Holovid® Secure Connect
Two-factor authentication: TOTP codes or codeless Secure Connect login. Anti-phishing, encrypted secrets, no external dependencies.
Use with caution
Holovid® Secure Connect works, but test it on a staging site before relying on it in 2026. Was last updated 2 months ago, and scores 60/100 on our health check.
- Tested with the latest WordPress (7.1)
- Small user base (<10 active installs)
- Very few reviews so far
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where Holovid® Secure Connect stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| 2FA | >100 |
| anti-phishing | #8 |
| authentication | >100 |
| security | >100 |
| two factor | >100 |
About Holovid® Secure Connect
From the official readme · v1.3.0Description
You have a WordPress site and you want to protect it from hackers? This plugin is made for you!
Today, a simple password is no longer enough. Hackers have tools to guess, steal or intercept them. Two-factor authentication (2FA) is like adding an extra lock to your door: even if someone finds your key, they cannot get in without the second lock.
Holovid® Secure Connect offers you two ways to protect your site:
- TOTP mode (temporary code)
A 6-digit code that changes every 30 seconds. You find it in the Holovid® Secure Connect app on your phone (or in Google Authenticator, Authy, etc.). You type the code, and you are in. It is the most common system, compatible with all authenticator apps.
- Secure Connect mode (codeless)
This one is even simpler: you do not type anything at all. A QR Code appears on your WordPress login page, you scan it with the Holovid® Secure Connect app, you confirm with a tap on your phone, and you are logged in. Fast, effortless.
But Secure Connect is not just convenient. It protects you against a particularly sneaky category of attacks: proxy phishing (known as “AiTM” attacks, such as Tycoon 2FA or EvilProxy). These attacks create a fake copy of your login page to intercept your TOTP code in real time. With Secure Connect, this technique does not work, because the signature is bound to the real domain of your site.
Both modes can coexist on your site. Each user chooses the one they prefer from their profile.
What makes this plugin different
- Two levels of protection to choose from: a classic temporary code or a codeless login from your phone.
- Resistant to proxy phishing: Secure Connect prevents hackers from intercepting your authentication, even if they copy your login page.
- Nothing leaves your server: TOTP mode works without calling any external service. The QR Code is generated directly by your server, in pure PHP, without going through Google or any other service.
- Your secrets are encrypted: TOTP keys are protected with AES-256-GCM encryption in your database. Even if the database leaks, they remain unreadable.
- One device = one account: each WordPress account is linked to a single phone. If someone tries to log in with a different device, the plugin detects it and denies access.
- Backup codes: in TOTP mode, 10 single-use codes are generated in case you lose your phone.
- Lightweight and dependency-free: no external library, no third-party service on the TOTP side. The plugin does everything itself.
- French and English: the interface automatically adapts to your WordPress language.
In a nutshell
TOTP (temporary code)
Secure Connect (codeless)
How does it work?
You type a 6-digit code
You scan a QR Code and confirm
Compatible with other apps?
Yes (Google Authenticator, Authy, etc.)
No, Holovid® Secure Connect only
Works offline?
Yes
No (requires internet)
Resistant to proxy phishing?
No
Yes
Backup codes?
Yes (10 codes)
No (an admin can deactivate)
External services
This plugin connects to the Holovid® Secure Connect server for the Secure Connect (codeless) authentication mode. The TOTP mode does not use any external service.
Holovid® Secure Connect API (api.holovid.net)
When Secure Connect is enabled, the plugin communicates with the Holovid® Secure Connect API hosted in Gravelines, France, in the following situations:
- Registration: when a user activates Secure Connect, the plugin requests a cryptographic challenge from the API. The site domain name is sent.
- Login: when a user logs in with Secure Connect, the plugin polls the API to check whether the user has confirmed the authentication on their phone. The challenge nonce and session token are sent.
- Device verification: when a device change is detected, the plugin checks with the API whether the previous device registration is still active. The account identifier and site domain are sent.
- Login page: the Secure Connect login page loads a JavaScript SDK from the API server to display the QR Code and handle the authentication flow.
No personal data (name, email, password) is ever sent to the API. Only cryptographic identifiers (nonce, session token, account ID) and the site domain are transmitted.
This service is provided by Holovid SAS (Bergerac, France).
Installation
It is quick, about 2 minutes:
- In your WordPress admin, go to: Plugins > Add New
- Click “Upload Plugin”, choose the ZIP file, then click “Install Now”
- Activate the plugin
- Go to your Profile (top right, click your name, then “Edit Profile”)
-
Scroll down to the “Holovid® Secure Connect” section
To activate TOTP mode:
- Click “Enable TOTP 2FA”
- Scan the QR Code that appears with the Holovid® Secure Connect app (or another authenticator app)
- Enter the 6-digit code to confirm
-
Write down the 10 backup codes somewhere safe (on paper, for example). If you lose your phone, these are what will let you log back in.
To activate Secure Connect mode:
-
Click “Enable Holovid® Secure Connect”
- Scan the QR Code with the Holovid® Secure Connect app
- Confirm the registration on your phone
- That is it. Next time you log in, a QR Code will automatically appear on the login page.
Frequently asked questions
I already use Google Authenticator, does it work?
Yes. TOTP mode uses the same standard as Google Authenticator, Authy, Microsoft Authenticator and all similar apps. If you are used to these apps, you will feel right at home.
What is the difference between TOTP and Secure Connect, in practice?
With TOTP, you open your app, read a 6-digit code, and type it on your site. It is simple and it works well. With Secure Connect, you do not type anything. A QR Code appears, you scan it, you confirm on your phone, and you are in. On top of being faster, Secure Connect protects you against proxy attacks (when a hacker creates a copy of your login page to steal your code in real time). TOTP does not protect against that.
Is my data safe?
Yes. TOTP secrets are encrypted with AES-256-GCM (an encryption standard used in banking and military applications) directly in your database. Secure Connect keys are generated and stored on your phone, in the system’s secure keychain (Keychain on iPhone, Keystore on Android). They never leave your device.
I lost my phone, what do I do?
In TOTP mode: use one of your 10 backup codes to log in. In Secure Connect mode: ask a site administrator to deactivate Secure Connect on your account (from your WordPress profile). Then you can reactivate it with your new phone.
Can I use Secure Connect on two phones?
No, one phone per account. This is a security choice: if someone steals your credentials, they cannot register their own phone as long as yours is active. To switch phones, deactivate Secure Connect from your profile, then reactivate it with the new one.
Does Secure Connect need internet?
Yes. When you scan the QR Code, your phone communicates with the Holovid® Secure Connect server (hosted in France) to verify the signature. TOTP mode, on the other hand, works completely offline.
Does it slow down my site?
No. The plugin only loads its scripts on the login page and on the profile page. It does not touch the rest of your site. On the TOTP side, everything is calculated locally, with no network calls.
Is it free?
Yes, the plugin is entirely free and will remain so.
Changelog
1.3.0
- Works with the new Holovid® Secure Connect app (formerly Holovid® ID): wording updated everywhere
- Holovid® Vault column removed; replaced by the app download QR Code, generated locally by the plugin (no remote image)
- Plugin icon served from the plugin itself: no request to an external server from the admin
- Bundled translations are now loaded by the plugin itself and take precedence over the WordPress.org language pack (no more mixed languages right after an update)
- WordPress 7.1 compatibility
1.2.16
- Added a “View details” link in the plugins list (opens the plugin information modal)
- French translation: glossary and typography compliance (non-breaking spaces, wording)
- Minor housekeeping: internal code comments made more generic
1.2.15
- Fixed the TOTP login screen: the 2FA code field is now displayed correctly (it was hidden by an over-broad CSS rule)
- Clearer TOTP login prompt (“Enter your 2FA code”) and improved spacing
- Unique prefix applied to the Secure Connect JavaScript object (WordPress.org review compliance)
1.2.14
- Holovid® Vault access button added
- Minor bug fixes
1.2.13
- QR code to download Holovid® Secure Connect application added
- Minor bug fixes
1.2.12
- WordPress 7.0 compatibility
- WordPress Plugin Check compliance (escaping, enqueued scripts, input sanitization)
Screenshots
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best Holovid® Secure Connect alternatives
All 2FA plugins →FAQ
Holovid® Secure Connect: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Oct 7, 2026
Is Holovid® Secure Connect free?
Yes. Holovid® Secure Connect is free to download and use from the official WordPress.org plugin directory.
Is Holovid® Secure Connect safe to use in 2026?
Holovid® Secure Connect works, but test it on a staging site before relying on it in 2026. Was last updated 2 months ago, and scores 60/100 on our health check.
How many websites use Holovid® Secure Connect?
Holovid® Secure Connect is active on <10 WordPress websites and has been downloaded 320 times since it launched in June 2026. It was downloaded 62 times in the last 30 days.
Does Holovid® Secure Connect work with WordPress 7.1?
Yes. The developer has tested Holovid® Secure Connect up to WordPress 7.1.3, the latest release. It requires WordPress 5.8 or newer.
What PHP version does Holovid® Secure Connect need?
Holovid® Secure Connect requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was Holovid® Secure Connect last updated?
The latest version, 1.3.0, was released on August 23, 2026 (2 months ago).
Who makes Holovid® Secure Connect?
Holovid® Secure Connect is developed and maintained by Holovid.
What are the best alternatives to Holovid® Secure Connect?
The most popular alternatives to Holovid® Secure Connect are Wordfence Security (5M+ installs), Really Simple Security (3M+ installs) and Limit Login Attempts Securi… (1M+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card