Just another contact form plugin. Simple but flexible.
About WP 2FA – Two-factor authentication for WordPress
The WP 2FA plugin is a free and easy-to-use two-factor authentication solution for WordPress websites. It adds an extra layer of security to your login process, protecting against password leaks, automated guessing, and brute force attacks. With the premium version, you get even more features such as additional 2FA methods, white labeling capabilities, and integration with WooCommerce.Screenshots











Frequently asked questions
What is WP 2FA?
WP 2FA is a free and easy-to-use WordPress plugin that adds two-factor authentication (2FA) to your website. It helps protect against password leaks, automated password guessing, and brute force attacks. The plugin allows you to enable 2FA for administrators, all users, or users with specific roles.
What 2FA methods does WP 2FA support?
WP 2FA supports multiple 2FA methods, including authenticator app TOTP and code over email. It also has an API to integrate alternative 2FA methods like WhatsApp or OTP tokens. The plugin supports universal 2FA apps such as Google Authenticator and Authy.
Does WP 2FA offer backup codes?
Yes, WP 2FA supports 2FA backup codes. This feature provides a way for users to log in if they lose access to their primary 2FA method.
Can I enforce 2FA for my users?
Yes, you can use 2FA policies to enforce 2FA for your users. You can set a grace period or require users to instantly set up 2FA upon logging in. Users do not need WordPress dashboard access to set up 2FA.
Changelog
2.8.0 (2024-07-17)
-
New features
-
Out of the box support for Yubico – use any YubiKey hardware key by Yubico as a 2FA method to log in to your WordPress website.
- Plugin & functionality improvements
- Bumped up the minimum supported PHP version from 7.2 to 7.3.
- Updated a number of strings in the settings + improved help text.
- The names of debug log file in uploads directory are now randomized.
- Updated the default text in different sections of the wizard to simplify things and improve UX.
- Adjusted the order in which the 2FA methods are listed.
- Updated the features’ page in the plugin – added the new features etc.
-
Updated all UTM parameters in the plugin’s URLs and links.
- Bug fixes
- Fixed: PHP fatal error in class-email-wizard-steps.php in some edge cases.
- Fixed: Apostrophe character shows up as ASCII in email subject.
- Fixed: Error with importing plugin’s settings from one website to another in some edge cases.
- Fixed: The grace period expiration setting did not have a default value / setting.
- Removed reference to Premium backup methods in the free edition’s wizard.
- Fixed: Redirecting to frontend 2FA page without permalinks set up does not work.
- Fixed: Some user profile 2FA buttons were not functioning properly when used on mobile.
- Fixed: Data was not always / all deleted when the setting “Delete data upon uninstall” was enabled.
-
Refer to the complete plugin changelog for more detailed information about what was new, improved and fixed in previous version updates of WP 2FA.
