on (OpenID Connect, authorization-code + PKCE, RS256 ID-token verification via JWKS)
  • New: link existing users by verified email; configurable default role for new users; optional single logout through the identity provider
  • Changed: the QR widget script is now bundled with the plugin instead of loaded from zapqr.ai
  • Hardened: explicit sanitization on all settings

1.0.0

  • Initial release: QR code credential fill on wp-login.php, theme and accent customization

اطلاعات

  • Version 1.1.0
  • Last updated 9 ساعت پیش
  • Active installations کمتر از 10
  • WordPress version 5.5 یا بالاتر
  • Tested up to 7.0.4
  • PHP version 7.4 یا بالاتر
  • Language
    English (US)
  • Tags
    authenticationloginpasskeypasswordlesssso
  • نمایش پیشرفته

امتیازها

No reviews have been submitted yet.

Your review

See all reviews

مشارکت کنندگان

  • dasecure

پشتیبانی

چیزی برای گفتن دارید؟ نیاز به کمک دارید؟

مشاهده انجمن پشتیبانی

کمک مالی

آیا تمایل دارید از پیشرفت این افزونه حمایت کنید؟

کمک مالی به این افزونه

  • درباره ما
  • اخبار
  • میزبانی
  • حریم خصوصی
  • ویترین
  • پوسته‌ها
  • افزونه‌ها
  • الگوها
  • یادگیری
  • پشیتبانی
  • توسعه‌دهندگان
  • WordPress.tv ↗
  • مشارکت کنید
  • رویدادها
  • حمایت ↗
  • Swag ↗
  • WordPress.com ↗
  • مت ↗
  • بی‌بی‌پرس ↗
  • بادی‌پرس ↗
WordPress.org
WordPress.org

فارسی (افغانستان)

  • از حساب X (تویتر سابق) ما دیدن کنید
  • Visit our Bluesky account
  • Visit our Mastodon account
  • Visit our Threads account
  • صفحه ی فیسبوک ما را بازدید نمایید
  • بازدید از حساب کاربری ما در اینستاگرام
  • بازدید از حساب کاربری ما در LinkedIn
  • Visit our TikTok account
  • از کانال یوتیوب ما دیدن کنید
  • Visit our Tumblr account
کد شعر است.
The WordPress® trademark is the intellectual property of the WordPress Foundation.