Most two-factor authentication plugins for WordPress still lead with SMS and email codes. Both are now the weakest options on the menu, and NIST’s guidelines say email should not be used for this at all. Passkeys are the thing that actually changed, and only some of these plugins have them. Below is what each one supports today, what it costs, and which to install.
Quick verdict
- Best overall: Wordfence. Passkeys and authenticator-app codes are in the free plugin, there is no account to create, and you get a firewall you were probably going to install anyway.
- Best free if you only want 2FA: miniOrange 2FA. Passkeys on the free tier, unlimited users, and the passkey check happens on your own server rather than a vendor’s.
- Best for client sites you have to police: WP 2FA. Role policies and grace periods are free; trusted devices and white labelling start at $79 a year for one site.
- Skip it if the plugin’s headline feature is SMS. That is the delivery method NIST classifies as restricted, and Wordfence scheduled its own legacy SMS codes for retirement on 1 July 2026.
- Our call: install Wordfence, turn on passkeys, keep an authenticator app as the fallback, print the recovery codes. Ten minutes, no invoice.
The best two-factor authentication plugins for WordPress in 2026
Eight plugins, checked against their own listings and their vendors’ pricing pages. The column that matters most is the first one. Passkeys and WebAuthn security keys are the only methods here that a convincing fake login page cannot harvest, because the credential is bound to your domain.
| Plugin | Passkeys / WebAuthn | Other methods | Free tier | Paid, per year unless stated |
|---|---|---|---|---|
| Wordfence | Yes, free and paid | TOTP app codes, recovery codes | Everything left of this column | Paid tiers buy firewall and malware features, not login security |
| miniOrange 2FA | Yes, free | TOTP, email OTP, security questions; SMS, WhatsApp and push are paid | Unlimited users | $69, $99 or $149 a year (USD) |
| WP 2FA | Yes, free tier ambiguous | TOTP, email code, backup codes; YubiKey, SMS and Authy push are paid | Unlimited users, role policies | Premium $79–$129 a year; Enterprise $89–$199 (USD) |
| Two Factor | No. U2F removed in 0.16.0 | TOTP, email codes, backup codes | The whole plugin | No paid tier |
| Kadence Security | No | Authenticator apps, email, backup codes | 2FA is in the free plugin | Pro features only inside Kadence Pro at $299 a year (USD) |
| Two Factor Authentication (UpdraftPlus) | No | TOTP and HOTP | Full 2FA on WordPress and WooCommerce forms | From £19 per 12 months on auto-renewal, £24 manual (GBP) |
| Duo Universal | Yes, through Duo | Duo push, hardware tokens, phone callback | Duo Free covers up to 10 users | Essentials $3, Advantage $6, Premier $9 per user per month (USD) |
| Rublon MFA | WebAuthn security keys | Mobile push, TOTP, QR code, YubiKey OTP, SMS | One protected user account | Business $2 per user per month, 15 licence minimum (USD) |
Wordfence

Version 9.0.0, released on 10 August 2026, added passkey authentication to Wordfence and the changelog is explicit that it is available for both free and premium installations. That single line reshuffled this entire category. The plugin sits on more than five million active installs, which puts phishing-resistant login within reach of a very large slice of the web without anyone having to buy anything.
Key features
Passkeys, authenticator-app codes and recovery codes, enabled per role. Passkeys work on the WooCommerce account page and through custom authentication integrations, so membership sites are covered without a second plugin. There is no external service, no per-user seat, and no account to create.
Price
Free for everything described above. Wordfence sells Premium, Care and Response tiers, but what those buy is real-time firewall rules, country blocking and support response times. Login security is not behind the paywall.
Best for
Almost everyone, and especially anyone who has not yet chosen from a shortlist of WordPress security plugins. If a firewall and a scanner are on your list anyway, this removes the need for a separate 2FA plugin entirely.
Skip it if
You want a login-only plugin. Wordfence is a full suite with a firewall, a malware scanner and live traffic logging, which is a lot of moving parts to accept for a second login factor. If your host already runs a firewall at the edge, you are duplicating work you have already paid for.
miniOrange 2FA

The most interesting free tier in this roundup. miniOrange 2FA puts passkeys, authenticator apps, email OTP and security questions in the free version, for unlimited users, and its listing states that passkey and TOTP verification happen entirely on your own site with no external calls. For a plugin from a vendor whose business is identity-as-a-service, that is a more generous line than you would expect.
Key features
Passkey registration from the user profile, multiple passkeys per user, backup codes as fallback, role-based enforcement and WooCommerce 2FA, all on the free tier. Hardware keys such as YubiKey and Titan work through the same WebAuthn flow. Paid tiers add SMS, WhatsApp and Telegram OTP, push notifications, trusted devices, multisite and custom branding.
Price
Free, then $69, $99 or $149 a year on the Starter, Enterprise and All Inclusive plans. Every tier, free included, covers unlimited users. The page quotes annual pricing in USD and does not publish a separate renewal rate.
Best for
Sites that want passkeys without adopting a whole security suite, and multi-author blogs where a per-user licence would get expensive fast.
Skip it if
You are allergic to upsells. The free plugin advertises its paid methods inside the settings screens, and the paid method list is long enough that the free tier can feel like a lobby. The features it does ship free are real, but you will see the pricing page more than once.
WP 2FA

WP 2FA from Melapress is the enforcement tool. Where other plugins let users opt in, this one is built around policies: pick the roles, set a grace period, and the wizard nags everyone into compliance without them needing dashboard access. That matters the moment you are responsible for a site with contributors you cannot phone.
Key features
Role-based 2FA policies with grace periods, a setup wizard users can complete from the front end, 16-digit backup codes, editable email templates and REST endpoints for headless setups, all free. Premium adds trusted devices, YubiKey, SMS, one-click email links, WooCommerce integration, white labelling and multiple passkeys per user.
Price
Free, then Premium at $79 for one site, rising to $89 for five, $99 for ten and $129 for twenty-five. The Enterprise line runs $89, $99, $129 and $199 across the same tiers. Licences are auto-renewing annual subscriptions and the vendor publishes no separate renewal discount, so budget for the same figure next year. The page geo-switches between USD, EUR and GBP; those are the USD prices.
Best for
Agencies and anyone administering a site with more than a handful of accounts. At $79 a year for a single site it is cheaper than one support call about a compromised editor account.
Skip it if
You specifically want free passkeys. The plugin’s feature list names passkeys as a core capability and reserves multiple passkeys per user for Premium, but its own FAQ still describes the free edition as authenticator app plus email code. Confirm on a test install before you promise a client passkeys on the free tier.
Two Factor
The official Two Factor plugin is maintained under the WordPress.org account, sits on 100,000-plus installs, and is the closest thing this category has to a reference implementation. It is also the clearest example of why you have to check dates on this stuff.
Version 0.16.0, released in March 2026, removed FIDO U2F support outright. The readme is blunt about why: deprecated and removed due to loss of browser support. What did not arrive to replace it was WebAuthn. So the one plugin with WordPress in its ownership line currently offers no passkeys and no security keys at all.
Key features
TOTP, email codes and backup codes, with a dedicated settings page added in 0.16.0 that lets an admin disable providers site-wide. Clean code, no upsells, no telemetry, no dashboard banner. Roughly 200 ratings averaging near the top of the scale.
Price
Free, permanently. There is no paid edition and no vendor behind it selling one.
Best for
Developers who want the smallest possible surface area, and anyone building on top of it. If you are writing custom auth flows, this is the codebase to extend.
Skip it if
Passkeys are on your requirements list, or you need to force 2FA on a role. There is no enforcement layer here at all: every user configures their own settings from their profile, and an admin can only hide providers, not mandate them.
Kadence Security (formerly iThemes Security)

This plugin has been through three names, and the price went somewhere unpleasant on the way. The free version still carries 700,000-plus installs and still does 2FA properly: authenticator apps, email and backup codes, with per-role control and 2FA reminders you can send from the admin.
Key features
Two-factor with authenticator apps, email and backup codes; brute force protection; a vulnerability scanner; user-level security settings. QR codes for 2FA setup are now generated locally by default rather than on a vendor server, which is a genuine privacy improvement worth noting.
Price
The free plugin covers 2FA. The paid features, including passwordless magic links and Patchstack virtual patching, are no longer sold on their own. They come bundled in Kadence Pro at $299 a year or Elite at $499; the $99 Essentials tier excludes security entirely. That is more than three times what WP 2FA Premium costs for a single site.
Best for
Sites already inside the Kadence ecosystem, where the bundle maths works out. If you are buying the theme and the blocks anyway, the security plugin arrives free.
Skip it if
You want passkeys, or you want to buy security on its own. There is no WebAuthn support here, and the standalone licence that made this plugin an easy recommendation has gone. Pair it with real brute-force protection and you have a good free stack; pay $299 for the 2FA and you have overpaid.
Two Factor Authentication by UpdraftPlus

Old, small and unusually well-behaved. This plugin has been in the directory since 2015, sits on 20,000-plus installs, and does one thing: standard TOTP and HOTP one-time codes, applied wherever your site’s login form happens to live. Note what is absent from that list. Its listing names no SMS option at all, despite years of roundups claiming otherwise.
Key features
TOTP and HOTP, per-role availability, a shortcode so users can manage their own settings without dashboard access, and encryption of the secret keys against an on-disk key so a database dump alone is not enough to forge codes. Free support covers WooCommerce, Theme My Login, AffiliatesWP and Profile Builder forms.
Price
Free, with Premium from £19 per 12 months on an auto-renewing subscription, or £24 if you renew manually. Five sites cost £29 and £39; twenty-five sites cost £59 and £69. Simba Hosting prices in pounds, so do not try to line these up against the dollar figures elsewhere on this page.
Best for
Sites with unusual login forms. Premium reaches Elementor Pro, bbPress, Ultimate Member, Easy Digital Downloads, Gravity Forms registration and Paid Memberships Pro, plus a catch-all that appends the code to the password for any form at all. That list of named integrations is the reason to choose this one.
Skip it if
You need passkeys or hardware keys. This is a one-time-code plugin and makes no pretence otherwise.
Duo Universal

Not really a WordPress plugin so much as a bridge. Duo Universal hands your login off to Duo’s hosted prompt, which then handles passkeys, biometrics, hardware tokens or push. If your organisation already runs Duo for the VPN and the laptops, this makes WordPress one more app behind the same policy engine. If it does not, you are adopting an identity platform to protect a blog.
Key features
Passkeys, biometrics, hardware tokens and phone-based methods through the Universal Prompt, with enrolment and policy managed centrally in Duo rather than per-site. Published by Duo Security themselves, so it will not be abandoned quietly.
Price
The plugin is free. Duo Free covers up to 10 users at no charge, which is enough for most agency teams. Above that, Essentials is $3 per user per month, Advantage $6 and Premier $9. At $3 a month a single user works out at $36 a year, and the bill grows with headcount rather than with sites.
Best for
Agencies and companies already standardised on Duo, where WordPress joins a policy engine that is already paid for and already understood by the people who have to use it.
Skip it if
You run one site with one admin, or you have clients who will not tolerate a third party in the login path. Note also that this plugin has 2,000 installs and one rating, and was last updated in January 2026, so it moves more slowly than the rest of this list.
Rublon MFA

The same hosted-service pattern as Duo, aimed at organisations that need MFA across VPNs and servers as well as WordPress. The plugin is well maintained and supports WebAuthn security keys, mobile push, TOTP, QR codes and YubiKey OTP behind a single prompt with a remember-this-device option.
Key features
One prompt, many methods, with self-enrolment built in so users bind their own device or security key at first login. Trusted-device bypass, and central policy across every application you connect, with WordPress as just one of them.
Price
Rublon Free protects exactly one user account, which is enough for a solo admin and nothing more. Business is $2 per user per month with a 15-licence minimum, so the real entry price is $360 a year. Enterprise is $4 per user per month with a 300-licence minimum.
Best for
Organisations already buying MFA for infrastructure, where WordPress is the fifth application on a list rather than the whole project.
Skip it if
You are a freelancer or a small team. The 15-licence floor makes the second user cost $360 a year, and the plugin’s 400 active installs tell you how many WordPress sites have concluded the same thing.
What most 2FA roundups get wrong
They still recommend SMS
NIST’s digital identity guidelines classify authentication over the public telephone network as restricted, and tell verifiers to weigh risk indicators such as device swap, SIM change and number porting before sending a code that way. Wordfence acted on the same reasoning: its 8.2.0 changelog announced that legacy SMS two-factor codes would be discontinued around 1 July 2026 and told sites to migrate users to app-based codes. If a plugin’s marketing leads with SMS, that is a signal about the plugin, not about your threat model.
They treat email codes as a real second factor
This one is worse, because it is nearly universal. NIST SP 800-63B states that email shall not be used for out-of-band authentication, listing interception in transit, rerouting attacks and access using only a password as the reasons. The last one is the killer: if the attacker has the password, and the password manager holding it also holds the email login, the second factor is not a second factor. Email codes are the default free fallback in Two Factor, WP 2FA and Kadence Security. Use them as account recovery, not as your second step.
They still list Wordfence Login Security
The standalone Wordfence Login Security plugin was closed on WordPress.org in August 2026 at the author’s request, and Wordfence 9.0.0’s scanner now raises an issue if it finds it installed, because the main plugin already provides everything it did. Any article still recommending it as a separate download is out of date. If it is on your site, deactivate it and let Wordfence handle login security.
They sell passkeys as bulletproof
Passkeys are the best option on this page because the credential is bound to your domain, so a phishing page on a lookalike URL gets nothing to replay. They are not magic. NIST will not accept syncable passkeys at its highest assurance level, because the private key has to be exportable for the sync to work at all. For a food blog that is irrelevant. For a client with compliance obligations it is a conversation, and the answer is a hardware key rather than a synced credential.
They never mention who 2FA actually locks out
You. Overwhelmingly, you. In practice the most common 2FA incident is an admin who reinstalled their phone without exporting their authenticator, not an attacker turned away at the door. Print the recovery codes, store them somewhere that is not the site, and keep a current backup before you enforce anything on anyone else.
What breaks, and how to not find out the hard way
- Custom login forms. WooCommerce, membership plugins and page-builder login widgets often bypass the standard hooks, so the second factor silently never fires. Test the actual form your users see, not
wp-login.php. - Full-page caching. If a caching plugin serves a cached login or account page, the 2FA prompt breaks in ways that look random. Exclude the login page and the account pages, then clear the cache.
- Passkeys and staging URLs. A passkey is bound to a domain. One created on
staging.example.comwill not work onexample.com. Enrol users after go-live, and test the flow on a throwaway copy first if you use InstaWP or similar. - Two plugins at once. Do not. Wordfence 9.0.0 shipped a hardening fix specifically for sites running it alongside plugins with non-standard authentication, which tells you how often this goes wrong.
- Phone numbers you now have to protect. Turning on SMS means storing user phone numbers, which are personal data with GDPR obligations attached. Another reason not to bother.
Which one should you actually install
- One site, one or two admins, no firewall yet. Wordfence. Passkeys on, app codes as fallback, done.
- One site, you already have a firewall you like. miniOrange 2FA free. You get passkeys without a second security suite fighting the first.
- Client sites, contributors you need to force into compliance. WP 2FA. Free tier for the policies, Premium at $79 a year for one site if you need trusted devices or white labelling.
- A membership or WooCommerce store with an unusual login form. The UpdraftPlus plugin, Premium tier, for its long list of named form integrations.
- A team of ten or fewer who already use Duo elsewhere. Duo Universal on the free tier, if your clients will accept a hosted prompt in the login path.
- You are building something custom. The Two Factor plugin, and accept that you are adding WebAuthn yourself.
Whatever you pick, remember what 2FA does not do. It stops a stolen password on its own from being enough. It does nothing about a vulnerable plugin, a compromised host account or a backdoor already sitting in your uploads folder. If the site has been misbehaving, run a malware scan before you lock the front door, and keep spam registrations under control if you allow public signups, because 2FA does not care how many fake accounts exist.
Frequently Asked Questions
Is SMS two-factor authentication still safe for WordPress?
It is the weakest option you can pick. NIST’s guidelines classify authentication over the phone network as restricted and tell verifiers to watch for SIM changes and number porting first. Wordfence scheduled its own legacy SMS codes for retirement on 1 July 2026. Use an authenticator app or a passkey instead.
Are email 2FA codes good enough?
No. NIST’s guidelines state that email shall not be used for out-of-band authentication, because the inbox is often protected by the same password you are trying to back up. Email codes are still the default fallback in several free plugins. Treat them as recovery, not as a second factor.
Do you need passkeys, or is an authenticator app enough?
An authenticator app is a large improvement over nothing and stops credential stuffing dead. Passkeys go further because the credential is bound to the site’s domain, so a convincing fake login page gets nothing to replay. If your plugin offers both, enable passkeys and keep app codes as the fallback.
What do passkeys need to work on a WordPress site?
HTTPS on the real domain, plus a browser that supports WebAuthn, which every current version of Chrome, Safari, Edge and Firefox does. Passkeys are bound to a domain, so one created on a staging URL will not work on production. Enrol users after the site goes live.
What happens if you lose your phone and get locked out?
Recovery codes, if you saved them. Generate and print them before you enable anything, because almost nobody does. Failing that, disable the plugin over SFTP by renaming its folder inside wp-content/plugins, or clear the 2FA user meta in the database. Both routes need host-level access.
Will a 2FA plugin break WooCommerce or membership logins?
It can. Custom login forms bypass the standard WordPress hooks, so the second factor never fires. Wordfence covers WooCommerce in its free plugin, WP 2FA puts WooCommerce integration behind Premium, and the UpdraftPlus plugin reaches Elementor Pro and bbPress forms only in its paid version. Test on staging first.
Can you run two 2FA plugins at once?
Do not. Two plugins hooking the same authentication filters is a documented source of trouble; Wordfence 9.0.0 specifically hardened its 2FA flow against plugins with non-standard authentication. Pick one, deactivate the other, and clear any half-configured credentials from user profiles before you enforce anything.
Does two-factor authentication slow a site down?
Not for visitors. The second factor only runs on the login and account pages, which are never cached and which most visitors never touch. What it can affect is your caching setup: if a full-page cache serves the login or account page, the prompt breaks. Exclude both.
Do you need to pay for a 2FA plugin at all?
Most sites do not. Wordfence and miniOrange both give you passkeys and authenticator-app codes for nothing, with no user cap. You start paying when you need trusted devices, white-labelled prompts for client sites, WooCommerce customer 2FA in some plugins, or hardware keys such as YubiKey.
Our call
Install Wordfence. That is the answer for the large majority of WordPress sites reading this, and it became the answer in August 2026 when passkeys landed in the free plugin. You get the strongest available second factor, an authenticator-app fallback, WooCommerce coverage and a firewall, for nothing, from a vendor with five million installs’ worth of reasons to keep it working.
If you specifically do not want a security suite, miniOrange 2FA free gives you the same passkey support with a much smaller footprint. If you are policing other people’s accounts, WP 2FA at $79 a year for one site is the tool built for that job. Everything else on this page is a good answer to a narrower question.
Then do the boring part: enable passkeys, keep app codes as the backup, print the recovery codes, and turn off the email option. The last one is the change most sites still have not made.





[…] for: anyone who wants one plugin to cover the firewall, the scanner and two-factor authentication for WordPress logins without stitching three tools […]
[…] firewall, file-integrity scanner, repair of core and repository files from clean originals, two-factor authentication, live traffic view, rate limiting.Price: free tier is complete and genuinely usable. Paid tier […]
[…] enough; it does not stop the flood of guesses. That is a separate purchase decision, covered in our two-factor authentication plugins […]