WP-WebAuthn
View on WordPress.orgScores higher than 45% of indexed plugins
About
WP-WebAuthn enables passwordless login through FIDO2 and U2F devices like Passkey, FaceID or Windows Hello for your site.
Security History
What It Does
WP-WebAuthn adds passwordless login to WordPress by letting users authenticate with FIDO2 and U2F hardware such as Passkeys, Face ID, Touch ID, and Windows Hello. It integrates with the standard WordPress login form and works alongside (rather than replacing) existing user accounts, so admins can require, allow, or leave optional the use of a security key for second-factor or sole credential.
Who It's For
This plugin suits organizations handling sensitive logins, including healthcare, finance, legal, government, and SaaS portals, where phishing-resistant authentication matters more than convenience. It also fits membership sites and intranets whose users are willing to enroll a device-based credential.
Who Should Skip It
Small blogs, hobby sites, or any WordPress install whose login is already covered by a single admin with a strong password and two-factor plugin should skip it, since the enrollment friction outweighs the benefit. Sites with users on older browsers without WebAuthn support, or shared workstations where no one enrolls a personal key, also do not need this.
The Bottom Line
WP-WebAuthn does exactly what it claims and is clearly kept current, scoring 75.78 out of 100 with flawless maintenance and compatibility. The two real caveats are its tiny install base and its 0.0% support thread resolution rate, so any organization adopting it for compliance should have an internal developer who can debug issues independently. For teams that already understand WebAuthn and want a focused, lightweight passwordless layer, it is a solid pick.
Related Plugins
Pick Really Simple Security if you need broad hardening, two-factor login, and SSL helpers rather than a dedicated passkey flow.
Choose Wordfence when your priority is a firewall, malware scanning, and conventional 2FA, not WebAuthn credentials.
Jetpack makes more sense if you want an all-in-one security, backup, and performance suite instead of a single-purpose authentication plugin.
Reach for AIOS when you need rule-based login protection, captcha, and brute-force defence with a free, mature toolbox.
WPS Hide Login is a better fit if you just want to obscure the wp-login URL as one layer among many, not implement FIDO2.