Product Preview · v1.1.1
BioAuth WP — Passkey sign-in

BioAuth lets each account register one Passkey and sign in with a username and device verification. Adding or removing a key requires the current account password. WordPress does not store a fingerprint or face image. This is not mandatory two-factor authentication, an SMS service, or a complete replacement for security plugins. Old keys must be registered again; test compatibility with 2FA and SSO plugins before use.
Compatibility
WordPress 6.5+, PHP 8.0+ with OpenSSL and mbstring, HTTPS, and a Passkey-capable browser. Locally tested with WordPress 6.8.3 and PHP 8.3.6. Real devices and combinations with security plugins need separate verification.
Installation overview
Install this product ZIP in WordPress Plugins. Do not leave the older version active alongside it. In your profile, enter your current password and register a Passkey. Test sign-in and password recovery in staging.
Changelog
1.1.1: Reject invalid authentication filter output. 1.1.0: WebAuthn validation, one-time challenge, and password confirmation for key registration and removal.