Title: WP 2FA &#8211; Two-factor authentication for WordPress
Author: Melapress
Published: <strong>Werurwe 20, 2020</strong>
Last modified: Nyakanga 21, 2026

---

Search plugins

![](https://ps.w.org/wp-2fa/assets/banner-772x250.png?rev=3270687)

![](https://ps.w.org/wp-2fa/assets/icon-256x256.png?rev=2961533)

# WP 2FA – Two-factor authentication for WordPress

 By [Melapress](https://profiles.wordpress.org/melapress/)

[Download](https://downloads.wordpress.org/plugin/wp-2fa.4.1.0.zip)

 * [Details](https://kin.wordpress.org/plugins/wp-2fa/#description)
 * [Reviews](https://kin.wordpress.org/plugins/wp-2fa/#reviews)
 * [Development](https://kin.wordpress.org/plugins/wp-2fa/#developers)

 [Support](https://wordpress.org/support/plugin/wp-2fa/)

## Description

### A free and easy-to-use two-factor authentication plugin for WordPress

Add an extra layer of security to your WordPress website login and protect your 
users. Enable two-factor authentication (2FA), the best protection against password
leaks, automated password guessing, and brute force attacks.

Use the WP 2FA plugin to enable two-factor authentication for your WordPress administrator,
enforce 2FA for all your website users, or for users with specific roles. This plugin
is very easy to use; everything can be configured via wizards with clear instructions,
so even non-technical users can set up 2FA without requiring technical assistance.

[Features](https://melapress.com/wordpress-2fa/features/?utm_source=wp+repo&utm_medium=repo+link&utm_campaign=wordpress_org&utm_content=wp2fa)
| [Getting Started](https://melapress.com/support/kb/wp-2fa-plugin-getting-started/?utm_source=wp+repo&utm_medium=repo+link&utm_campaign=wordpress_org&utm_content=wp2fa)
| [Get the Premium!](https://melapress.com/wordpress-2fa/pricing/?utm_source=wp+repo&utm_medium=repo+link&utm_campaign=wordpress_org&utm_content=wp2fa)

### 🔒 WP 2FA key plugin features and capabilities

 * **Passkeys support** for passwordless logins
 * **Free two-factor authentication (2FA)** for all users
 * **Multiple 2FA methods** supported, including authenticator app (TOTP) and code
   over email
 * **Developer API** to integrate any alternative 2FA method (WhatsApp, OTP Token,
   etc.)
 * **Universal 2FA app support** – works with Google Authenticator, Authy, and any
   TOTP-compatible app
 * **Backup codes** (16 digits) for recovery access
 * **Wizard-driven setup** – no technical knowledge required
 * **2FA policies** to enforce setup with grace periods or instant activation
 * **REST API endpoints** for custom integrations and headless WordPress setups
 * **Dashboard-free setup** – users can configure 2FA without WP admin access
 * **Editable email templates** for full customization
 * **Much more!**

### 💎 Upgrade to WP 2FA Premium and get even more benefits

The premium version of WP 2FA comes bundled with even more features to take your
WordPress website login security to the next level.

With the premium edition of WP 2FA, you get more 2FA methods, 1-click integration
with WooCommerce, trusted devices feature, extensive white labeling capabilities,
and much more!

[Check out WP 2FA Premium!](https://melapress.com/wordpress-2fa/pricing/?utm_source=wp+repo&utm_medium=repo+link&utm_campaign=wordpress_org&utm_content=wp2fa)

### Premium features list

 * **Everything in the free version**
 * **Full white labeling capabilities** to change all text and visuals in the wizards,
   emails, SMS, and 2FA pages
 * **Support for multiple passkeys per user** for flexible passwordless logins
 * **Zero-setup email 2FA** that automatically enrolls users without manual configuration
 * **YubiKey hardware key support** for enterprise-grade security
 * **Additional 2FA methods** such as SMS, email link, and more
 * **Trusted devices** so users can log in without 2FA for a configured period
 * **Require 2FA on password reset** to strengthen account protection
 * **Allow next user login without 2FA** to help recover accounts locked out of 
   authentication
 * **One-click WooCommerce integration** to enable 2FA for customers and store admins
 * **And much more!**

Refer to the [WP 2FA plugin features and benefits page](https://melapress.com/wordpress-2fa/features/?utm_source=wp+repo&utm_medium=repo+link&utm_campaign=wordpress_org&utm_content=wp2fa)
to learn more about the benefits of upgrading to WP 2FA Premium.

### 🛠️ Free and premium support

Support for the free edition of WP 2FA is free on the [WordPress support forums](https://wordpress.org/support/plugin/wp-2fa/).
Premium world-class support via one-to-one email is available to the Premium users–
[upgrade to premium](https://melapress.com/wordpress-2fa/pricing/?utm_source=wp+repo&utm_medium=repo+link&utm_campaign=wordpress_org&utm_content=wp2fa)
to benefit from email support.

For any other queries, feedback, or if you simply want to get in touch with us, 
please use our [contact form](https://melapress.com/contact/?utm_source=wp+repo&utm_medium=repo+link&utm_campaign=wordpress_org&utm_content=wp2fa).

#### MAINTAINED & SUPPORTED BY MELAPRESS

Melapress develops high-quality WordPress management and security plugins, such 
as Melapress Login Security, Melapress Role Editor, and WP Activity Log; the #1 
user-rated activity log plugin for WordPress.

Browse our list of [WordPress security and administration plugins](https://melapress.com/?utm_source=wp+repo&utm_medium=repo+link&utm_campaign=wordpress_org&utm_content=wp2fa)
to see how our plugins can help you better manage and improve the security and administration
of your WordPress websites and users.

### Installing WP 2FA

### From within WordPress

 1. Navigate to ‘Plugins’ > ‘Add New’
 2. Search for ‘WP 2FA’
 3. Install & activate WP 2FA from your Plugins page

### Manually

 1. Download the plugin from the WordPress plugins repository
 2. Unzip the zip file and upload the folder to the ‘/wp-content/plugins/ directory’
 3. Activate the WP 2FA plugin through the ‘Plugins’ menu in WordPress

### As featured on:

 * [WP Beginner](https://www.wpbeginner.com/plugins/how-to-add-two-factor-authentication-for-wordpress/)
 * [IsitWP](https://www.isitwp.com/best-wordpress-security-authentication-plugins/)
 * [WP Astra](https://wpastra.com/two-factor-authentication-wordpress/)
 * [MainWP](https://mainwp.com/how-to-use-the-wp-2fa-plugin-on-your-child-sites/)
 * [FixRunner](https://www.fixrunner.com/wordpress-two-factor-authentication/)
 * [Inmotion Hosting](https://www.inmotionhosting.com/support/edu/wordpress/plugins/wp-2fa/)
 * [WP Marmite](https://wpmarmite.com/en/wordpress-two-factor-authentication/)

## Screenshots

[⌊The first-time install wizard allows you to set up 2FA on your website and for
your users within seconds.⌉⌊The first-time install wizard allows you to set up 2FA
on your website and for your users within seconds.⌉[

The first-time install wizard allows you to set up 2FA on your website and for your
users within seconds.

[⌊The wizards make setting up 2FA very easy, so even non-technical users can set
up 2FA without requiring help.⌉⌊The wizards make setting up 2FA very easy, so even
non-technical users can set up 2FA without requiring help.⌉[

The wizards make setting up 2FA very easy, so even non-technical users can set up
2FA without requiring help.

[⌊Setting up Passkeys is also a straightforward in WP 2FA. The users just have to
follow the step by step instructions.⌉⌊Setting up Passkeys is also a straightforward
in WP 2FA. The users just have to follow the step by step instructions.⌉[

Setting up Passkeys is also a straightforward in WP 2FA. The users just have to 
follow the step by step instructions.

[⌊You can require users to enable 2FA and also give them a grace period to do so.⌉⌊
You can require users to enable 2FA and also give them a grace period to do so.⌉[

You can require users to enable 2FA and also give them a grace period to do so.

[⌊Users can also use one-time codes via email as a two-factor authentication method.⌉⌊
Users can also use one-time codes via email as a two-factor authentication method
.⌉[

Users can also use one-time codes via email as a two-factor authentication method.

[⌊Users can configure and use Passkeys to log in to the website when using WP 2FA.⌉⌊
Users can configure and use Passkeys to log in to the website when using WP 2FA.⌉[

Users can configure and use Passkeys to log in to the website when using WP 2FA.

[⌊Users can easily manage their Passkeys from their user profile page.⌉⌊Users can
easily manage their Passkeys from their user profile page.⌉[

Users can easily manage their Passkeys from their user profile page.

[⌊You can use policies to require users to instantly set up and use 2FA, so the 
next time they log in, they will be prompted with this.⌉⌊You can use policies to
require users to instantly set up and use 2FA, so the next time they log in, they
will be prompted with this.⌉[

You can use policies to require users to instantly set up and use 2FA, so the next
time they log in, they will be prompted with this.

[⌊You can give users a grace period until they configure 2FA. You can also specify
what the plugin should do once the grace period is over.⌉⌊You can give users a grace
period until they configure 2FA. You can also specify what the plugin should do 
once the grace period is over.⌉[

You can give users a grace period until they configure 2FA. You can also specify
what the plugin should do once the grace period is over.

[⌊It is recommended for all users to also generate backup codes, in case they cannot
access the primary device.⌉⌊It is recommended for all users to also generate backup
codes, in case they cannot access the primary device.⌉[

It is recommended for all users to also generate backup codes, in case they cannot
access the primary device.

[⌊In the user profile, users only have a few 2FA options, so it is not confusing
for them, and everything is self-explanatory.⌉⌊In the user profile, users only have
a few 2FA options, so it is not confusing for them, and everything is self-explanatory
.⌉[

In the user profile, users only have a few 2FA options, so it is not confusing for
them, and everything is self-explanatory.

## FAQ

### Does the plugin send any data to Melapress?

No, the plugin does not send any data to us whatsoever. The only data we receive
is license data from the premium edition of the plugin.

### What 2FA methods are available with the plugin?

The free edition of WP 2FA includes the following 2FA methods: Authenticator app
2FA and code over email. This allows you to use Google Authenticator OTP The premium
edition adds YubiKey, one-click email link, SMS 2FA, and Authy push notifications.

### How can I integrate two-factor authentication (2FA) into my custom login process or AJAX-based form?

WP 2FA includes a REST API that allows developers to enable and verify 2FA during
custom authentication flows, such as AJAX-based login forms, mobile apps, or headless
WordPress websites. Refer to the [REST API in WP 2FA documentation](https://melapress.com/support/kb/wp-2fa-rest-api/?utm_source=wp+repo&utm_medium=repo+link&utm_campaign=wordpress_org&utm_content=wp2fa)
for more information.

### How can I ensure I do not get locked out?

WP 2FA includes backup authentication methods so that if the primary authentication
method fails, you and your users can still log in. The free version of the plugin
includes backup codes, which can be configured during 2FA configuration or at any
point after that from the profile page. The premium edition adds 2FA backup codes
over email.

### What happens if I get locked out?

In the unlikely event that you are unable to supply your 2FA code, there are several
steps you can take to gain access to your WordPress dashboard. First, check if there
is another administrator who can reset your 2FA. If this is not possible, manually
deactivate the plugin, log in without 2FA, re-activate the plugin, and then reconfigure
your 2FA.

### Does WP 2FA support multi-site networks?

Yes, WP 2FA is multisite compatible. The plugin can be activated at the network 
level. 2FA policies can be enforced on all users, a subsection of users, or per 
site on the network. It also supports network setups with different domains.

### Does the plugin receive updates?

We update the plugin fairly regularly to ensure the plugin continues to run in tip-
top shape while adding new features from time to time.

### Does the plugin support Google Authenticator?

Yes, WP 2FA fully supports Google Authenticator on WordPress. [WP 2FA also supports many other 2FA authenticator apps](https://melapress.com/support/kb/wp-2fa-configuring-2fa-apps/?utm_source=wp+repo&utm_medium=repo+link&utm_campaign=wordpress_org&utm_content=wp2fa).

### Can I get support if I get stuck?

Support for the free edition of the plugin is provided only via the WordPress.org
support forums. You can also refer to our [support pages](https://melapress.com/support/?utm_source=wp+repo&utm_medium=repo+link&utm_campaign=wordpress_org&utm_content=wp2fa)
for all the technical and product documentation.

If you are using the Premium edition, you get direct access to our support team 
via one-to-one [email support](https://melapress.com/support/submit-ticket/?utm_source=wp+repo&utm_medium=repo+link&utm_campaign=wordpress_org&utm_content=mls).

### How can I report security bugs?

You can report security bugs through the Patchstack Vulnerability Disclosure Program.
Please use this [form](https://patchstack.com/database/vdp/wp-2fa). For more details,
please refer to our [Melapress plugins security program](https://melapress.com/plugins-security-program/).

## Reviews

![](https://secure.gravatar.com/avatar/a0a16688cf30e36751be0ed50cf151bc506165ac56dc3e5cce7848e01609e123?
s=60&d=retro&r=g)

### 󠀁[Highly recommended!](https://wordpress.org/support/topic/highly-recommended-788/)󠁿

 [jero5566](https://profiles.wordpress.org/jero5566/) Nyakanga 15, 2026 1 reply

​”Highly recommended! The support team is incredibly professional, warm, and patient.
They took the time to guide me step-by-step to resolve my issues. I strongly recommend
everyone to upgrade to the Premium version—the paid features are extremely convenient,
powerful, and easy to use. It is absolutely worth every penny!”

![](https://secure.gravatar.com/avatar/555e08197e5a8b6b450f765e37fad69e2ad12a292b9c2a26a7e2a3a28c1be59c?
s=60&d=retro&r=g)

### 󠀁[Great Support](https://wordpress.org/support/topic/great-support-6677/)󠁿

 [alan](https://profiles.wordpress.org/f1alan/) Nyakanga 14, 2026 1 reply

The plugin is very easy to use but the best thing about it is that they are very
responsive and helpful on the support forum which cannot be taken for granted with
WordPress plugins.

![](https://secure.gravatar.com/avatar/f5d9aa88d12585389b3cdafaf12a79674a565bd378a049b68ed1e6693d65a388?
s=60&d=retro&r=g)

### 󠀁[Great Plugin!](https://wordpress.org/support/topic/great-plugin-41631/)󠁿

 [logandev](https://profiles.wordpress.org/logandev/) Nyakanga 13, 2026 1 reply

Super helpful and gives you an extra layer of security!

![](https://secure.gravatar.com/avatar/1e67dd57f9d059fd0d60f89b6ed37b173e2948519cdadc05345d2748293be9d8?
s=60&d=retro&r=g)

### 󠀁[Quick Response, most helpful](https://wordpress.org/support/topic/quick-response-most-helpful/)󠁿

 [sd360](https://profiles.wordpress.org/sd360/) Nyakanga 10, 2026 1 reply

support helped us pinpoint the issue with had – there was a conflict with our customised
code, we will use this plugin again once we sort out our own code. Thanks for your
speedy response!

![](https://secure.gravatar.com/avatar/700d86b9cd928dca97f9b100650fbff46af292b53e0707988e31f5518807d99f?
s=60&d=retro&r=g)

### 󠀁[Great Support](https://wordpress.org/support/topic/great-support-6663/)󠁿

 [maximecassebras](https://profiles.wordpress.org/maximecassebras/) Kamena 28, 2026
1 reply

Perfect, great support

![](https://secure.gravatar.com/avatar/caed692fad04c42a8edad1e67f2918b4dda5f428c8217835af4766e1fea35dc0?
s=60&d=retro&r=g)

### 󠀁[Exactly what’s needed, simple UI, always works](https://wordpress.org/support/topic/exactly-whats-needed-simple-ui-always-works/)󠁿

 [artkarr](https://profiles.wordpress.org/artkarr/) Gicurasi 12, 2026 1 reply

Great plugin that does what it says! We use it for multiple sites and never had 
issues. I recommend this for any WP site.

 [ Read all 173 reviews ](https://wordpress.org/support/plugin/wp-2fa/reviews/)

## Contributors & Developers

“WP 2FA – Two-factor authentication for WordPress” is open source software. The 
following people have contributed to this plugin.

Contributors

 *   [ Melapress ](https://profiles.wordpress.org/melapress/)
 *   [ robertabela ](https://profiles.wordpress.org/robert681/)

“WP 2FA – Two-factor authentication for WordPress” has been translated into 14 locales.
Thank you to [the translators](https://translate.wordpress.org/projects/wp-plugins/wp-2fa/contributors)
for their contributions.

[Translate “WP 2FA – Two-factor authentication for WordPress” into your language.](https://translate.wordpress.org/projects/wp-plugins/wp-2fa)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/wp-2fa/), check out
the [SVN repository](https://plugins.svn.wordpress.org/wp-2fa/), or subscribe to
the [development log](https://plugins.trac.wordpress.org/log/wp-2fa/) by [RSS](https://plugins.trac.wordpress.org/log/wp-2fa/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 4.1.0 (2026-07-21)

 * **New functionality**
    - Added an option to customize the OTP code validity period for zero-setup 2FA.
 * **Functionality & plugin improvements**
    - Improved email delivery guidance and test email error messages, with clearer
      troubleshooting information and links to the email deliverability documentation.
    - Improved the front-end 2FA settings validation message and styling when the
      page slug has not been configured.
    - Authy OneTouch approval requests are now validated entirely server-side. Approval
      identifiers are single-use and are no longer exposed to the browser.
    - Moved the user profile backup-method link customization to the relevant user
      profile section of the white labeling settings.
    - Improved the login error shown when an unexpected issue prevents 2FA verification.
    - Improved spacing between the **Add Passkey** button and the passkeys table
      when the backup methods information link is displayed.
 * **Bug fixes**
    - Fixed the **Customize email templates** heading on the white labeling page.
    - Fixed Twilio SMS delivery failures after upgrading to version 4.0, which could
      prevent users from receiving login or setup codes even when their Twilio credentials
      verified successfully.
    - Fixed missing **Edit Page** and **View Page** buttons in the Premium edition’s
      front-end settings page.
    - Fixed the **Bypass 2FA when logging in with passkeys** setting being disabled
      when switching between REST and native passkey modes.
    - Fixed the new-interface announcement modal repeatedly appearing because the
      selected option could not be saved.
    - Fixed passkey registration failing after closing and reopening the **Add a
      Passkey** modal in the same browser tab.
    - Fixed the **Remember this device** checkbox being unresponsive on WooCommerce
      login forms in the Premium edition until a failed verification attempt occurred.
 * **Security fix**
 * Fixed a passkeys bypass issue in the classic login flow reported by Jakub Herman.

Refer to the complete [plugin changelog](https://melapress.com/support/kb/wp-2fa-plugin-changelog/?utm_source=wordpress.org&utm_medium=referral&utm_campaign=WP2FA&utm_content=plugin+repos+description)
for more detailed information about what was new, improved and fixed in previous
version updates of WP 2FA.

## Meta

 *  Version **4.1.0**
 *  Last updated **13 hours ago**
 *  Active installations **100,000+**
 *  WordPress version ** 5.5 or higher **
 *  Tested up to **7.0.2**
 *  PHP version ** 7.4 or higher **
 *  Languages
 * [Dutch](https://nl.wordpress.org/plugins/wp-2fa/), [English (US)](https://wordpress.org/plugins/wp-2fa/),
   [Finnish](https://fi.wordpress.org/plugins/wp-2fa/), [German](https://de.wordpress.org/plugins/wp-2fa/),
   [Greek](https://el.wordpress.org/plugins/wp-2fa/), [Japanese](https://ja.wordpress.org/plugins/wp-2fa/),
   [Polish](https://pl.wordpress.org/plugins/wp-2fa/), [Romanian](https://ro.wordpress.org/plugins/wp-2fa/),
   [Russian](https://ru.wordpress.org/plugins/wp-2fa/), [Spanish (Chile)](https://cl.wordpress.org/plugins/wp-2fa/),
   [Spanish (Colombia)](https://es-co.wordpress.org/plugins/wp-2fa/), [Spanish (Ecuador)](https://es-ec.wordpress.org/plugins/wp-2fa/),
   [Spanish (Spain)](https://es.wordpress.org/plugins/wp-2fa/), [Spanish (Venezuela)](https://ve.wordpress.org/plugins/wp-2fa/),
   and [Swedish](https://sv.wordpress.org/plugins/wp-2fa/).
 *  [Translate into your language](https://translate.wordpress.org/projects/wp-plugins/wp-2fa)
 * Tags
 * [2-factor authentication](https://kin.wordpress.org/plugins/tags/2-factor-authentication/)
   [2FA](https://kin.wordpress.org/plugins/tags/2fa/)[google authenticator](https://kin.wordpress.org/plugins/tags/google-authenticator/)
   [two factor authentication](https://kin.wordpress.org/plugins/tags/two-factor-authentication/)
   [WordPress authentication](https://kin.wordpress.org/plugins/tags/wordpress-authentication/)
 *  [Advanced View](https://kin.wordpress.org/plugins/wp-2fa/advanced/)

## Ratings

 4.7 out of 5 stars.

 *  [  156 5-star reviews     ](https://wordpress.org/support/plugin/wp-2fa/reviews/?filter=5)
 *  [  3 4-star reviews     ](https://wordpress.org/support/plugin/wp-2fa/reviews/?filter=4)
 *  [  0 3-star reviews     ](https://wordpress.org/support/plugin/wp-2fa/reviews/?filter=3)
 *  [  2 2-star reviews     ](https://wordpress.org/support/plugin/wp-2fa/reviews/?filter=2)
 *  [  12 1-star reviews     ](https://wordpress.org/support/plugin/wp-2fa/reviews/?filter=1)

[Your review](https://wordpress.org/support/plugin/wp-2fa/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/wp-2fa/reviews/)

## Contributors

 *   [ Melapress ](https://profiles.wordpress.org/melapress/)
 *   [ robertabela ](https://profiles.wordpress.org/robert681/)

## Support

Issues resolved in last two months:

     3 out of 4

 [View support forum](https://wordpress.org/support/plugin/wp-2fa/)