WordPress.org
  • News
  • Showcase
  • Hosting
    • Themes
    • Plugins
    • Patterns
    • Blocks
    • Openverse ↗︎
    • Learn WordPress
    • Documentation
    • Forums
    • Developers
    • WordPress.tv ↗︎
    • Make WordPress
    • Education
    • Photo Directory
    • Five for the Future
    • Events
    • Job Board ↗︎
    • About WordPress
    • Enterprise
    • Gutenberg ↗︎
    • Swag Store ↗︎
  • Get WordPress
Get WordPress
WordPress.org

Plugin Directory

SecureAuth Authenticator 2FA

  • Submit a plugin
  • My favorites
  • Log in
  • Submit a plugin
  • My favorites
  • Log in

SecureAuth Authenticator 2FA

By Helmi
Download
  • Details
  • Reviews
  • Installation
  • Development
Support

Description

SecureAuth Authenticator 2FA enhances your WordPress login security by requiring a time-based one-time password (TOTP) in addition to the regular username and password. The TOTP code is generated by an authenticator app on your mobile device, adding an extra layer of protection even if your password is compromised.

This plugin is lightweight, secure, and easy to use. It integrates directly into the user profile page to allow users to set up and manage their two-factor authentication with ease.

Features:

  • Adds a TOTP (Time-Based One-Time Password) field to the login form.
  • User-friendly 2FA setup available on each user’s profile page.
  • Generates secret keys and displays QR codes for scanning with mobile apps.
  • Compatible with apps like Google Authenticator, Microsoft Authenticator, and Authy.
  • Secure handling with nonce verification and input sanitization.
  • No external libraries required (except Google Chart API for QR code).

Installation

  1. Upload the plugin files to the /wp-content/plugins/secureauth-authenticator-2fa directory or install the plugin through the WordPress plugin screen.
  2. Activate the plugin via the Plugins menu in WordPress.
  3. Navigate to Users > Your Profile and scroll to the SecureAuth Authenticator 2FA section.
  4. Scan the QR code using your mobile authenticator app and enable 2FA.
  5. On your next login, you’ll be prompted to enter the TOTP code from your app along with your password.

FAQ

What if I lose access to my authenticator app?

You should always save the secret key provided during setup in a secure location. If you lose access, a site administrator can disable 2FA for your account directly through the database or your user profile.

Does this plugin support recovery codes or backup options?

Not yet. This plugin is intentionally kept minimal to reduce complexity. However, recovery features may be added in future updates based on user feedback.

Which user roles can enable 2FA?

Currently, any logged-in user with access to their profile page can enable 2FA individually.

Is 2FA mandatory for all users?

No. As of version 1.0.0, 2FA is optional and must be enabled manually by each user.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“SecureAuth Authenticator 2FA” is open source software. The following people have contributed to this plugin.

Contributors
  • Helmi

Translate “SecureAuth Authenticator 2FA” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

1.0.0

  • Initial release.
  • Add TOTP-based 2FA support for WordPress login.
  • QR code generation using Google Chart API.
  • Secure nonce verification and input sanitization.

Meta

  • Version 1.0.0
  • Last updated 5 months ago
  • Active installations Fewer than 10
  • WordPress version 5.0 or higher
  • Tested up to 6.8.3
  • Tags
    2FAlogin securitytotptwo factor authenticationwordpress security
  • Advanced View

Ratings

No reviews have been submitted yet.

Add my review

See all reviews

Contributors

  • Helmi

Support

Got something to say? Need help?

View support forum

  • About
  • News
  • Hosting
  • Privacy
  • Showcase
  • Themes
  • Plugins
  • Patterns
  • Learn
  • Documentation
  • Developers
  • WordPress.tv ↗
  • Get Involved
  • Events
  • Donate ↗
  • Five for the Future
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org
  • Visit our X (formerly Twitter) account
  • Visit our Bluesky account
  • Visit our Mastodon account
  • Visit our Threads account
  • Visit our Facebook page
  • Visit our Instagram account
  • Visit our LinkedIn account
  • Visit our TikTok account
  • Visit our YouTube channel
  • Visit our Tumblr account
Code is Poetry