WP 2FA – Two-factor Authentication for WordPress



Add an extra layer of security to your WordPress website login page and its users. Enable two-factor authentication (2FA), the best protection against users using weak passwords, and automated password guessing and brute force attacks.

Features | Getting Started | More Info

Use the WP 2FA plugin to enable two-factor authentication for your WordPress administrator user, and to enforce your website users, or some of them to use 2FA. This plugin is very easy to use. It has wizards with clear instructions, so even non technical users can setup 2FA without requiring technical assistance.

Maintained & Supported by WP White Security

WP White Security builds high-quality niche WordPress security & admin plugins such as Password Policy Manager, a plugin with which you can ensure all your users use strong passwords.

Browse our list of WordPress plugins that can help you better manage and improve the security of your WordPress websites and users.

WP 2FA Key plugin features & capabilities

  • Free Two-factor authentication (2FA) for all users
  • Supports TOTP (code from 2FA apps like Google Authenticator and Authy) and OTP (email based codes)
  • Supports 2FA backup codes
  • Very easy to use and wizard driven
  • Use policies to enforce 2FA with a grace period or require your users to instantly setup 2FA upon login
  • Protection against automated password guessing and dictionary attacks

FREE Plugin Support

Support for the WP 2FA plugin is available for free via:

For any other queries, feedback, or if you simply want to get in touch with us please use our contact form.

Related Links and Documentation

From within WordPress

  1. Visit ‘Plugins > Add New’
  2. Search for ‘WP 2FA’
  3. Install & activate the WP 2FA from your Plugins page.


  1. Download the plugin from the WordPress plugins repository
  2. Unzip the zip file and upload the wp-2fa folder to the /wp-content/plugins/ directory
  3. Activate the WWP 2FA plugin through the ‘Plugins’ menu in WordPress


  • The first-time install wizard allows you to setup 2FA on your website and for your user within seconds.
  • The wizards make setting up 2FA very easy, so even non technical users can setup 2FA without requiring help.
  • You can require users to enable 2FA and also give them a grace period to do so.
  • Users can also use one-time codes via email as a two-factor authentication method.
  • You can use policies to require users to instantly set up and use 2FA, so the next time they login they will be prompted with this.
  • It is recommended for all users to also generate backup codes, in case they cannot access the primary device.
  • In the user profile users only have a few 2FA options, so it is not confusing for them and everything is self explanatory.
  • The plugin blocks the accounts of users who are required to have 2FA but fail to enable it within the grace period, so they do not jeopardize the security of your website.


May 13, 2021
Very happy for the support given by the creators of the plugin, especially in the Spanish translations. Thank you.
April 29, 2021
and I've tested almost every available plugins. The plugin is very user-friendly and has all the functions that I need. Once I had to reach out to the support since there was an issue with our CRM system and they solved it very quick. Thanks again! Highly recommended!
April 25, 2021
Love this plugin. There‘s only a potential defect in the latest version when downloading the txt File with the backup codes. On my site this txt file doesn‘t contain the codes. Is this a known issue? Best
March 31, 2021
I had been looking for a long time and tried many 2FA solutions for WordPress before this one came. Everyone before had problems in one way or another. Above all, they were cumbersome for both users and administrators. Then came WP 2FA… I use WP 2FA on several sites and for a long time. I have not had any problems whatsoever, either technical or user-friendly.WP 2FA is without comparison the best 2FA plugin available for WP.
Read all 41 reviews

Contributors & Developers

“WP 2FA – Two-factor Authentication for WordPress” is open source software. The following people have contributed to this plugin.


“WP 2FA – Two-factor Authentication for WordPress” has been translated into 4 locales. Thank you to the translators for their contributions.

Translate “WP 2FA – Two-factor Authentication for WordPress” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.


1.6.0 (2021-05-13)

Release notes: New user 2FA status, custom redirects and many other new features & improvements

  • New features

  • Improvements

    • Backup codes are now aptional: administrators can disable them so the plugin does not suggest users to create them.
    • Removed reference to “WordPress” in the 2FA wizard.
    • Optimized the code that retrieves the list of users, roles and sites on a multisite network.
    • User 2FA settings are now saved as array in the database instead of comma separated list.
    • Added an alert to notify users that all the changes will be lost if they terminate the wizard without setting up 2FA.
    • Improved the wizard and the user input sanitization.
    • Converted a number of database settings to filters.
    • Standardized the text and button labels on the 2FA code page.
    • Hidden the wizard’s holding page.
    • Plugin now uses the Site name and site email address as from email address.
    • 2FA apps logos in wizard now link directly to the application’s specific instructions.
  • Bug fixes

    • In some cases the plugin was sending multiple emails when settings were changed.
    • Image URLs in modal wizard contain extra slash.
    • Some sections of the wizard were not displayed properly on the Safari browser.
    • In some edge cases users selected the 2FA email method but they were prompted to scan a QR code when using the front-end wizard.

Refer to the complete plugin changelog for more detailed information about what was new, improved and fixed in previous version updates of WP 2FA.