Mrsea Login brings a green-and-ivory design to the WordPress login page and lets site administrators choose a custom login URL. Users can add an extra verification step with a time-based authenticator app.
Login design
Custom login URL
Optional two-factor authentication
Two-factor protection is optional and configured per account. Installing the plugin alone does not enable it for all users. HTTPS and PHP OpenSSL with AES-256-GCM support are required for enrollment.
Privacy and external services
Mrsea Login does not use a Google API, send setup secrets to a QR service, or load a remote QR library. The QR code is rendered in the user’s browser using bundled JavaScript. The plugin adds no analytics or telemetry.
The plugin stores the login/redirect slugs in options and the encrypted authenticator secret, last accepted time step and hashed recovery codes in user metadata. Pending setup data expires after ten minutes. Retry counters expire after five minutes. Short-lived database lock rows serialize security changes and are removed after use; abandoned locks can be recovered after sixty seconds.
Deactivation stops Mrsea Login’s protections. Uninstalling does not automatically erase enrollment data or settings; this supports reinstallation without silently removing saved security configuration. A verified site administrator can remove an account’s _mrsea_login_two_factor user-meta entry when intentionally resetting its enrollment. Do not remove another user’s security settings without identity verification.
Compatibility and security boundaries
mrsea_login_otp field for enrolled users. Password-only attempts fail.Google Authenticator is a trademark of Google LLC. Mrsea Login is an independent plugin and is not affiliated with or endorsed by Google or WordPress.
Mrsea Login is the renamed continuation of the earlier 1.3.x plugin.
Back up your site and keep an administrator session open. Install Mrsea Login,
then deactivate the old plugin and activate Mrsea Login. Do not run both.
Version 1.4.1 moves custom options and user metadata to the unique mrsea_login
prefix. Existing login slugs, encrypted secrets and recovery codes are imported
from the privately distributed predecessor when first needed.
Do not change WordPress salts during migration. Test in a private window.
If the previous plugin is still active, Mrsea Login pauses instead of running
its login hooks. A warning appears in the dashboard.
Mrsea Login by Seyi Aluko, licensed under GPLv2 or later.
Bundled qrcode-generator 2.0.4 by Kazuhiko Arase, MIT licensed.
Source: https://github.com/kazuhikoarase/qrcode-generator
The bundled js/qrcode.js is readable source; no build step is required.
Its license is included in js/LICENSE-qrcode.txt.