Take the password
off the attack surface.
Bring the same fingerprint/face passkey sign-in that Google and Apple use to your WordPress. On the free foundation you install first, Pro adds cross-device QR login, phased role-based enforcement, recovery codes, and true passwordless mode. No subscription — from $19 for one site — with one year of updates and email support.
🛡 14-day money-back guarantee — full refund, no questions asked | GPL v2+
- Layered break-glass — you are never locked out
- Set up in a few clicks — no expertise needed
- Buy once — the license never expires
- Coexists with SiteGuard / Wordfence
The actual admin screen (settings dashboard)
why passkeys
Your password is being hunted, right now.
wp-login.php is a classic target that bots around the world hammer around the clock. Passkeys don’t make the password stronger — they remove the password entirely.
THREAT 01 — Brute force / credential stuffing
Automated, 24/7, and never tired
No human can keep pace with bots trying leaked password lists one after another.
THREAT 02 — Phishing
Type it into a fake login and it’s over
However complex the password, entering it on a lookalike site hands it straight to the attacker.
THREAT 03 — Reuse
Another site’s breach becomes your way in
The same password leaked from a different service opens your admin dashboard.
PASSKEY — Neutralized by design
There is no secret to steal
A passkey is public-key crypto. The secret never leaves the device and is bound to your domain, so it won’t work on a fake site. Brute force, phishing, and reuse simply don’t apply.
※ Passkeys (WebAuthn / FIDO2) are the industry-standard passwordless method backed by Google, Apple, and Microsoft. Their phishing resistance comes from binding authentication cryptographically to the domain — but if password login is left enabled alongside, that path remains open (→ Pro’s “true passwordless” mode).
free + pro
Free gets it working. Pro locks it down.
Passkey login works today with Free alone. Pro then closes the “password back door” that’s left — one exit at a time.
Everything here, for free.
- Passkey registration & login (Touch ID / Windows Hello / phone)
- Drop it on any page with shortcodes or blocks
- Rename, suspend, and a site-wide passkey list
- 2FA-plugin coexistence, audit log, security notices
Seal the password’s way out.
- Role-based passkey enforcement (phased rollout with a grace period)
- Disable password login + close the reset / application-password back doors
- Cross-device QR login (with an anti-relay confirmation code)
- Step-up authentication, recovery codes, trusted-device management
pro features
What Pro does for you.
Leave the hard design to Pro. A few toggles on the settings screen bring up enterprise-grade authentication policy.
Cross-device QR login
Show a QR on your computer, scan it with your phone, and approve. A 4-digit confirmation code on the computer blocks relay (phishing) attacks.
Role-based enforcement
Make passkeys mandatory, starting with admins. A grace-period rollout migrates everyone without disruption, and the last administrator is exempt automatically.
Step-up authentication
Require a passkey confirmation after a password login. Choose “adaptive” (only on unusual devices/locations) or “always” (every time).
True passwordless mode
Beyond disabling password login, also turn off “Lost your password?” and application passwords — closing the REST and email-to-password back doors.
Recovery codes & magic links
Lost a passkey? Get back in with single-use recovery codes and an email login link. Users are notified automatically when their codes run low.
Trusted-device management
See which devices step-up has stopped challenging, and revoke that trust from a device you’ve sold or lent — one at a time or all at once.
More Pro features that run the operation
Authenticator policy via FIDO MDS (refuse compromised authenticators, require a FIDO certification level) / security-event webhooks to Slack, Teams, or a SIEM / weekly & monthly adoption reports / enrolment-nudge emails for users without a passkey / downgrade-attack alerts / network-wide multisite policy / WP-CLI commands (metadata refresh, recovery-code issue, reports). The image CAPTCHA of SiteGuard / CloudSecure applies to the Pro login screens too.
Role enforcement (grace period · exemptions)
Adoption (registration rate by role · last 30 days)
QR login (approve on phone · confirmation code)
no lockout by design
“Getting locked out” is engineered away.
The scariest part of enforcing passkeys is locking yourself out. Rapls Passkey Pro puts four escape routes in place before it tightens anything.
1. The last admin is never forced
Enforcement and password-disabling never apply to the last remaining administrator, so a full lockout can’t happen by construction.
2. Emergency bypass constant
One line in wp-config.php lifts all enforcement from the server side. If you can reach your hosting, you can always recover.
3. Recovery codes + email links
From “Can’t use your passkey?” on the login screen, get back in with a single-use code or an email link — all recorded in the audit log.
4. Phased enforcement with a grace period
Not “mandatory overnight” — it moves from notice → grace period → required, and users without a passkey see a prompt to register.
And until the license is activated, Pro adds no restrictions at all. Free’s passkey login keeps working the whole time, so no one gets locked out mid-rollout.
free vs pro
Free vs Pro
Pro includes everything in Free. Each “—” below is a defense you only get with Pro.
| Feature | Free | Pro |
|---|---|---|
| Passkey registration & login (Touch ID / Windows Hello / phone) | ✓ | ✓ |
| Shortcodes & Gutenberg blocks | ✓ | ✓ |
| Rename, suspend, site-wide passkey list | ✓ | ✓ |
| 2FA-plugin coexistence, audit log, security notices | ✓ | ✓ |
| Cross-device QR login (with anti-relay code) | — | ✓ |
| Role-based enforcement (phased rollout with grace period) | — | ✓ |
| Recovery codes & email login links | — | ✓ |
| Step-up authentication (adaptive / always) | — | ✓ |
| Disable password login + block reset & app passwords | — | ✓ |
| Trusted-device list & revocation | — | ✓ |
| Authenticator policy (FIDO MDS · AAGUID deny-list) | — | ✓ |
| Adoption reports · Slack / Teams webhooks · WP-CLI | — | ✓ |
| Passkey sign-up (register a new account with a passkey) | — | ✓ |
| Network-wide multisite policy | — | ✓ |
pricing
Launch pricing — buy once.
Not a subscription. One purchase includes a year of free updates & email support. The license itself never expires.
| Annual subscription (other paid security / 2FA) | Rapls Passkey Pro | |
|---|---|---|
| Payment | Renews every year (auto-billed) | One-time (pay once) |
| Per site, roughly | $49–99 / year | From $19 (launch price) |
| Year 2 onward | Keeps billing | Keep using it at no extra cost Extending updates / support is optional |
※ Typical annual price band for paid 2FA / login-security plugins on a single site (as of July 2026, from vendors’ own sites; excluding sales, FX, and tax; all renew yearly).
Free
Try passkeys for free first
$0
Free forever · WordPress.org
- Passkey registration & login
- Shortcodes & blocks
- Rename, suspend, passkey list
- 2FA coexistence, audit log, notices
Pro · 1 site
For a personal blog or business site
$39
$19-50%
One-time · 1 year of updates & support
⏳ Launch price — until Dec 31, 2026
- Everything in Free +
- QR login · role enforcement
- True passwordless · step-up auth
- Recovery codes · trusted-device management
Pro · 5 sites
For agencies & freelancers
$79
$39-50%
One-time · 1 year of updates & support
⏳ Launch price — until Dec 31, 2026
- Everything in the 1-site plan
- Use on up to 5 sites
- Protect client sites together
- As low as ~$8 per site
Right after purchase we email your license key and download link. Updates are delivered straight to your dashboard and verified by SHA-256 before installing.
Before you buy
- The free “Rapls Passkey” plugin is installed and active (Pro is its add-on)
- PHP 8.2+, WordPress 6.0+, and served over HTTPS
- We recommend confirming passkey login works on Free first
compatibility
It runs on your usual WordPress.
Works alongside SiteGuard WP Plugin, CloudSecure WP Security, Wordfence (Login Security), and Two-Factor. Their image CAPTCHA applies to the Pro login screens too, and a passkey satisfies the Wordfence / Two-Factor second factor. Even under security plugins that lock the REST API to logged-in users, the passkey login route is designed to keep working.
faq
Frequently asked questions
If I lose my phone or passkey, am I locked out?
No. There are layered escape routes: single-use recovery codes, an email login link, a one-line emergency bypass in wp-config.php, and server-side recovery via WP-CLI. The last administrator is never forced in the first place.
Is it safe to enforce passkeys for everyone?
You migrate gradually. Pick roles and roll out as “notice → grace period → required,” with a prompt for anyone who hasn’t registered. You can watch progress in the adoption report and audit log.
Is it a subscription? Does it stop working in year 2?
It’s a one-time purchase. The license never expires and there are no feature tiers. You get one year of free updates and email support; after that the plugin keeps working (extending updates is optional).
How do updates arrive?
Because it’s distributed outside WordPress.org, updates come straight to your dashboard. The download goes through a short-lived signed token and the ZIP is verified by SHA-256 before installing. A “Check for updates” link is added to the plugins list.
Can I use just the free version?
Yes. Registering, signing in with, and managing passkeys is complete in Free alone. Pro is the add-on for sites that want to seal the “password back door” or enforce passkeys across an organization. Try Free first.
Does it work with SiteGuard or Wordfence?
Yes. The image CAPTCHA of SiteGuard / CloudSecure is applied to the Pro login screens (recovery code, magic link, sign-up) too. It also integrates with 2FA such as Wordfence Login Security and Two-Factor — logins weaker than a passkey still have to pass the site’s 2FA.
If the license server goes down, does my site stop?
No. Once activated, a license rides out a server outage for a 14-day grace window. And while unlicensed, Pro adds no restrictions, so login is never blocked.
Can I get a refund?
Within 14 days of purchase, we refund in full for any reason. See our refund policy for details.
A password-free dashboard,
starting today.
Buy once, with a year of updates. Try passkeys on Free first, then move the sites you want to lock down to Pro. Launch 50% OFF runs until Dec 31, 2026 (full price after).
🛡 14-day money-back guarantee — full refund, no questions asked