73
Two Factor Authentication
Reliable TOTP protection that charges extra to actually enforce it.
Healthy
73/100
The plugin provides solid TOTP security but locks mandatory enforcement behind a paywall.
Active installs
~25,000
our estimate · wp.org shows 20k+
Rating
4.4★
77 ratings
Trend · vs a year ago
-1%
Holding steady
74 → 73 installs/day
Downloads over time
real new installs per day · release spikes shown separately from the trend2025-04-302025-08-082025-11-162026-02-232026-06-03
organicrelease spikerelease tailorganic trend · 14d rolling median
Holding steady · -1% in the last year
74/day a year ago→73/day today
Reviews
what people actually sayTwo Factor Authentication is a generally well-regarded TOTP/authenticator-app-based 2FA plugin praised for ease of setup and responsive support, but it draws consistent criticism for locking essential features (like mandatory enforcement) behind a paid tier and offering no email-based one-time passcode option.
What people like
- +Easy to install, activate, and configure×4
- +Works reliably with Google Authenticator and other TOTP apps×5
- +Support team is responsive and persistent in resolving issues×3
- +Regularly updated and maintained over a long period×2
- +Works across multiple servers and WordPress installs without interference
Common complaints
- −Key features such as mandatory 2FA enforcement are locked behind the paid version, making the free version limited in practical use×2
- −No support for email-based one-time passcodes; requires users to install a third-party authenticator app×2
- −Setup failures reported: QR/barcode scanning errors and the plugin appearing to do nothing for certain user roles×2
- −No documentation or exposed hooks/actions for custom login form integration; additional paid work reportedly required for custom implementations
- −PHP 8 compatibility concerns raised by at least one user
- −User settings occupy a top-level admin menu item rather than a more appropriate location like the user profile page
- −Per-site annual licensing cost considered too high for developers managing multiple sites
Review trustMostly organic
- 4.47★Verified rating — holds steady vs the raw 4.40★
- 5%One-shot reviewers — most reviewers are active community members
- past spikeReview timing — up to 50% of all reviews landed in a single month
Reviews per month · 5★ vs lower
2023-09-182025-02-092026-06-04
5★ reviews1–4★ reviews
All-time ratings · 77 total
Latest reviews · 77 analyzed
- 2024-01-21★★★★★Nice plugin, Excellent plugin, works greatly like a charm.Emilio Lejit
- 2024-01-16★★★★★This plugin does not support OTP via email.lcastonguay
- 2024-01-06★★★★★Just workspave1
- 2023-08-26★★★★★Can't say enough good things about themgangof4
- 2022-09-16★★★★★Almost Worth Itkurtmanos
- 2022-04-04★★★★★Shortcode doesn't work.Mike1-shot
- 2022-02-07★★★★★EmpfehlenswertGünter Duba
- 2021-08-18★★★★★Nothing short of outstanding!ryazhari
- 2021-07-27★★★★★It did not work at allinfo2
- 2021-05-27★★★★★Invalid Barcodemahyulan
Releases
recent versions from WordPress.org SVNAlternatives to Two Factor Authentication
Top Security plugins, ranked by score.For developers & the curious
the raw signals behind the grade — none of this is on the friendly summary aboveDownload signals
Baselines are computed on organic days only — release spikes and their tails are excluded, so they're not inflated by the auto-update wave.
81
Baseline · median of last 7 organic days
73
Prior 7-day baseline
62
Floor · 25th percentile over 14 days
81
Latest day · 2026-06-03(organic)
+11.0%
Week-over-week organic trend
Review signals
Concentration and drive-by metrics drive the review-burst and fake-review flags. 30–40% solo reviewers is normal; we only flag the extremes.
50%
Max month share · biggest single 30-day window
3.43
Distribution CV · <0.6 even, >1.5 bursty
81%
5★ share in analyzed sample
5%
Solo reviewers · only this one wp.org activity
—
Volume velocity · last 6mo vs prior 6mo
4.39 → 4.47★
Sample avg · raw → solo-filtered