Two Factor (2FA) Authentication via Email icon

Two Factor (2FA) Authentication via Email

by Sully

View on WordPress.org
77 Quality Score
Active Installs
18/30

With roughly 9,000 active installs, adoption is modest, placing the plugin well outside the mainstream security category but enough to show a real user base.

Update Freshness
25/25

The plugin was updated on 2026-06-21 and is tested against WordPress 7.0, signalling active and current development despite the small install count.

User Rating
12/15

A perfect 100/100 across only 4 ratings is encouraging but statistically thin, so the real-world signal is limited.

Support Health
8/15

Zero support threads, zero resolutions and no public track record make this the plugin's weakest area; if something breaks you are essentially on your own.

WP Compatibility
15/15

Full marks for compatibility: it requires only PHP 5.6 and WordPress 4.6, runs on the latest 7.0 release, and is unlikely to conflict with standard hosting environments.

Scores higher than 57% of indexed plugins

About

Enable one-click login with this WordPress Two-Factor Authentication (2FA) plugin, utilizing email for added security.

Active Installs 9k+
Rating ★★★★★ 5/5
Last Updated 2026-09-11 3:09pm GMT
Requires WordPress 4.6+
Tested Up To 7.1
Requires PHP 5.6+

Security History

1 known vulnerability, all patched
1 Medium

Most recent: February 18, 2026

View details ▸

Powered by Wordfence Intelligence

What It Does

Two Factor (2FA) Authentication via Email adds a second login step to WordPress by sending a one-click approval link or code to the user's email address. Instead of typing a code from an authenticator app, users simply confirm the login attempt from their inbox. It is a lightweight 2FA layer aimed at site owners who want stronger login protection without deploying TOTP or hardware keys.

Who It's For

This plugin is best for small to mid-sized WordPress sites that handle sensitive logins, such as membership portals, client dashboards, or small e-commerce stores, where users may not be willing to install an authenticator app. It also suits site admins who manage a limited number of trusted users and want to enforce 2FA with minimal friction. If your audience is already comfortable checking email during login, the workflow feels almost invisible.

Who Should Skip It

If you run a high-stakes site with regulatory requirements (HIPAA, PCI-DSS, or SOC 2), skip this plugin: email-based 2FA is widely considered weaker than TOTP or hardware keys, and email inboxes are themselves a common attack vector. Larger sites managing thousands of users should also look elsewhere, since support capacity here is essentially nonexistent.

The Bottom Line

Two Factor (2FA) Authentication via Email delivers exactly what its name promises, and its 77.21/100 quality score reflects solid maintenance and compatibility paired with very limited support and a narrow feature set. It is a reasonable choice for small sites that want a low-friction 2FA upgrade, but anyone serious about security should pair it with a broader security plugin or move to a TOTP-based solution. Treat it as a convenience layer, not a complete security strategy.

Tags

2FA 2fa-authentication authentication two factor two factor authentication