=== VWEB Admin Email Login Verify ===
Contributors: jaingaurav9981
Donate link: https://vwebindia.com/
Tags: login, authentication, email, security, two-factor
Requires at least: 6.0
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 1.0.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Administrators must enter an email verification code after password login. Regular users log in without extra verification.

== Description ==

VWEB Admin Email Login Verify is a VWEB India plugin that adds an extra login step only for administrator (and other selected) roles.

After the username and password are accepted, WordPress emails a 6-digit code to that user's account email. The dashboard opens only after the correct code is entered. Subscribers, customers, and other roles you do not select log in as usual.

This is not a generic two-factor suite. It is a focused admin-only email code for wp-login.php, built by [VWEB India](https://vwebindia.com/).

= What it does =

* Checks the password first, then starts email verification for selected roles
* Sends a 6-digit code to the user's WordPress profile email
* Lets regular users sign in with no extra step
* Expires unused codes (default 10 minutes)
* Limits failed code attempts (default 5)
* Allows resending a code after a short cooldown
* Skips REST API, XML-RPC, WP-CLI, cron, and AJAX authentication

= Settings =

Go to **Settings → VWEB Login Verify** to:

* Enable or disable verification
* Choose which roles need a code (Administrator is selected by default)
* Set how long a code stays valid
* Set how many wrong codes are allowed

= Email delivery =

The plugin uses WordPress `wp_mail()`. If codes do not arrive, configure SMTP on the site and check the spam folder.

= Emergency disable =

If you cannot receive mail and are locked out of admin, add this line to `wp-config.php`, log in, fix email, then remove the line:

`define( 'AELV_DISABLE', true );`

== Installation ==

1. Upload the `vweb-admin-email-login-verify` folder to the `/wp-content/plugins/` directory, or install the zip through **Plugins → Add New → Upload Plugin**.
2. Activate the plugin through the **Plugins** screen.
3. Confirm the site can send email.
4. Open **Settings → VWEB Login Verify** if you want to change roles or timings.
5. Log out and test an administrator login.

== Frequently Asked Questions ==

= Which email receives the code? =

The Email field on that user's WordPress profile (**Users → Profile**). It is not a separate plugin address.

= Do regular users get a code? =

No. Only roles you select under **Settings → VWEB Login Verify** must verify. The default is Administrator.

= What if the email never arrives? =

Check spam, confirm the profile email is correct, and set up an SMTP plugin so `wp_mail()` can send. You can use **Resend code** on the verification screen.

= What if I am locked out? =

Add `define( 'AELV_DISABLE', true );` to `wp-config.php` to turn the plugin off, log in, fix mail, then remove that line. You can also deactivate the plugin over FTP or WP-CLI.

= Does this replace two-factor apps? =

No. It is email verification for selected roles after a successful password login, not an authenticator-app or hardware-key plugin.

== Changelog ==

= 1.0.0 =
* Initial release.
* Email verification for administrators after password login.
* Regular users log in without a code.
* Settings for roles, code expiry, and failed attempts.

== Upgrade Notice ==

= 1.0.0 =
Initial release. Confirm site email works before requiring admin verification.
