WP

WP 2FA

by Melapress

Rolls out two-factor authentication policy-first, so you can require it by role with a grace period.

4.7177 WordPress.org reviewsSecurityFreemium

This link may earn us a commission. It never changes our rating.

What WP 2FA does

Rolls out two-factor authentication policy-first, so you can require it by role with a grace period.

It sits in the security part of a WordPress stack and is sold by Melapress on a freemium basis. We recommend it in our security guides because it does that one job well without asking you to rebuild the rest of the site around it.

Every plugin adds work to a page request, so treat this as a decision with a cost. Record a speed test before you install it and run the same test afterwards, on the same page, so you know exactly what it charged you.

Real user ratings

Score

4.7/5

Reviews

177

Active installs

100,000+

Downloads

1.8M

Latest version

4.1.0

Last updated

2026-08-11

These figures come straight from the public WordPress.org plugin directory API for version 4.1.0, not from us. Check them yourself on the WordPress.org listing. Our own editorial score is 4.7/5.

Where WP 2FA ranks elsewhere

WP 2FA does not appear in the published "best of" lists we track from WPBeginner, TechRadar, Kinsta, Themeisle and similar sites. That is not a mark against it - those roundups are short and skew towards the biggest names.

What changed in the latest version

v4.1.0Latest release2027-07-21
  • New functionality Added an option to customize the OTP code validity period for zero-setup 2FA.
  • Security fix Fixed the Customize email templates heading on the white labeling page.
  • Functionality & plugin improvements Improved email delivery guidance and test email error messages, with clearer troubleshooting information and links to the email deliverability documentation.
  • Improved the front-end 2FA settings validation message and styling when the page slug has not been configured.
  • Authy OneTouch approval requests are now validated entirely server-side. Approval identifiers are single-use and are no longer exposed to the browser.
  • Moved the user profile backup-method link customization to the relevant user profile section of the white labeling settings.
  • Improved the login error shown when an unexpected issue prevents 2FA verification.
  • Improved spacing between the Add Passkey button and the passkeys table when the backup methods information link is displayed.

Release notes are the developer's own words, published on WordPress.org. Read the full changelog

Pros and cons

  • Policy and grace periods by role
  • A free tier you can trial before paying
  • Actively maintained and used on production sites we test
  • Some methods need the premium build
  • The features most sites need sit in the paid tier

How to use it

  1. 1Take a full backup before enabling any blocking feature.
  2. 2Turn on login protection and two-factor for administrator accounts first.
  3. 3Schedule scans outside peak hours to protect response times.
  4. 4Set alerts to a monitored inbox, not the default admin address.
  5. 5Re-run the speed test so you know what the protection costs you.

How it compares

Other security plugins we recommend, with their rating and pricing model.

PluginOur ratingWordPress.orgPricingBest for
WP 2FA4.74.7 (177)FreemiumPolicy and grace periods by role
Akismet4.74.7 (1,186)FreemiumCatches almost all comment spam with no tuning
Antispam Bee4.84.8 (226)FreePrivacy friendly spam filtering with no account
Duo4.24 (1)FreemiumCentral policy control for teams
Jetpack Protect4.34.6 (123)FreemiumFree vulnerability alerts
Limit Login Attempts Reloaded4.84.8 (1,483)FreemiumBig protection for almost no overhead

Guides that cover WP 2FA