WP-WebAuthn icon

WP-WebAuthn

by Axton

View on WordPress.org
76 Quality Score
Active Installs
15/30

Popularity scored 49 out of 30 thanks to a relative boost from a niche audience, but raw installs sit at only 2,000, indicating a specialised rather than mainstream plugin.

Update Freshness
25/25

Maintenance is a perfect 100 out of 25, reflecting a very recent update on April 15, 2026 and tested compatibility with WordPress 6.9.4.

User Rating
14/15

User ratings landed at 90 out of 15 across 17 reviews, suggesting strong satisfaction from a small but engaged user base.

Support Health
8/15

Support health scored only 50 out of 15, with just 1 support thread and a 0.0% resolution rate, which is a real concern for any production deployment.

WP Compatibility
15/15

Compatibility scored 100 out of 15, with the plugin tested against WordPress 6.9.4 and requiring only PHP 7.4, leaving little doubt about technical fit.

Scores higher than 45% of indexed plugins

About

WP-WebAuthn enables passwordless login through FIDO2 and U2F devices like Passkey, FaceID or Windows Hello for your site.

Active Installs 2k+
Rating ★★★★½ 4.5/5
Last Updated 2026-04-15 5:57pm GMT
Requires WordPress 5.0+
Tested Up To 6.9.7
Requires PHP 7.4+

Security History

3 known vulnerabilities, all patched
3 Medium

Most recent: March 20, 2026

View details ▸

Powered by Wordfence Intelligence

What It Does

WP-WebAuthn adds passwordless login to WordPress by letting users authenticate with FIDO2 and U2F hardware such as Passkeys, Face ID, Touch ID, and Windows Hello. It integrates with the standard WordPress login form and works alongside (rather than replacing) existing user accounts, so admins can require, allow, or leave optional the use of a security key for second-factor or sole credential.

Who It's For

This plugin suits organizations handling sensitive logins, including healthcare, finance, legal, government, and SaaS portals, where phishing-resistant authentication matters more than convenience. It also fits membership sites and intranets whose users are willing to enroll a device-based credential.

Who Should Skip It

Small blogs, hobby sites, or any WordPress install whose login is already covered by a single admin with a strong password and two-factor plugin should skip it, since the enrollment friction outweighs the benefit. Sites with users on older browsers without WebAuthn support, or shared workstations where no one enrolls a personal key, also do not need this.

The Bottom Line

WP-WebAuthn does exactly what it claims and is clearly kept current, scoring 75.78 out of 100 with flawless maintenance and compatibility. The two real caveats are its tiny install base and its 0.0% support thread resolution rate, so any organization adopting it for compliance should have an internal developer who can debug issues independently. For teams that already understand WebAuthn and want a focused, lightweight passwordless layer, it is a solid pick.

Tags

fido login passkey security webauthn