That is not the contract that is being used within your plugin. For all we know you will withdraw the funds that are not yours. I am not saying you will but not allowing people to look at it, is because you more or less you have the ability to take everyone’s funds whenever you wish, aside from the 1.5%.
It seems you are worried about people taking it. You should be more worried about people using it.
As you can see, I am using your plugin but it is not proving the QR Code the same way on the frontend.
The backend 2FA works like you reference.
</img>
(https://snag.gy/fHeJCK.jpg)