Setting up Two-Factor Authentication on WordPress

Protecting your WordPress admin with just a password is no longer enough in 2026. Wordfence reports more than 100,000 brute-force attempts per minute against WordPress sites worldwide. Even the strongest password can leak through a data breach on another service.

Two-Factor Authentication (2FA) adds a second layer of defense. Even if an attacker knows your password, they still cannot log in without the second factor. This guide walks you through enabling 2FA on WordPress from scratch, with a comparison of the most popular plugins.

Quick summary: Enabling 2FA on WordPress takes less than 10 minutes and is a one-time setup. It is the single highest-impact security improvement you can make on any WordPress site.

What Is 2FA and How Does It Work on WordPress?

Two-Factor Authentication combines something you know (your password) with something you have (your phone or an authenticator app). Even if an attacker steals your password, they cannot log in without the second factor on your physical device.

For WordPress, there are three main 2FA methods:

Why You Should Enable 2FA on WordPress

Many site owners think "my site is too small to be a target." In reality, automated bots scan every WordPress installation they can find regardless of size. Every site is at risk.

Key statistic: Microsoft reports that 2FA blocks the vast majority of automated account attacks. No other security measure gives you this level of protection for so little effort.

Top 3 WordPress 2FA Plugins Compared

1. WP 2FA (Best for beginners)

WP 2FA by Melapress is the easiest option for non-technical users. It includes a step-by-step setup wizard, supports TOTP apps, email OTP, and backup codes, and lets administrators manage user policies directly from the dashboard.

2. Google Authenticator by miniOrange

The most feature-rich option. Supports Google Authenticator, Authy, Microsoft Authenticator, email OTP, SMS OTP, and push notifications. Ideal for organizations with specific security policies.

3. Two Factor Authentication by David Anderson

A lightweight, clean-code plugin with no bloat and no data sent off-site. Perfect for developers who want basic TOTP 2FA without extra features.

Step-by-Step: Setting Up WP 2FA

We use WP 2FA as the example because it is the most beginner-friendly option with comprehensive features.

Step 1: Install the Plugin

  1. Go to WordPress Admin → Plugins → Add New Plugin
  2. Search for WP 2FA
  3. Click Install Now, then Activate
  4. The plugin launches a Setup Wizard automatically

Step 2: Choose Your 2FA Method

The Setup Wizard asks which method to use. Choose "One-time code generated with the authenticator app" (TOTP) for maximum security, or "One-time code sent over email" for convenience.

Step 3: Set Role-Based Enforcement

WP 2FA lets you specify which user roles must use 2FA. Recommended settings:

Grace Period: WP 2FA lets you set a grace period (e.g., 3 days) giving users time to configure 2FA before the system locks them out. Always set this to avoid user confusion on sites with multiple users.

Step 4: Scan the QR Code with an Authenticator App

  1. Download Google Authenticator or Authy on your smartphone
  2. Open the app and tap + or Scan QR Code
  3. Scan the QR code displayed on the WordPress setup page
  4. The app will show a 6-digit code that refreshes every 30 seconds
  5. Enter that code in the WordPress verification field and click Verify

Step 5: Save Your Recovery Codes

After successful setup, WordPress will display 8–10 Recovery Codes. Each code can only be used once and is your backup if you lose your phone.

Critical: Store Recovery Codes somewhere safe — in a password manager or printed and locked away. If you lose your phone and have no Recovery Codes, you will be locked out of WordPress Admin and will need to disable the plugin via FTP or File Manager directly.

Which Authenticator App Is Best: Google Authenticator vs Authy vs Microsoft Authenticator

Before scanning the QR code, you need to choose an authenticator app. Each has different strengths depending on how many sites you manage and what kind of backup you need.

AppCloud BackupMulti-DeviceBest for
Google AuthenticatorGoogle Account backupDevice transfer supportedGeneral users with a Gmail account
AuthyAuthy Cloud (encrypted)iOS + Android + DesktopAdmins managing multiple sites
Microsoft AuthenticatorMicrosoft Account backupiOS + AndroidOffice 365 / Teams users

For administrators managing multiple WordPress sites, Authy is generally the best choice because it syncs across devices and restores from its encrypted cloud backup if you lose your phone. The newer Google Authenticator also supports account backup via Google Account.

Tip: Regardless of which app you choose, back up all accounts inside the app AND save the Recovery Codes that WP 2FA provides. Two separate backup layers prevent a catastrophic lockout.

2FA on WooCommerce and Membership Sites — What to Configure

Sites running WooCommerce or a membership plugin such as MemberPress have additional considerations when enabling 2FA.

# List all custom roles registered in WordPress via WP-CLI
wp role list

# Or check via the WordPress admin:
# Tools → Site Health → Info → WordPress Constants

Testing and Verifying 2FA After Setup

After completing the setup, a critical step that many administrators skip is testing an actual login in a new browser or Incognito window before closing the current session. This way, if 2FA has a configuration problem, you can fix it without needing FTP access.

  1. Open a new browser window or Incognito / Private browsing mode
  2. Navigate to the WordPress login page (/wp-login.php or /wp-admin)
  3. Enter your username and password as usual
  4. The system will prompt for an OTP from your authenticator app
  5. Open the app on your phone and enter the 6-digit code
  6. Confirm that login succeeds and the dashboard loads correctly

A successful login confirms 2FA is working correctly. You can then safely close the original session.

Pro tip: Test one Recovery Code to confirm your backup actually works. Remember that each Recovery Code can only be used once — generate a new set after using one.

Enforcing 2FA for All Users on Your Site

If your WordPress site has multiple users (editors, authors, etc.), administrators can require everyone to set up 2FA through WP 2FA policies.

  1. Go to WP 2FA → Policies
  2. Set which roles are required (All Users, or just Administrator + Editor)
  3. Set a Grace Period of 3–7 days
  4. Save — users will see a setup prompt on their next login

Users who have not set up 2FA will see a notice on every login until they do. After the grace period expires, they will be redirected to the 2FA setup page automatically and cannot access the dashboard without completing setup.

Plugin Comparison Table

PluginTOTP AppEmail OTPRecovery CodesRole ControlPrice
WP 2FA✓✓✓✓Free / Premium
Google Auth (miniOrange)✓✓✓✓Free (1 user) / Paid
Two Factor (David Anderson)✓✓LimitedNoFree 100%
Wordfence 2FA✓No✓✓Included in Wordfence

Troubleshooting Common 2FA Issues

TOTP Code Is Invalid

TOTP codes are time-based. If your phone's clock is out of sync with the server, the code will fail. Enable "Automatic Date & Time" on your phone, or use the Sync option in Google Authenticator settings.

Lost Your Phone or Deleted the App

Use the Recovery Codes you saved during setup. If you have no Recovery Codes, disable the plugin via FTP or File Manager:

# Via DirectAdmin File Manager
# Navigate to public_html/wp-content/plugins/
# Rename folder: wp-2fa → wp-2fa-disabled
# WordPress will automatically deactivate the plugin

Users Not Receiving Email OTP

Check the spam folder first. If email delivery is unreliable, install an SMTP plugin like WP Mail SMTP to send through a proper SMTP server instead of PHP's native mail() function, which is often blocked by spam filters.

WordPress Hosting with Free SSL — from 500 THB/year

AsiaGB Hosting is fully WordPress-compatible with DirectAdmin, SSD storage, free SSL certificate, and automatic backup on the 1st and 15th of each month. Starting at just 500 THB/year.

View Hosting Plans →