This plugin hasn’t been tested with the latest 3 major releases of WordPress. It may no longer be maintained or supported and may have compatibility issues when used with more recent versions of WordPress.

Perfect Paper Passwords


The Perfect Paper Passwords plugin for WordPress gives you free multifactor authentication for your WordPress blog.

The multifactor authentication requirement can be enabled on a per user basis, You could enable it for your administrator account, but login as usual with less privileged accounts.

The Perfect Paper Passwords system itself was created by Steve Gibson,

This plugin requires the SHA256 hashing algorithm, the BCMath library and Mcrypt/AES-128 (Rijndael-128) to be available in your PHP installation, it’s not possible to activate the plugin without


Localization files must be named like this: (Italian binary file)

perfectpaperpasswords-it_IT.po (Italian source file)

in order to be recognized by my plugin.


Thanks to:

Aldo Latino for his help, suggestions and Italian translation.


  • Perfect Paper Passwords section on the Profile and Personal options page.
  • The enhanced loginbox.
  • Passcard generation at
  • Passcards containing Perfect Paper Passwords


  1. Install and activate the plugin.
  2. Enter a secret on the Users -> Profile and Personal options page, in the Perfect Paper Passwords section.
  3. After saving your changes, copy the Sequence key, and goto and create yourself a few passcards.
  4. That’s it, you are ready to login with Perfect Paper Passwords on your WordPress blog.


Are there any special requirements for my WordPress/PHP installation ?

Yes, your PHP installation needs the SHA256 hashing algorithm, BCMath library and Mcrypt/AES-128 (Rijndael-128)

Can I use Perfect Paper Passwords with the Android/iPhone apps for WordPress ?

No, that wont work, but you could create a special account for mobile usage and choose not to enable
Perfect Paper Passwords for this account.

Oops, I lost my passcards, as well as my secret/sequencekey, can’t get access to my WordPress blog, what to do now ?

You’ll have to somehow delete the plugin from your WordPress installation, using cPanel, FTP or SSH you
can delete the /wp-content/plugins/perfect-paper-passwords directory.

Perfect Paper Passwords, how secure is this, how does it work ?

Steve Gibson (the creator) explains it very well here : and

Contributors & Developers

“Perfect Paper Passwords” is open source software. The following people have contributed to this plugin.




Bugfix: Another single/double quote problem fixed.


Bugfix: Secrets with single or double quotes didn’t work.


Userspecific passcode length, anything from 2 to 16 characters can be used.

Italian translation by Aldo Latino

HTML cleanup (Validation errors)

Algorithm used to show code/cardnumbers to unknown users changed,
should be a bit harder to guess valid usernames now.



Trying to clean up svn mess after screenshot rename operation


Screenshot files renamed.


Version bumb to fix svn problem


Nicer looking plugin name on the plugin site


  • Initial release