Release of the Passwordless X1280 Plugin for WordPress

The Passwordless Alliance has released “Passwordless X1280,” a passwordless plugin for WordPress, in the official WordPress.org plugin directory. Now, websites running on WordPress can implement passwordless authentication based on the international standard ITU-T X.1280 simply by installing the plugin, without the need for additional development.

The primary reason for choosing WordPress is its scale. According to W3Techs, as of October 2026, 40.1% of all websites are powered by WordPress, and when narrowed down to websites using a CMS (content management system), that figure rises to 58.6%. Since four out of every ten websites run on WordPress, any change to WordPress’s login method will directly impact a large number of online service users.

Passwordless X1280 is a plugin that implements the international standard X.1280—approved by the ITU-T in March 2024—which is a framework for out-of-band server authentication using mobile devices. When a user accesses the login screen, a one-time AutoPassword is displayed, and the user verifies that the same value appears in their smartphone app. Through this verification process, the user first confirms that the service they are accessing is legitimate before logging in—this is mutual authentication, the core principle of X.1280. If the values match, the process is completed by authorizing the login using the smartphone’s biometric authentication, such as Face ID or a fingerprint.

During this process, no password is entered or transmitted. Even if malware is installed on the user’s PC or smartphone, there is no password to intercept, so account theft through password theft can be prevented. Additionally, since login approval occurs via an out-of-band method on a smartphone—a trusted device separate from the PC—there is no need to equip the PC with additional hardware such as biometric authentication devices or security keys.

Above all, it is designed to minimize the burden of implementation for WordPress site administrators. The plugin requires no modifications to WordPress core files—simply install the plugin, and you’re done. Furthermore, it uses only standard WordPress hooks and is compatible with Multisite environments as well as major caching and other security plugins. After installation, users can choose between password-based and passwordless login methods on the login screen, and administrators can completely disable password-based login in the settings if desired.

The plugin, the user mobile app (available on the App Store and Google Play), and the X1280 authentication server distributed via Docker Hub are all provided free of charge for both B2C and G2C online services. Service operators simply need to sign up for free as a Service Member with the Passwordless Alliance to receive a Server Key; a test key is issued automatically upon sign-up. The costs associated with this free distribution are covered by advertising revenue from the user apps. Installation requires WordPress 5.8 or higher, PHP 7.4 or higher, and a site with HTTPS enabled; users simply need a smartphone with the Passwordless X1280 app installed.

Woo Jong-hyun, Chairman of the Passwordless Alliance, stated, “Four out of every ten websites worldwide run on WordPress, and we are pleased to be able to expand the adoption of international standard passwordless authentication within this ecosystem.” He added, “We will eliminate the inconvenience of password management through international standards and free software accessible to everyone, and accelerate the arrival of a passwordless digital era.”

The Passwordless X1280 plugin is available for download at WordPress.org (https://wordpress.org/plugins/passwordless-x1280/) and instructions for signing up as a service member and obtaining a server key can be found on the Passwordless Alliance website (www.passwordlessalliance.org).

Facebook
Twitter
LinkedIn