WPThumbs
Themes Plugins By purpose By industry Best-of lists Fix it guides
Free Plugin by WordPress.org v0.16.0

Two Factor

Enable Two-Factor Authentication (2FA) using time-based one-time passwords (TOTP), email, and backup verification codes.

Two Factor

The facts

Rating
4.8★ from 208
Active installs
100k+
Price
Free
Last updated
27 Mar 2026
Added
Aug 2015
Requires WP
6.8
Tested up to
WP 6.9.7
Requires PHP
7.2
Downloads
1,755,689

Our analysis

AI-assisted

The Two Factor plugin enhances the security of your WordPress login by requiring a second form of authentication alongside your password. This additional layer helps to protect against unauthorized access, even if passwords are compromised.

Users can choose from various authentication methods, including authenticator apps, email codes, and backup codes. Site administrators can manage settings for users and encourage the use of backup methods to prevent account lockouts.

Best for: This plugin is suitable for WordPress site owners looking to enhance their site's security.

What it does well

  • Free to use from the WordPress.org directory
  • Supports multiple authentication methods
  • Allows site administrators to configure settings for users
  • High security with time-based one-time passwords
  • User-friendly setup instructions

Where it falls short

  • Each user must configure their own settings
  • FIDO U2F Security Keys support has been removed

Verdict

Two Factor provides a straightforward way to implement two-factor authentication for WordPress, making it a valuable tool for improving site security.

From the developer

WordPress.org's own description of Two Factor, lightly tidied.

The Two-Factor plugin adds an extra layer of security to your WordPress login by requiring users to provide a second form of authentication in addition to their password. This helps protect against unauthorized access even if passwords are compromised.

Setup Instructions

Important: Each user must individually configure their two-factor authentication settings.

For Individual Users

  1. Navigate to your profile: Go to “Users” → “Your Profile” in the WordPress admin
  2. Find Two-Factor Options: Scroll down to the “Two-Factor Options” section
  3. Choose your methods: Enable one or more authentication providers (noting a site admin may have hidden one or more so what is available could vary):
    • Authenticator App (TOTP) – Use apps like Google Authenticator, Authy, or 1Password
    • Email Codes – Receive one-time codes via email
    • Backup Codes – Generate one-time backup codes for emergencies
    • Dummy Method – For testing purposes only (requires WP_DEBUG)
  4. Configure each method: Follow the setup instructions for each enabled provider
  5. Set primary method: Choose which method to use as your default authentication
  6. Save changes: Click “Update Profile” to save your settings

For Site Administrators

  • Plugin settings: The plugin provides a settings page under “Settings → Two-Factor” to configure which providers should be disabled site-wide.
  • User management: Administrators can configure 2FA for other users by editing their profiles
  • Security recommendations: Encourage users to enable backup methods to prevent account lockouts

Available Authentication Methods

Authenticator App (TOTP) – Recommended

  • Security: High – Time-based one-time passwords
  • Setup: Scan QR code with authenticator app
  • Compatibility: Works with Google Authenticator, Authy, 1Password, and other TOTP apps
  • Best for: Most users, provides excellent security with good usability

Backup Codes – Recommended

  • Security: Medium – One-time use codes
  • Setup: Generate 10 backup codes for emergency access
  • Compatibility: Works everywhere, no special hardware needed
  • Best for: Emergency access when other methods are unavailable

Email Codes

  • Security: Medium – One-time codes sent via email
  • Setup: Automatic – uses your WordPress email address
  • Compatibility: Works with any email-capable device
  • Best for: Users who prefer email-based authentication

FIDO U2F Security Keys

  • Deprecated and removed due to loss of browser support.

Read the full description on the official page →

Tagged as

Alternatives

Other plugins for securing a site.

Really Simple Security

Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vuln...

Free 3M+ installs 4.9★ (8,862)
Wordfence Security

Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team....

Free 5M+ installs 4.7★ (4,983)
Akismet Anti-spam: Spam Protection

The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam sol...

Free 5M+ installs 4.7★ (1,186)
Loginizer

Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.

Free 1M+ installs 4.8★ (1,030)
Safe SVG

Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website.

Free 1M+ installs 4.9★ (79)
All-In-One Security

Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plu...

Free 1M+ installs 4.7★ (1,715)