PLUGIN SECURITY
Is Two Factor safe?
Enable Two-Factor Authentication (2FA) using time-based one-time passwords (TOTP), email, and backup verification codes.
What this plugin does
- Slug:
two-factor - Author: WordPress.org
- 100000+ active installs
- 96/100 rating (208 reviews on wordpress.org)
- 1750601 all-time downloads
- On WordPress.org since 2015-08-10
2FAauthenticationMFAsecuritytotp
Maintenance status
- Latest known version: 0.16.0
- Last updated: 2026-03-27 5:24pm GMT
- Tested up to WordPress: 6.9.7
- Requires PHP: 7.2+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
No known vulnerabilities are recorded in our database for Two Factor. This does not mean the plugin is audited or guaranteed safe — only that no CVE or vulnerability report is on file.
Safer / more established alternatives
- Wordfence Security – Firewall, Malware Scan, and Login Security — 5000000+ active installs — 94/100 (4979) — max PHP 8.4
- Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) — 3000000+ active installs — 98/100 (8861) — max PHP 8.4
- Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention — 1000000+ active installs — 96/100 (1477) — max PHP 8.4
- Limit Login Attempts — 300000+ active installs — 92/100 (202) — max PHP 8.4
- WP 2FA – Two-factor authentication for WordPress — 100000+ active installs — 94/100 (176)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.