Best Two-Factor Authentication Plugins for WordPress

Most two-factor authentication plugins for WordPress still lead with SMS and email codes. Both are now the weakest options on the menu, and NIST’s guidelines say email should not be used for this at all. Passkeys are the thing that actually changed, and only some of these plugins have them. Below is what each one supports today, what it costs, and which to install.

Quick verdict

  • Best overall: Wordfence. Passkeys and authenticator-app codes are in the free plugin, there is no account to create, and you get a firewall you were probably going to install anyway.
  • Best free if you only want 2FA: miniOrange 2FA. Passkeys on the free tier, unlimited users, and the passkey check happens on your own server rather than a vendor’s.
  • Best for client sites you have to police: WP 2FA. Role policies and grace periods are free; trusted devices and white labelling start at $79 a year for one site.
  • Skip it if the plugin’s headline feature is SMS. That is the delivery method NIST classifies as restricted, and Wordfence scheduled its own legacy SMS codes for retirement on 1 July 2026.
  • Our call: install Wordfence, turn on passkeys, keep an authenticator app as the fallback, print the recovery codes. Ten minutes, no invoice.

The best two-factor authentication plugins for WordPress in 2026

Eight plugins, checked against their own listings and their vendors’ pricing pages. The column that matters most is the first one. Passkeys and WebAuthn security keys are the only methods here that a convincing fake login page cannot harvest, because the credential is bound to your domain.

PluginPasskeys / WebAuthnOther methodsFree tierPaid, per year unless stated
WordfenceYes, free and paidTOTP app codes, recovery codesEverything left of this columnPaid tiers buy firewall and malware features, not login security
miniOrange 2FAYes, freeTOTP, email OTP, security questions; SMS, WhatsApp and push are paidUnlimited users$69, $99 or $149 a year (USD)
WP 2FAYes, free tier ambiguousTOTP, email code, backup codes; YubiKey, SMS and Authy push are paidUnlimited users, role policiesPremium $79–$129 a year; Enterprise $89–$199 (USD)
Two FactorNo. U2F removed in 0.16.0TOTP, email codes, backup codesThe whole pluginNo paid tier
Kadence SecurityNoAuthenticator apps, email, backup codes2FA is in the free pluginPro features only inside Kadence Pro at $299 a year (USD)
Two Factor Authentication (UpdraftPlus)NoTOTP and HOTPFull 2FA on WordPress and WooCommerce formsFrom £19 per 12 months on auto-renewal, £24 manual (GBP)
Duo UniversalYes, through DuoDuo push, hardware tokens, phone callbackDuo Free covers up to 10 usersEssentials $3, Advantage $6, Premier $9 per user per month (USD)
Rublon MFAWebAuthn security keysMobile push, TOTP, QR code, YubiKey OTP, SMSOne protected user accountBusiness $2 per user per month, 15 licence minimum (USD)
Methods, versions and install counts checked against each plugin’s WordPress.org listing in August 2026; prices checked the same week against each vendor’s own pricing page, each of which is linked in that plugin’s section below. Melapress serves USD, EUR or GBP depending on where you are; the WP 2FA figures above are the USD ones. Simba Hosting sells the UpdraftPlus plugin in GBP only, so it is not comparable with the dollar prices in this table. Wordfence’s own pricing page was not reachable at the check date, so no Wordfence paid figure is quoted here.

Wordfence

The Wordfence Login Security plugin page on wordfence.com, headed Two-Factor Authentication, XML-RPC Protection, and Login Page CAPTCHA, beside a blue padlock shield logo
Screenshot of the standalone Wordfence Login Security plugin, which was closed on WordPress.org in August 2026. Its features now ship inside the main Wordfence plugin.

Version 9.0.0, released on 10 August 2026, added passkey authentication to Wordfence and the changelog is explicit that it is available for both free and premium installations. That single line reshuffled this entire category. The plugin sits on more than five million active installs, which puts phishing-resistant login within reach of a very large slice of the web without anyone having to buy anything.

Key features

Passkeys, authenticator-app codes and recovery codes, enabled per role. Passkeys work on the WooCommerce account page and through custom authentication integrations, so membership sites are covered without a second plugin. There is no external service, no per-user seat, and no account to create.

Price

Free for everything described above. Wordfence sells Premium, Care and Response tiers, but what those buy is real-time firewall rules, country blocking and support response times. Login security is not behind the paywall.

Best for

Almost everyone, and especially anyone who has not yet chosen from a shortlist of WordPress security plugins. If a firewall and a scanner are on your list anyway, this removes the need for a separate 2FA plugin entirely.

Skip it if

You want a login-only plugin. Wordfence is a full suite with a firewall, a malware scanner and live traffic logging, which is a lot of moving parts to accept for a second login factor. If your host already runs a firewall at the edge, you are duplicating work you have already paid for.

miniOrange 2FA

The miniOrange WordPress Two Factor Authentication plugin page, listing Google Authenticator, OTP over SMS, OTP over email, push notifications, FIDO2 and WebAuthn among its supported methods

The most interesting free tier in this roundup. miniOrange 2FA puts passkeys, authenticator apps, email OTP and security questions in the free version, for unlimited users, and its listing states that passkey and TOTP verification happen entirely on your own site with no external calls. For a plugin from a vendor whose business is identity-as-a-service, that is a more generous line than you would expect.

Key features

Passkey registration from the user profile, multiple passkeys per user, backup codes as fallback, role-based enforcement and WooCommerce 2FA, all on the free tier. Hardware keys such as YubiKey and Titan work through the same WebAuthn flow. Paid tiers add SMS, WhatsApp and Telegram OTP, push notifications, trusted devices, multisite and custom branding.

Price

Free, then $69, $99 or $149 a year on the Starter, Enterprise and All Inclusive plans. Every tier, free included, covers unlimited users. The page quotes annual pricing in USD and does not publish a separate renewal rate.

Best for

Sites that want passkeys without adopting a whole security suite, and multi-author blogs where a per-user licence would get expensive fast.

Skip it if

You are allergic to upsells. The free plugin advertises its paid methods inside the settings screens, and the paid method list is long enough that the free tier can feel like a lobby. The features it does ship free are real, but you will see the pricing page more than once.

WP 2FA

The WP 2FA plugin banner showing a phone displaying a six-digit code beside a login form, with bullet points reading free 2FA for all users, custom login page support, and supports multiple 2FA apps

WP 2FA from Melapress is the enforcement tool. Where other plugins let users opt in, this one is built around policies: pick the roles, set a grace period, and the wizard nags everyone into compliance without them needing dashboard access. That matters the moment you are responsible for a site with contributors you cannot phone.

Key features

Role-based 2FA policies with grace periods, a setup wizard users can complete from the front end, 16-digit backup codes, editable email templates and REST endpoints for headless setups, all free. Premium adds trusted devices, YubiKey, SMS, one-click email links, WooCommerce integration, white labelling and multiple passkeys per user.

Price

Free, then Premium at $79 for one site, rising to $89 for five, $99 for ten and $129 for twenty-five. The Enterprise line runs $89, $99, $129 and $199 across the same tiers. Licences are auto-renewing annual subscriptions and the vendor publishes no separate renewal discount, so budget for the same figure next year. The page geo-switches between USD, EUR and GBP; those are the USD prices.

Best for

Agencies and anyone administering a site with more than a handful of accounts. At $79 a year for a single site it is cheaper than one support call about a compromised editor account.

Skip it if

You specifically want free passkeys. The plugin’s feature list names passkeys as a core capability and reserves multiple passkeys per user for Premium, but its own FAQ still describes the free edition as authenticator app plus email code. Confirm on a test install before you promise a client passkeys on the free tier.

Two Factor

The official Two Factor plugin is maintained under the WordPress.org account, sits on 100,000-plus installs, and is the closest thing this category has to a reference implementation. It is also the clearest example of why you have to check dates on this stuff.

Version 0.16.0, released in March 2026, removed FIDO U2F support outright. The readme is blunt about why: deprecated and removed due to loss of browser support. What did not arrive to replace it was WebAuthn. So the one plugin with WordPress in its ownership line currently offers no passkeys and no security keys at all.

Key features

TOTP, email codes and backup codes, with a dedicated settings page added in 0.16.0 that lets an admin disable providers site-wide. Clean code, no upsells, no telemetry, no dashboard banner. Roughly 200 ratings averaging near the top of the scale.

Price

Free, permanently. There is no paid edition and no vendor behind it selling one.

Best for

Developers who want the smallest possible surface area, and anyone building on top of it. If you are writing custom auth flows, this is the codebase to extend.

Skip it if

Passkeys are on your requirements list, or you need to force 2FA on a role. There is no enforcement layer here at all: every user configures their own settings from their profile, and an admin can only hide providers, not mandate them.

Kadence Security (formerly iThemes Security)

Archived iThemes Security Pro landing page reading The Best WordPress Security Plugin to Secure and Protect WordPress, with a line offering the Pro version for $99
Archive shot from the plugin’s iThemes era. The same codebase went to Solid Security and is now Kadence Security, and the $99 standalone price on this page no longer exists.

This plugin has been through three names, and the price went somewhere unpleasant on the way. The free version still carries 700,000-plus installs and still does 2FA properly: authenticator apps, email and backup codes, with per-role control and 2FA reminders you can send from the admin.

Key features

Two-factor with authenticator apps, email and backup codes; brute force protection; a vulnerability scanner; user-level security settings. QR codes for 2FA setup are now generated locally by default rather than on a vendor server, which is a genuine privacy improvement worth noting.

Price

The free plugin covers 2FA. The paid features, including passwordless magic links and Patchstack virtual patching, are no longer sold on their own. They come bundled in Kadence Pro at $299 a year or Elite at $499; the $99 Essentials tier excludes security entirely. That is more than three times what WP 2FA Premium costs for a single site.

Best for

Sites already inside the Kadence ecosystem, where the bundle maths works out. If you are buying the theme and the blocks anyway, the security plugin arrives free.

Skip it if

You want passkeys, or you want to buy security on its own. There is no WebAuthn support here, and the standalone licence that made this plugin an easy recommendation has gone. Pair it with real brute-force protection and you have a good free stack; pay $299 for the 2FA and you have overpaid.

Two Factor Authentication by UpdraftPlus

The UpdraftPlus website hero, an orange shield logo over a photo of a laptop on a desk, with the line Secure your WordPress login with our two factor authentication plugin

Old, small and unusually well-behaved. This plugin has been in the directory since 2015, sits on 20,000-plus installs, and does one thing: standard TOTP and HOTP one-time codes, applied wherever your site’s login form happens to live. Note what is absent from that list. Its listing names no SMS option at all, despite years of roundups claiming otherwise.

Key features

TOTP and HOTP, per-role availability, a shortcode so users can manage their own settings without dashboard access, and encryption of the secret keys against an on-disk key so a database dump alone is not enough to forge codes. Free support covers WooCommerce, Theme My Login, AffiliatesWP and Profile Builder forms.

Price

Free, with Premium from £19 per 12 months on an auto-renewing subscription, or £24 if you renew manually. Five sites cost £29 and £39; twenty-five sites cost £59 and £69. Simba Hosting prices in pounds, so do not try to line these up against the dollar figures elsewhere on this page.

Best for

Sites with unusual login forms. Premium reaches Elementor Pro, bbPress, Ultimate Member, Easy Digital Downloads, Gravity Forms registration and Paid Memberships Pro, plus a catch-all that appends the code to the password for any form at all. That list of named integrations is the reason to choose this one.

Skip it if

You need passkeys or hardware keys. This is a one-time-code plugin and makes no pretence otherwise.

Duo Universal

Duo's Two-Factor Authentication product page on duo.com, with a green and grey geometric illustration and a button reading Download the 2FA Evaluation Guide

Not really a WordPress plugin so much as a bridge. Duo Universal hands your login off to Duo’s hosted prompt, which then handles passkeys, biometrics, hardware tokens or push. If your organisation already runs Duo for the VPN and the laptops, this makes WordPress one more app behind the same policy engine. If it does not, you are adopting an identity platform to protect a blog.

Key features

Passkeys, biometrics, hardware tokens and phone-based methods through the Universal Prompt, with enrolment and policy managed centrally in Duo rather than per-site. Published by Duo Security themselves, so it will not be abandoned quietly.

Price

The plugin is free. Duo Free covers up to 10 users at no charge, which is enough for most agency teams. Above that, Essentials is $3 per user per month, Advantage $6 and Premier $9. At $3 a month a single user works out at $36 a year, and the bill grows with headcount rather than with sites.

Best for

Agencies and companies already standardised on Duo, where WordPress joins a policy engine that is already paid for and already understood by the people who have to use it.

Skip it if

You run one site with one admin, or you have clients who will not tolerate a third party in the login path. Note also that this plugin has 2,000 installs and one rating, and was last updated in January 2026, so it moves more slowly than the rest of this list.

Rublon MFA

Rublon's homepage headed Secure access to networks, servers and applications, showing a laptop with a self-enrolment dialog and a phone displaying a push prompt with red Deny and green Approve buttons

The same hosted-service pattern as Duo, aimed at organisations that need MFA across VPNs and servers as well as WordPress. The plugin is well maintained and supports WebAuthn security keys, mobile push, TOTP, QR codes and YubiKey OTP behind a single prompt with a remember-this-device option.

Key features

One prompt, many methods, with self-enrolment built in so users bind their own device or security key at first login. Trusted-device bypass, and central policy across every application you connect, with WordPress as just one of them.

Price

Rublon Free protects exactly one user account, which is enough for a solo admin and nothing more. Business is $2 per user per month with a 15-licence minimum, so the real entry price is $360 a year. Enterprise is $4 per user per month with a 300-licence minimum.

Best for

Organisations already buying MFA for infrastructure, where WordPress is the fifth application on a list rather than the whole project.

Skip it if

You are a freelancer or a small team. The 15-licence floor makes the second user cost $360 a year, and the plugin’s 400 active installs tell you how many WordPress sites have concluded the same thing.

What most 2FA roundups get wrong

They still recommend SMS

NIST’s digital identity guidelines classify authentication over the public telephone network as restricted, and tell verifiers to weigh risk indicators such as device swap, SIM change and number porting before sending a code that way. Wordfence acted on the same reasoning: its 8.2.0 changelog announced that legacy SMS two-factor codes would be discontinued around 1 July 2026 and told sites to migrate users to app-based codes. If a plugin’s marketing leads with SMS, that is a signal about the plugin, not about your threat model.

They treat email codes as a real second factor

This one is worse, because it is nearly universal. NIST SP 800-63B states that email shall not be used for out-of-band authentication, listing interception in transit, rerouting attacks and access using only a password as the reasons. The last one is the killer: if the attacker has the password, and the password manager holding it also holds the email login, the second factor is not a second factor. Email codes are the default free fallback in Two Factor, WP 2FA and Kadence Security. Use them as account recovery, not as your second step.

They still list Wordfence Login Security

The standalone Wordfence Login Security plugin was closed on WordPress.org in August 2026 at the author’s request, and Wordfence 9.0.0’s scanner now raises an issue if it finds it installed, because the main plugin already provides everything it did. Any article still recommending it as a separate download is out of date. If it is on your site, deactivate it and let Wordfence handle login security.

They sell passkeys as bulletproof

Passkeys are the best option on this page because the credential is bound to your domain, so a phishing page on a lookalike URL gets nothing to replay. They are not magic. NIST will not accept syncable passkeys at its highest assurance level, because the private key has to be exportable for the sync to work at all. For a food blog that is irrelevant. For a client with compliance obligations it is a conversation, and the answer is a hardware key rather than a synced credential.

They never mention who 2FA actually locks out

You. Overwhelmingly, you. In practice the most common 2FA incident is an admin who reinstalled their phone without exporting their authenticator, not an attacker turned away at the door. Print the recovery codes, store them somewhere that is not the site, and keep a current backup before you enforce anything on anyone else.

What breaks, and how to not find out the hard way

  • Custom login forms. WooCommerce, membership plugins and page-builder login widgets often bypass the standard hooks, so the second factor silently never fires. Test the actual form your users see, not wp-login.php.
  • Full-page caching. If a caching plugin serves a cached login or account page, the 2FA prompt breaks in ways that look random. Exclude the login page and the account pages, then clear the cache.
  • Passkeys and staging URLs. A passkey is bound to a domain. One created on staging.example.com will not work on example.com. Enrol users after go-live, and test the flow on a throwaway copy first if you use InstaWP or similar.
  • Two plugins at once. Do not. Wordfence 9.0.0 shipped a hardening fix specifically for sites running it alongside plugins with non-standard authentication, which tells you how often this goes wrong.
  • Phone numbers you now have to protect. Turning on SMS means storing user phone numbers, which are personal data with GDPR obligations attached. Another reason not to bother.

Which one should you actually install

  • One site, one or two admins, no firewall yet. Wordfence. Passkeys on, app codes as fallback, done.
  • One site, you already have a firewall you like. miniOrange 2FA free. You get passkeys without a second security suite fighting the first.
  • Client sites, contributors you need to force into compliance. WP 2FA. Free tier for the policies, Premium at $79 a year for one site if you need trusted devices or white labelling.
  • A membership or WooCommerce store with an unusual login form. The UpdraftPlus plugin, Premium tier, for its long list of named form integrations.
  • A team of ten or fewer who already use Duo elsewhere. Duo Universal on the free tier, if your clients will accept a hosted prompt in the login path.
  • You are building something custom. The Two Factor plugin, and accept that you are adding WebAuthn yourself.

Whatever you pick, remember what 2FA does not do. It stops a stolen password on its own from being enough. It does nothing about a vulnerable plugin, a compromised host account or a backdoor already sitting in your uploads folder. If the site has been misbehaving, run a malware scan before you lock the front door, and keep spam registrations under control if you allow public signups, because 2FA does not care how many fake accounts exist.

Frequently Asked Questions

Is SMS two-factor authentication still safe for WordPress?

It is the weakest option you can pick. NIST’s guidelines classify authentication over the phone network as restricted and tell verifiers to watch for SIM changes and number porting first. Wordfence scheduled its own legacy SMS codes for retirement on 1 July 2026. Use an authenticator app or a passkey instead.

Are email 2FA codes good enough?

No. NIST’s guidelines state that email shall not be used for out-of-band authentication, because the inbox is often protected by the same password you are trying to back up. Email codes are still the default fallback in several free plugins. Treat them as recovery, not as a second factor.

Do you need passkeys, or is an authenticator app enough?

An authenticator app is a large improvement over nothing and stops credential stuffing dead. Passkeys go further because the credential is bound to the site’s domain, so a convincing fake login page gets nothing to replay. If your plugin offers both, enable passkeys and keep app codes as the fallback.

What do passkeys need to work on a WordPress site?

HTTPS on the real domain, plus a browser that supports WebAuthn, which every current version of Chrome, Safari, Edge and Firefox does. Passkeys are bound to a domain, so one created on a staging URL will not work on production. Enrol users after the site goes live.

What happens if you lose your phone and get locked out?

Recovery codes, if you saved them. Generate and print them before you enable anything, because almost nobody does. Failing that, disable the plugin over SFTP by renaming its folder inside wp-content/plugins, or clear the 2FA user meta in the database. Both routes need host-level access.

Will a 2FA plugin break WooCommerce or membership logins?

It can. Custom login forms bypass the standard WordPress hooks, so the second factor never fires. Wordfence covers WooCommerce in its free plugin, WP 2FA puts WooCommerce integration behind Premium, and the UpdraftPlus plugin reaches Elementor Pro and bbPress forms only in its paid version. Test on staging first.

Can you run two 2FA plugins at once?

Do not. Two plugins hooking the same authentication filters is a documented source of trouble; Wordfence 9.0.0 specifically hardened its 2FA flow against plugins with non-standard authentication. Pick one, deactivate the other, and clear any half-configured credentials from user profiles before you enforce anything.

Does two-factor authentication slow a site down?

Not for visitors. The second factor only runs on the login and account pages, which are never cached and which most visitors never touch. What it can affect is your caching setup: if a full-page cache serves the login or account page, the prompt breaks. Exclude both.

Do you need to pay for a 2FA plugin at all?

Most sites do not. Wordfence and miniOrange both give you passkeys and authenticator-app codes for nothing, with no user cap. You start paying when you need trusted devices, white-labelled prompts for client sites, WooCommerce customer 2FA in some plugins, or hardware keys such as YubiKey.

Our call

Install Wordfence. That is the answer for the large majority of WordPress sites reading this, and it became the answer in August 2026 when passkeys landed in the free plugin. You get the strongest available second factor, an authenticator-app fallback, WooCommerce coverage and a firewall, for nothing, from a vendor with five million installs’ worth of reasons to keep it working.

If you specifically do not want a security suite, miniOrange 2FA free gives you the same passkey support with a much smaller footprint. If you are policing other people’s accounts, WP 2FA at $79 a year for one site is the tool built for that job. Everything else on this page is a good answer to a narrower question.

Then do the boring part: enable passkeys, keep app codes as the backup, print the recovery codes, and turn off the email option. The last one is the change most sites still have not made.

Alshifa Anwer
Alshifa Anwer
Articles: 55

3 Comments

Leave a Reply

Your email address will not be published. Required fields are marked *