WordPress Two-Factor Authentication Setup: How to Turn It On
A stolen or guessed password is one of the easiest ways into a WordPress site. Two-factor authentication shuts that door. Here is how to turn it on, which method to choose, and how to make sure every admin uses it.
By Nathan Cross, Co-Founder, Network & Security Engineering·
Why a password alone is not enough
WordPress two-factor authentication setup matters because your login page sits at a predictable address, /wp-login.php or /wp-admin, and the whole internet can see it. Automated bots hammer those pages around the clock, trying common passwords and credentials leaked from other breaches. If one of your admin passwords has ever been reused on a site that got hacked, it is likely already on a list someone is testing against you right now.
Two-factor authentication (2FA, sometimes called MFA or two-step verification) adds a second proof of identity on top of the password: a one-time code from an app on your phone, for example. Even if an attacker has your password, they cannot log in without that second factor. The official WordPress hardening guidance lists strong authentication as a core defence (WordPress.org, Hardening WordPress).
For a small business this is one of the highest-value changes you can make, because the risk is not theoretical. In Verizon's 2025 DBIR, ransomware or extortion appeared in 88% of breaches at small and medium businesses, versus 39% at larger organizations (Verizon 2025 DBIR), and a compromised admin login is a common first step in those incidents.
Pick a 2FA plugin
WordPress does not ship with two-factor authentication built in, so you add it with a plugin. Several well-maintained, free options exist on the WordPress.org plugin directory. Look for one that is actively updated, has a large install base, and supports app-based codes (the standard called TOTP).
Common choices include the official Two-Factor plugin from the WordPress contributor team, WP 2FA, and the 2FA features bundled into broader security plugins like Wordfence or Solid Security. Any of these will do the job. If you already run a security plugin, check whether it includes 2FA before installing a second one, because overlapping plugins add maintenance and attack surface for no benefit.
Installation is the usual flow: in your dashboard go to Plugins, then Add New, search for the plugin, install and activate. From there each plugin adds a setup section, usually under Users, your profile, or a dedicated Settings menu.
App-based codes vs SMS
When you set up 2FA you will be asked to choose a method. The strongest practical option for most sites is an authenticator app. You install something like Google Authenticator, Microsoft Authenticator, Authy, or 1Password on your phone, scan a QR code the plugin shows you, and the app then generates a fresh six-digit code every thirty seconds. These codes are calculated on your device, so they work even with no signal and never travel over the network.
Text-message (SMS) codes are better than no second factor, but they are the weakest option. SMS can be intercepted, and attackers sometimes hijack a phone number through a SIM-swap scam to receive the codes themselves. If a plugin offers both, prefer the app. Reserve SMS for people who genuinely cannot use an app.
Some plugins also support email codes or hardware security keys. Email is convenient but only as secure as the mailbox behind it. Hardware keys (such as a YubiKey, using the WebAuthn standard) are the gold standard if you want to invest in them, and worth considering for the one or two accounts with full administrator rights.
Save your recovery codes
When you enable app-based 2FA, the plugin gives you a set of one-time backup codes, usually eight or ten of them. These are your way back in if you lose your phone, get a new device, or the authenticator app gets wiped. Do not skip this step. Locking yourself out of your own admin account is the most common 2FA mishap, and recovering access without the codes can mean editing the database or disabling the plugin over FTP.
Store the recovery codes somewhere safe and offline: a password manager entry, a printed copy in a drawer, or both. Do not paste them into a sticky note on the same laptop you log in from, and do not email them to yourself in plain text. Each code works once, so cross them off as you use them and regenerate a fresh set when you are running low.
It is also wise to have two people with working 2FA on any business site, or at least one trusted backup admin. That way a single lost phone never leaves the whole site stranded.
Enforce 2FA for every admin
Turning on 2FA for your own account is a good start, but it only protects your account. If another user with administrator or editor rights still logs in with a password alone, that account is the soft spot an attacker will aim for. The goal is to require 2FA for everyone who can change the site, not just leave it optional.
Most 2FA plugins let you enforce two-factor by role. Look in the plugin settings for an option like require 2FA for Administrators and Editors, often with a grace period (say seven days) that gives existing users time to set it up before they are locked out. Set the policy, pick a reasonable grace window, and tell your team it is coming.
While you are in there, prune the user list. Remove accounts for people who have left, downgrade anyone who does not need admin rights, and make sure every remaining high-privilege account has a unique strong password as well as 2FA. Fewer admins means fewer doors to defend.
Confirm it is actually working
After you enable and enforce 2FA, test it. Log out, log back in, and confirm the second-factor prompt appears and your code is accepted. Then ask each admin to do the same so nobody is silently still on password-only. A policy that is set but not actually applied to a stale account is a false sense of security.
This is exactly the kind of internal control that an outside scan cannot see. A free external scan tells you what attackers can probe from the public internet: your DNS, email authentication, TLS certificate, security headers, and exposed files. Whether 2FA is actually switched on for every admin lives inside WordPress. The same BadgerScan, upgraded to Pro, adds a read-only plugin that checks 2FA status, admin configuration, and exact plugin and theme versions from the inside, then fuses inside and outside into one plain-English grade. For the full picture of locking down a site, see our WordPress security guide and the small-business hardening checklist.
See whether your defences hold up from the outside
Two-factor authentication closes one of the biggest doors into your site. Run a free BadgerScan to check the rest: your DNS, email security, TLS, security headers, exposed files, and known CVEs. Upgrade to Pro and the read-only plugin confirms 2FA is on for every admin and grades the inside and outside as one plain-English report.
Run a free security scanFrequently asked questions
Does WordPress have built-in two-factor authentication?
No. Core WordPress does not include 2FA, so you add it with a plugin. Free, well-maintained options on the WordPress.org directory include the official Two-Factor plugin, WP 2FA, and the 2FA features inside security plugins like Wordfence or Solid Security. Pick one actively updated plugin rather than stacking several.
What happens if I lose the phone with my authenticator app?
You use one of the backup recovery codes the plugin gave you when you set up 2FA. Each code works once and lets you log in without the app. This is why you must save those codes somewhere safe and offline before you finish setup. If you have no codes and no backup admin, you may have to disable the plugin over FTP or edit the database to get back in.
Is SMS-based 2FA good enough?
It is far better than nothing, but it is the weakest method. SMS can be intercepted, and attackers sometimes hijack a phone number through a SIM-swap scam. Where a plugin offers it, prefer an authenticator app that generates codes on your device. Reserve SMS for users who genuinely cannot run an app.
How do I make sure every admin uses 2FA, not just me?
Most 2FA plugins let you enforce two-factor by user role, usually with a grace period. Turn on the require-2FA option for Administrators and Editors, set a reasonable window like seven days, and confirm each user has actually completed setup by having them log out and back in.