This project is not covered by Drupal’s security advisory policy.
There is an open security issue: OTP form is not protected against brute force
If you want to use this module, your options are:
- Choose another, actively maintained module instead
- Following the unsupported project process.
- Hire someone to fix the security bug so the module can be re-published and supported (Consider hiring companies listed in the Marketplace)
The module when enabled provides the option to users to setup 2FA using Email OTP. Once setup on a user profile that user will go through the 2FA login process where they will receive OTP in email, it will be verified by the module and if succesful user will be logged in. No extra configurations needed simply install the module and enable it.
1.1.6
Adds admin configurations;
- Allow admins to control whether users can enable/disable 2FA?
- Resend wait time (in minutes) configurable between 1 to 5 minutes, default 2 minutes.
- Force setup 2FA on next login.
- Provide a message on redirect to 2FA setup after login.
Project information
Unsupported
Not supported (i.e. abandoned), and no longer being developed. Learn more about dealing with unsupported (abandoned) projectsNo further development
No longer developed by its maintainers.- Project categories: Access control, Security
218 sites report using this module
- Created by ahmed.raza on , updated
This project is not covered by the security advisory policy.
Use at your own risk! It may have publicly disclosed vulnerabilities.

