Reliable and Lightweight Two-Factor Security Solution for WordPress
The Two-Factor plugin provides a robust and user-friendly way to enhance WordPress login security by adding an additional authentication layer. It supports multiple verification methods, including authenticator apps, email codes, and backup codes, making it flexible for different user needs. The setup process is straightforward, and the plugin integrates seamlessly with the default login system. Overall, it is a dependable solution for protecting websites from unauthorized access and security threats.
Excellent
It’s an excellent plugin; I use it on all my sites.
Work as expect
The basic options expected:1. I must be able to use any authentication app.2. An option to use email as 2nd auth.But this plugin also have backup code.
Excellent
It’s an excellent plugin; I use it on all my sites.
Work as expect
The basic options expected:1. I must be able to use any authentication app.2. An option to use email as 2nd auth.But this plugin also have backup code.
Users can undermine, only suitable for admin
This plugin requires individual users to manage 2FA. Individual users can remove 2FA from their profile at any time leaving that account vulnerable. An admin would need to check regularly that this hasn’t been removed. There is discussion about a custom function to force a user back to the profile page. I tested this. A user can still leave the account with 2FA off, albeit they cannot navigation anywhere but the profile page. However, in this state a bad actor can login with a password only to the unprotected account, then configure 2FA to their own device, this then removes the redirect and therefore undermines the entire process. This is a significant flaw. However, the plugin can protect a single admin account but any sort of user hierarchy is not protected.
Excellent
It’s an excellent plugin; I use it on all my sites.
Work as expect
The basic options expected:1. I must be able to use any authentication app.2. An option to use email as 2nd auth.But this plugin also have backup code.
worked and super fast support time.
Not only did it work well for my use case with a customer who wanted to offer optional 2fa, but when i asked about customizing the code validation page i had a response in minutes. Very impressive. Worked well with a theme my login branded site.
Users can undermine, only suitable for admin
This plugin requires individual users to manage 2FA. Individual users can remove 2FA from their profile at any time leaving that account vulnerable. An admin would need to check regularly that this hasn’t been removed. There is discussion about a custom function to force a user back to the profile page. I tested this. A user can still leave the account with 2FA off, albeit they cannot navigation anywhere but the profile page. However, in this state a bad actor can login with a password only to the unprotected account, then configure 2FA to their own device, this then removes the redirect and therefore undermines the entire process. This is a significant flaw. However, the plugin can protect a single admin account but any sort of user hierarchy is not protected.
works well
works well, but it is causing my website slower somehow,i suggest to go through website lighthouse speed check before activate it
2fishone
March 24, 2026
|
3 replies
Great plugin with a compatibility issue
A great plugin and absolutely useful and important! Unfortunately, there is a problem that needs to be addressed and resolved: The QR code generated for 2FA apps is reported as incorrect by the 2FAS smartphone app. If you type the code below into the app, everything works fine. This problem did not occur with Google Authenticator. Of course, it seems to be a problem with the 2FAS app, because Google can do it! But shouldn’t the problem be analyzed in more detail on the developer side? I will probably also inform the developer of the app. However, it would certainly be best if the two experts (plugin here and app there) got in touch with each other.
michavo73
August 20, 2025
|
3 replies