PLUGIN SECURITY

Is Google Authenticator safe?

Google Authenticator for your WordPress blog.

What this plugin does

  • Slug: google-authenticator
  • Author: Ivan
  • 20000+ active installs
  • 86/100 rating (135 reviews on wordpress.org)
  • 751732 all-time downloads
  • On WordPress.org since 2011-05-16

authenticationloginotppasswordsecurity

Maintenance status

  • Latest known version: 0.56
  • Last updated: 2026-08-23 8:48pm GMT
  • Tested up to WordPress: 7.1
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

1 known CVE on file for Google Authenticator. Reported between 2016 and 2026.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-14204 Google Authenticator [google-authenticator] < 0.56 Cross-Site Request Forgery (CSRF) Unknown < 0.56 0.56 2026-08-03 ✓ fixed in latest
Google Authenticator [google-authenticator] < 0.48 Unknown < 0.48 0.48 2016-04-28 ✓ fixed in latest
Google Authenticator [google-authenticator] < 0.48 Unknown < 0.48 0.48 2016-04-28 ✓ fixed in latest
Google Authenticator [google-authenticator] < 0.48 Unknown < 0.48 0.48 ✓ fixed in latest
Google Authenticator <= 0.47 - Two Factor Authentication Bypass Unknown < 0.48 0.48 ✓ fixed in latest

How to fix it

Keep Google Authenticator updated — 0.56 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.