WebAuthn Provider for Two Factor icon

WebAuthn Provider for Two Factor

by Volodymyr Kolesnykov

View on WordPress.org
74 Quality Score
Active Installs
14/30

At roughly 1,000 active installs it is a niche plugin, well behind mainstream security tools but appropriate for a specialized authentication extension.

Update Freshness
24/25

Last updated March 2026 and tested against WordPress 6.9.4, so it is actively maintained and current with the latest core release.

User Rating
14/15

A 92 out of 100 from 11 ratings indicates users who try it tend to be happy, though the small sample size limits how much weight that average carries.

Support Health
8/15

With zero support threads and zero resolved, there is no public track record of how the developer handles issues, which is a real risk for a security-critical plugin.

WP Compatibility
15/15

Full marks here: it supports WordPress 6.0+, runs on PHP 8.1, and was recently tested against the newest core version.

Scores higher than 34% of indexed plugins

About

WebAuthn authentication provider for Two Factor plugin.

Active Installs 1k+
Rating ★★★★½ 4.6/5
Last Updated 2026-03-12 8:17am GMT
Requires WordPress 6.0+
Tested Up To 6.9.7
Requires PHP 8.1+

Security History

1 known vulnerability, all patched
1 Medium

Most recent: June 10, 2026

View details ▸

Powered by Wordfence Intelligence

What It Does

This plugin adds WebAuthn (FIDO2) hardware key and biometric authentication as a second login factor for sites running the Two Factor plugin. Instead of TOTP codes, users tap a security key, fingerprint reader, or platform authenticator to verify their identity. It integrates directly into the standard WordPress login flow once Two Factor is installed and configured.

Who It's For

This is best for organizations that handle sensitive data and need phishing-resistant, hardware-backed login on their WordPress sites, such as clinics, financial firms, government offices, and membership sites under compliance pressure. It is also a strong fit for agencies and remote teams that already use YubiKeys or platform authenticators elsewhere and want consistent strong authentication on WordPress admin accounts.

Who Should Skip It

Casual bloggers, small business sites without compliance requirements, or anyone without compatible hardware keys or biometric devices will find this plugin unnecessary, since it adds friction without a matching threat model. It also requires the separate Two Factor plugin and PHP 8.1, so older stacks are not supported.

The Bottom Line

WebAuthn Provider for Two Factor delivers exactly what its name promises: a well-maintained, modern way to require hardware keys or biometrics on WordPress logins. The tiny install base and zero resolved support threads mean you are trusting a small project with security-critical functionality, so test thoroughly and keep backups. Overall Quality Score of 74.73/100 reflects excellent maintenance and compatibility offset by limited adoption and an unproven support record.

Tags

2FA login security two factor webauthn