Google Authenticator icon

Google Authenticator

by Ivan

View on WordPress.org
80 Quality Score
Active Installs
19/30

At 20,000 active installs this is a niche tool, well behind the million-plus install counts of the mainstream security plugins.

Update Freshness
25/25

A last-updated date of April 2026 and confirmed compatibility with WordPress 7.0 indicate the author is actively maintaining the codebase.

User Rating
13/15

A score of 86 from 135 ratings is solid, though the sample size is modest enough that a handful of unhappy users could shift the average noticeably.

Support Health
8/15

Zero support threads and zero resolutions is a yellow flag: it can mean there have been no problems, or it can mean users have nowhere to turn when things break.

WP Compatibility
15/15

Compatibility with WordPress 7.0 and a minimum requirement of 4.5 give it a very wide compatibility window across current and older sites.

Scores higher than 77% of indexed plugins

About

Google Authenticator for your WordPress blog.

Active Installs 20k+
Rating ★★★★ 4.3/5
Last Updated 2026-08-23 8:48pm GMT
Requires WordPress 4.5+
Tested Up To 7.1

Security History

2 known vulnerabilities, all patched
2 Medium

Most recent: August 3, 2026

View details ▸

Powered by Wordfence Intelligence

What It Does

Google Authenticator adds a second layer of login protection to WordPress by requiring a one-time code from the Google Authenticator app in addition to the standard username and password. It integrates directly with the wp-login.php flow so that admins, editors, or other roles must verify their identity with TOTP on every sign-in. It is a focused, single-purpose 2FA tool rather than a full security suite.

Who It's For

This plugin suits site owners who run environments where a compromised password alone would be damaging, such as financial services portals, healthcare provider dashboards, corporate intranets, or membership sites with sensitive member data. It is also a reasonable fit for multi-author publishing teams and SaaS-style WordPress installations that need a quick path to mandatory 2FA without buying a paid identity product.

Who Should Skip It

If you already run a broader security plugin like Wordfence, Jetpack Security, or All-In-One Security that bundles TOTP two-factor authentication, you do not need this add-on and would be better off using the built-in feature. Small personal blogs or sites with a single trusted user will get little practical benefit and will only add friction to their own logins.

The Bottom Line

Google Authenticator is a competent, actively maintained 2FA plugin that does one thing and does it well, with an overall quality score of 79.66/100. The main caveat is support: zero public threads means you are trusting a single-maintainer project with no visible help channel. If you only need TOTP and are comfortable with that risk, it is a reasonable choice; otherwise, the 2FA features bundled into Wordfence or AIOS offer a safer all-in-one path.

Tags

authentication login otp password security