
Protecting your WordPress admin with just a password is no longer enough in 2026. Wordfence reports more than 100,000 brute-force attempts per minute against WordPress sites worldwide. Even the strongest password can leak through a data breach on another service.
Two-Factor Authentication (2FA) adds a second layer of defense. Even if an attacker knows your password, they still cannot log in without the second factor. This guide walks you through enabling 2FA on WordPress from scratch, with a comparison of the most popular plugins.
Quick summary: Enabling 2FA on WordPress takes less than 10 minutes and is a one-time setup. It is the single highest-impact security improvement you can make on any WordPress site.
What Is 2FA and How Does It Work on WordPress?
Two-Factor Authentication combines something you know (your password) with something you have (your phone or an authenticator app). Even if an attacker steals your password, they cannot log in without the second factor on your physical device.
For WordPress, there are three main 2FA methods:
- TOTP (Time-based One-Time Password) — Apps like Google Authenticator or Authy generate a 6-digit code that changes every 30 seconds. This is the most popular and most secure method.
- Email OTP — A one-time code sent to your email address. Simpler but dependent on your email account security.
- SMS OTP — A code sent via SMS. Vulnerable to SIM-swapping attacks and generally not recommended.
Why You Should Enable 2FA on WordPress
Many site owners think "my site is too small to be a target." In reality, automated bots scan every WordPress installation they can find regardless of size. Every site is at risk.
- Stops Brute Force Attacks — Even a correct password is useless without the OTP.
- Defeats Credential Stuffing — Leaked credentials from other sites cannot be used against your WordPress login.
- Mitigates Phishing — Even if a user submits their password to a fake site, the attacker still lacks the OTP.
- Helps meet compliance requirements such as PDPA and general security standards.
Key statistic: Microsoft reports that 2FA blocks the vast majority of automated account attacks. No other security measure gives you this level of protection for so little effort.
Top 3 WordPress 2FA Plugins Compared
1. WP 2FA (Best for beginners)
WP 2FA by Melapress is the easiest option for non-technical users. It includes a step-by-step setup wizard, supports TOTP apps, email OTP, and backup codes, and lets administrators manage user policies directly from the dashboard.
- Active Installs: 80,000+
- Supports: TOTP, Email OTP, Recovery Codes
- Role-based enforcement (Administrator, Editor, Author, etc.)
- Grace Period setting so users have time to set up before being locked out
2. Google Authenticator by miniOrange
The most feature-rich option. Supports Google Authenticator, Authy, Microsoft Authenticator, email OTP, SMS OTP, and push notifications. Ideal for organizations with specific security policies.
- Active Installs: 20,000+
- Broadest range of authentication methods
- IP restriction and trusted device features
- Free version limited to 1 user; paid plan for multi-user sites
3. Two Factor Authentication by David Anderson
A lightweight, clean-code plugin with no bloat and no data sent off-site. Perfect for developers who want basic TOTP 2FA without extra features.
- Active Installs: 10,000+
- Supports TOTP and Email OTP
- Minimal performance impact
- 100% open source
Step-by-Step: Setting Up WP 2FA
We use WP 2FA as the example because it is the most beginner-friendly option with comprehensive features.
Step 1: Install the Plugin
- Go to WordPress Admin → Plugins → Add New Plugin
- Search for
WP 2FA - Click Install Now, then Activate
- The plugin launches a Setup Wizard automatically
Step 2: Choose Your 2FA Method
The Setup Wizard asks which method to use. Choose "One-time code generated with the authenticator app" (TOTP) for maximum security, or "One-time code sent over email" for convenience.
Step 3: Set Role-Based Enforcement
WP 2FA lets you specify which user roles must use 2FA. Recommended settings:
- Administrator — Always required, no exceptions
- Editor — Required (can edit all posts)
- Author — Strongly recommended
- Contributor / Subscriber — Optional depending on your security policy
Grace Period: WP 2FA lets you set a grace period (e.g., 3 days) giving users time to configure 2FA before the system locks them out. Always set this to avoid user confusion on sites with multiple users.
Step 4: Scan the QR Code with an Authenticator App
- Download Google Authenticator or Authy on your smartphone
- Open the app and tap + or Scan QR Code
- Scan the QR code displayed on the WordPress setup page
- The app will show a 6-digit code that refreshes every 30 seconds
- Enter that code in the WordPress verification field and click Verify
Step 5: Save Your Recovery Codes
After successful setup, WordPress will display 8–10 Recovery Codes. Each code can only be used once and is your backup if you lose your phone.
Critical: Store Recovery Codes somewhere safe — in a password manager or printed and locked away. If you lose your phone and have no Recovery Codes, you will be locked out of WordPress Admin and will need to disable the plugin via FTP or File Manager directly.
Which Authenticator App Is Best: Google Authenticator vs Authy vs Microsoft Authenticator
Before scanning the QR code, you need to choose an authenticator app. Each has different strengths depending on how many sites you manage and what kind of backup you need.
| App | Cloud Backup | Multi-Device | Best for |
|---|---|---|---|
| Google Authenticator | Google Account backup | Device transfer supported | General users with a Gmail account |
| Authy | Authy Cloud (encrypted) | iOS + Android + Desktop | Admins managing multiple sites |
| Microsoft Authenticator | Microsoft Account backup | iOS + Android | Office 365 / Teams users |
For administrators managing multiple WordPress sites, Authy is generally the best choice because it syncs across devices and restores from its encrypted cloud backup if you lose your phone. The newer Google Authenticator also supports account backup via Google Account.
Tip: Regardless of which app you choose, back up all accounts inside the app AND save the Recovery Codes that WP 2FA provides. Two separate backup layers prevent a catastrophic lockout.
2FA on WooCommerce and Membership Sites — What to Configure
Sites running WooCommerce or a membership plugin such as MemberPress have additional considerations when enabling 2FA.
- WooCommerce customers (Subscriber role) — Mandatory 2FA for customers is generally not recommended as it creates friction. Consider making it optional unless your store handles particularly sensitive data.
- Shop Manager / WooCommerce Admin — Always require 2FA. These roles have access to order data and customer information.
- Custom roles — If plugins create custom roles such as "Content Editor" or "Product Manager", you must add them manually to WP 2FA Policies. They will not appear in the default role list automatically.
# List all custom roles registered in WordPress via WP-CLI
wp role list
# Or check via the WordPress admin:
# Tools → Site Health → Info → WordPress Constants
Testing and Verifying 2FA After Setup
After completing the setup, a critical step that many administrators skip is testing an actual login in a new browser or Incognito window before closing the current session. This way, if 2FA has a configuration problem, you can fix it without needing FTP access.
- Open a new browser window or Incognito / Private browsing mode
- Navigate to the WordPress login page (
/wp-login.phpor/wp-admin) - Enter your username and password as usual
- The system will prompt for an OTP from your authenticator app
- Open the app on your phone and enter the 6-digit code
- Confirm that login succeeds and the dashboard loads correctly
A successful login confirms 2FA is working correctly. You can then safely close the original session.
Pro tip: Test one Recovery Code to confirm your backup actually works. Remember that each Recovery Code can only be used once — generate a new set after using one.
Enforcing 2FA for All Users on Your Site
If your WordPress site has multiple users (editors, authors, etc.), administrators can require everyone to set up 2FA through WP 2FA policies.
- Go to WP 2FA → Policies
- Set which roles are required (All Users, or just Administrator + Editor)
- Set a Grace Period of 3–7 days
- Save — users will see a setup prompt on their next login
Users who have not set up 2FA will see a notice on every login until they do. After the grace period expires, they will be redirected to the 2FA setup page automatically and cannot access the dashboard without completing setup.
Plugin Comparison Table
| Plugin | TOTP App | Email OTP | Recovery Codes | Role Control | Price |
|---|---|---|---|---|---|
| WP 2FA | ✓ | ✓ | ✓ | ✓ | Free / Premium |
| Google Auth (miniOrange) | ✓ | ✓ | ✓ | ✓ | Free (1 user) / Paid |
| Two Factor (David Anderson) | ✓ | ✓ | Limited | No | Free 100% |
| Wordfence 2FA | ✓ | No | ✓ | ✓ | Included in Wordfence |
Troubleshooting Common 2FA Issues
TOTP Code Is Invalid
TOTP codes are time-based. If your phone's clock is out of sync with the server, the code will fail. Enable "Automatic Date & Time" on your phone, or use the Sync option in Google Authenticator settings.
Lost Your Phone or Deleted the App
Use the Recovery Codes you saved during setup. If you have no Recovery Codes, disable the plugin via FTP or File Manager:
# Via DirectAdmin File Manager
# Navigate to public_html/wp-content/plugins/
# Rename folder: wp-2fa → wp-2fa-disabled
# WordPress will automatically deactivate the plugin
Users Not Receiving Email OTP
Check the spam folder first. If email delivery is unreliable, install an SMTP plugin like WP Mail SMTP to send through a proper SMTP server instead of PHP's native mail() function, which is often blocked by spam filters.
WordPress Hosting with Free SSL — from 500 THB/year
AsiaGB Hosting is fully WordPress-compatible with DirectAdmin, SSD storage, free SSL certificate, and automatic backup on the 1st and 15th of each month. Starting at just 500 THB/year.
View Hosting Plans →