89
Two Factor
Lightweight security that relies entirely on your users being cooperative.
HealthyGrowing
89/100
This lightweight plugin is easy to use but lacks the ability for admins to mandate security.
Active installs
~150,000
our estimate · wp.org shows 100k+
Rating
4.8★
207 ratings
Trend · vs a year ago
+377%
Growing fast
246 → 1,171 installs/day
Downloads over time
real new installs per day · release spikes shown separately from the trend2025-04-302025-08-082025-11-162026-02-232026-06-03
organicrelease spikerelease tailorganic trend · 14d rolling median
Growing fast · +377% in the last year
246/day a year ago→1,171/day today
Reviews
what people actually sayTwo Factor is a well-regarded, lightweight WordPress 2FA plugin praised for its simplicity and reliability, but it has a meaningful security gap: admins cannot enforce 2FA on other users, leaving non-admin accounts vulnerable if users disable it themselves.
What people like
- +Easy to set up and use — install, activate, configure in user profile, done×5
- +Reliable and stable over time across multiple sites×3
- +Supports multiple verification methods including authenticator apps, email codes, and backup codes×2
- +Integrates seamlessly with the default WordPress login system×2
- +Responsive developer support
Common complaints
- −No admin-enforced 2FA: individual users can disable 2FA on their own accounts at any time, leaving those accounts unprotected without the admin noticing
- −The enforcement workaround (redirect to profile page) is bypassable — a bad actor can log in with just a password and reconfigure 2FA to their own device, fully undermining the redirect
- −QR code generated for 2FA setup is not recognized correctly by at least one popular authenticator app (2FAS), requiring manual code entry as a workaround
- −May negatively impact website loading speed
Review trustReviews look organic
- 4.79★Verified rating — holds steady vs the raw 4.80★
- 11%One-shot reviewers — most reviewers are active community members
Reviews per month · 5★ vs lower
2023-07-202025-01-102026-06-04
5★ reviews1–4★ reviews
All-time ratings · 207 total
Latest reviews · 90 analyzed
- 2026-05-28★★★★★Users can undermine, only suitable for adminkloproterra1-shot
- 2026-05-07★★★★★worked and super fast support time.bowerwebsolutions
- 2026-04-27★★★★★Excellentaelbo
- 2026-04-23★★★★★Version wordpress 6.9.4mjezegou351-shot
- 2026-04-23★★★★★Reliable and Lightweight Two-Factor Security Solution for WordPresssinghamritwp
- 2026-04-02★★★★★Easy install, light speedDennis Dallau
- 2026-04-01★★★★★Simple, Reliable & Essential Security PluginGuy Sharpe1-shot
- 2026-03-28★★★★★works well2fishone
- 2026-03-28★★★★★Two Factor = PERFECTleuviah
- 2026-03-28★★★★★Works perfect on 3 websites for more than 3 yearsfliebman9
Releases
recent versions from WordPress.org SVNAlternatives to Two Factor
Top Security plugins, ranked by score.For developers & the curious
the raw signals behind the grade — none of this is on the friendly summary aboveDownload signals
Baselines are computed on organic days only — release spikes and their tails are excluded, so they're not inflated by the auto-update wave.
472
Baseline · median of last 7 organic days
1,191
Prior 7-day baseline
603
Floor · 25th percentile over 14 days
1,461
Mean release-day peak (30d)
1,287
Latest day · 2026-06-03(tail)
-60.4%
Week-over-week organic trend
Review signals
Concentration and drive-by metrics drive the review-burst and fake-review flags. 30–40% solo reviewers is normal; we only flag the extremes.
17%
Max month share · biggest single 30-day window
1.17
Distribution CV · <0.6 even, >1.5 bursty
86%
5★ share in analyzed sample
11%
Solo reviewers · only this one wp.org activity
+140%
Volume velocity · last 6mo vs prior 6mo
4.67 → 4.79★
Sample avg · raw → solo-filtered