80 Quality Score
Active Installs
19/30

With roughly 20,000 active installs it is a mid-tier niche plugin, well behind the 100,000+ installs of the official Two Factor plugin but still meaningful enough to have a real user base.

Update Freshness
25/25

Last updated in March 2026 and tested against WordPress 7.0, so the maintenance signal is strong and there is no sign of abandonment.

User Rating
13/15

An 88 out of 100 from 77 ratings is a solid score, though the small sample size means it is less statistically reliable than plugins with thousands of reviews.

Support Health
8/15

Zero support threads and zero resolutions on record, which is a yellow flag since it suggests either very few users need help or that help requests are going elsewhere like GitHub or email.

WP Compatibility
15/15

Requiring only PHP 5.6 and WordPress 3.4, while being tested up to WP 7.0, gives it an extremely wide compatibility footprint that will run on virtually any host.

Scores higher than 79% of indexed plugins

About

Secure WordPress login with Two Factor Authentication - supports WP, Woo + other login forms, HOTP, TOTP (Google Authenticator, Authy, etc.)

Active Installs 20k+
Rating ★★★★ 4.4/5
Last Updated 2026-08-13 11:17am GMT
Requires WordPress 3.4+
Tested Up To 7.1
Requires PHP 5.6+

Security History

2 known vulnerabilities, all patched
1 High 1 Medium

Most recent: December 18, 2018

View details ▸

Powered by Wordfence Intelligence

What It Does

Two Factor Authentication adds a second verification step to WordPress, WooCommerce, and other login forms using time-based (TOTP) and counter-based (HOTP) codes from apps like Google Authenticator or Authy. It works alongside your existing password login so users must also enter a code from their device to get in. The plugin focuses purely on the 2FA layer rather than bundling in firewalls, malware scanning, or broader security suites.

Who It's For

This plugin is a good fit for site owners who specifically need to bolt two-factor authentication onto WordPress and WooCommerce login screens without adding a heavyweight security suite. It is especially useful for membership sites, online stores, client portals, healthcare or financial sites, and any WordPress install where account compromise would have real consequences. Agencies managing multiple client sites will appreciate that it covers both standard WP and Woo login forms out of the box.

Who Should Skip It

If you already run a broader security plugin like Wordfence or Really Simple Security that includes built-in 2FA, adding this on top is redundant and creates configuration overlap. Sites with very few logged-in users, simple brochure sites, or anyone who only needs basic brute-force protection should look at Limit Login Attempts Reloaded instead, since full 2FA adds friction for every login.

The Bottom Line

Two Factor Authentication scores a respectable 79.96 out of 100, with excellent maintenance and compatibility but a noticeable gap in support activity and modest install numbers. It is a reasonable, focused choice for WooCommerce and membership sites that want TOTP and HOTP without buying into a larger security suite, but the complete absence of public support threads means you should be comfortable troubleshooting on your own. If community support or a larger user base matters more than WooCommerce-specific coverage, the free Two Factor plugin is the safer default.

Tags

2FA google authenticator TFA two factor two factor auth