Two Factor
by Plugin contributors
The community two-factor plugin: TOTP, email codes and backup codes with no upsells.
This link may earn us a commission. It never changes our rating.
What Two Factor does
The community two-factor plugin: TOTP, email codes and backup codes with no upsells.
It sits in the security part of a WordPress stack and is sold by Plugin contributors on a free basis. We recommend it in our security guides because it does that one job well without asking you to rebuild the rest of the site around it.
Every plugin adds work to a page request, so treat this as a decision with a cost. Record a speed test before you install it and run the same test afterwards, on the same page, so you know exactly what it charged you.
Real user ratings
Score
4.8/5
Reviews
208
Active installs
100,000+
Downloads
1.8M
Latest version
0.16.0
Last updated
2026-03-27
These figures come straight from the public WordPress.org plugin directory API for version 0.16.0, not from us. Check them yourself on the WordPress.org listing. Our own editorial score is 4.4/5.
Where Two Factor ranks elsewhere
| Publisher | List | Position |
|---|---|---|
| WPBeginner | Best WordPress Security Plugins | #8 of 8 |
| Themeisle | Best WordPress Plugins | #11 of 22 |
Positions are read from the published articles themselves, so they reflect that publisher's order rather than ours. Lists get re-ordered over time, so follow the link if you want the current version.
What changed in the latest version
- Breaking Changes: Remove legacy FIDO U2F provider support by #439 .
- New Features: Add a dedicated settings page for plugin configuration in wp-admin by #764 .
- New Features: Add a support links filter so consumers can customize contextual recovery/help links by #615 .
- New Features: Refresh backup codes UI styling and behavior by #804 .
- Bug Fixes: Delete stored TOTP secrets when the TOTP provider is disabled by #802 .
- Bug Fixes: Harden provider handling so login/settings checks do not fail open when expected providers disappear by #586 .
- Bug Fixes: Ensure only configured providers are saved and enabled in user settings by #798 .
- Bug Fixes: Improve settings-page accessibility and fix profile settings link behavior by #828 and #830 .
- Breaking Changes: Trigger two-factor flow only when expected by @kasparsd in #660 and #793 .
- New Features: Include user IP address and contextual warning in two-factor code emails by @todeveni in #728
- New Features: Optimize email text for TOTP by @masteradhoc in #789
- New Features: Add "Settings" action link to plugin list for quick access to profile by @hardikRathi in #740
- New Features: Additional form hooks by @eric-michel in #742
- New Features: Full RFC6238 Compatibility by @ericmann in #656
- New Features: Consistent user experience for TOTP setup by @kasparsd in #792
- Documentation: @since docs by @masteradhoc in #781
- New Features: Add filter for rest_api_can_edit_user_and_update_two_factor_options by @gutobenn in #689
- Development Updates: Remove Coveralls tooling and add inline coverage report by @kasparsd in #717
- Development Updates: Update blueprint path to pull from main branch instead of a deleted f… by @georgestephanis in #719
- Development Updates: Fix blueprint and wporg asset deploys by @kasparsd in #734
- Development Updates: Upload release only on tag releases by @kasparsd in #735
- Development Updates: Bump playwright and @playwright/test by @dependabot[bot] in #721
- Development Updates: Bump tar-fs from 3.1.0 to 3.1.1 by @dependabot[bot] in #720
- Development Updates: Bump node-forge from 1.3.1 to 1.3.2 by @dependabot[bot] in #724
Release notes are the developer's own words, published on WordPress.org. Read the full changelog
Pros and cons
- Simple, free and well maintained
- Free with no licence to renew
- Actively maintained and used on production sites we test
- No enforcement policies
- Support is community-led rather than guaranteed
How to use it
- 1Take a full backup before enabling any blocking feature.
- 2Turn on login protection and two-factor for administrator accounts first.
- 3Schedule scans outside peak hours to protect response times.
- 4Set alerts to a monitored inbox, not the default admin address.
- 5Re-run the speed test so you know what the protection costs you.
How it compares
Other security plugins we recommend, with their rating and pricing model.
| Plugin | Our rating | WordPress.org | Pricing | Best for |
|---|---|---|---|---|
| Two Factor | 4.4 | 4.8 (208) | Free | Simple, free and well maintained |
| Akismet | 4.7 | 4.7 (1,186) | Freemium | Catches almost all comment spam with no tuning |
| Antispam Bee | 4.8 | 4.8 (226) | Free | Privacy friendly spam filtering with no account |
| Duo | 4.2 | 4 (1) | Freemium | Central policy control for teams |
| Jetpack Protect | 4.3 | 4.6 (123) | Freemium | Free vulnerability alerts |
| Limit Login Attempts Reloaded | 4.8 | 4.8 (1,483) | Freemium | Big protection for almost no overhead |
Guides that cover Two Factor

8 Best WordPress Two-Factor Authentication Plugins for 2026
Two-factor authentication limits the damage of a stolen password. A sound rollout also needs recovery codes, role policies and an emergency access procedure.
Updated 10 September 2026

How to Restrict User Login to One Device in WordPress
Limiting concurrent sessions can discourage account sharing, but a device is not a stable identity, so you need a clear policy and a safe recovery path.
Updated 10 September 2026
Alternatives
Other security plugins
Akismet
Automattic
Comment and form spam filtering run through Automattic's hosted service, checked against a global spam corpus.
1,186 reviews · 406.0M downloads · v5.7.2
Antispam Bee
pluginkollektiv
Blocks comment spam locally with no external service and no personal data leaving your server.
226 reviews · 13.0M downloads · v2.11.13
Duo
Cisco Duo
Enterprise two-factor from Cisco Duo, with push approval and device policy controls.
1 reviews · 20K downloads · v1.2.1
