Duo
by Cisco Duo
Enterprise two-factor from Cisco Duo, with push approval and device policy controls.
This link may earn us a commission. It never changes our rating.
What Duo does
Enterprise two-factor from Cisco Duo, with push approval and device policy controls.
It sits in the security part of a WordPress stack and is sold by Cisco Duo on a freemium basis. We recommend it in our security guides because it does that one job well without asking you to rebuild the rest of the site around it.
Every plugin adds work to a page request, so treat this as a decision with a cost. Record a speed test before you install it and run the same test afterwards, on the same page, so you know exactly what it charged you.
Real user ratings
Score
4/5
Reviews
1
Active installs
2,000+
Downloads
20K
Latest version
1.2.1
Last updated
2026-01-06
These figures come straight from the public WordPress.org plugin directory API for version 1.2.1, not from us. Check them yourself on the WordPress.org listing. Our own editorial score is 4.2/5.
Where Duo ranks elsewhere
Duo does not appear in the published "best of" lists we track from WPBeginner, TechRadar, Kinsta, Themeisle and similar sites. That is not a mark against it - those roundups are short and skew towards the biggest names.
What changed in the latest version
- Adds support for new Duo certificate authorities.
- Updated dependencies to require duo_universal_php v1.1.0
- Refactored 2FA session management Switching between multisites will no longer logout the current user.
- Clearing WordPress caches will no longer logout all users.
- There is no longer a 48 hour Duo session separate from the WordPress session.
- Fix plugin file paths on clustered hosting environments.
- Fixed debug logging to properly enable when using the WP_DEBUG constant.
Release notes are the developer's own words, published on WordPress.org. Read the full changelog
Pros and cons
- Central policy control for teams
- A free tier you can trial before paying
- Actively maintained and used on production sites we test
- Overkill for a small site
- The features most sites need sit in the paid tier
How to use it
- 1Take a full backup before enabling any blocking feature.
- 2Turn on login protection and two-factor for administrator accounts first.
- 3Schedule scans outside peak hours to protect response times.
- 4Set alerts to a monitored inbox, not the default admin address.
- 5Re-run the speed test so you know what the protection costs you.
How it compares
Other security plugins we recommend, with their rating and pricing model.
| Plugin | Our rating | WordPress.org | Pricing | Best for |
|---|---|---|---|---|
| Duo | 4.2 | 4 (1) | Freemium | Central policy control for teams |
| Akismet | 4.7 | 4.7 (1,186) | Freemium | Catches almost all comment spam with no tuning |
| Antispam Bee | 4.8 | 4.8 (226) | Free | Privacy friendly spam filtering with no account |
| Jetpack Protect | 4.3 | 4.6 (123) | Freemium | Free vulnerability alerts |
| Limit Login Attempts Reloaded | 4.8 | 4.8 (1,483) | Freemium | Big protection for almost no overhead |
| Loggedin | 4.4 | 4.9 (111) | Free | Stops shared account credentials |
Guides that cover Duo
Alternatives
Other security plugins
Akismet
Automattic
Comment and form spam filtering run through Automattic's hosted service, checked against a global spam corpus.
1,186 reviews · 406.0M downloads · v5.7.2
Antispam Bee
pluginkollektiv
Blocks comment spam locally with no external service and no personal data leaving your server.
226 reviews · 13.0M downloads · v2.11.13
Jetpack Protect
Automattic
Free vulnerability scanning against a maintained database of plugin, theme and core issues.
123 reviews · 2.6M downloads · v6.1.0

