Skip to content

Admins log in with password only, no 2FA.

Single-factor login on WordPress is risk. Plugins like Wordfence Login Security, Two Factor or WP 2FA add TOTP in five minutes.

Try this first

  1. 1Pick a 2FA plugin: Wordfence Login Security (free), Two Factor (from Plugin Contributors, free) or WP 2FA. All work with Google Authenticator or Authy.
  2. 2Make it mandatory for all admin roles. Give users a week to set it up, after that no access without.
  3. 3Document recovery codes. Lost phone means lost access; storing recovery codes in a password manager is mandatory.
  4. 4Test on your own account first before forcing it on other admins. Nothing worse than locking yourself and the team out.
  5. 5Combine with strong passwords via a password manager. 2FA on a weak password is still risk under phishing.
  6. 6For low-risk roles (authors, editors) make 2FA optional or recommended, not mandatory. Friction should match risk.

When to bring us in

Handle customer data, finance, healthcare or government clients? Beyond 2FA, SSO (Microsoft Entra ID, Google Workspace) is sensible. That moves you toward WP SAML or Auth0.

See also

None of the above fits?

Describe your situation below. We pass your input plus the steps you already saw to our AI and return tailored next-step advice. If it's too risky to DIY, we'll say so.

Who are you?

For the AI question we need your email and company, so we can follow up if the AI gets stuck, and to prevent abuse.

Limited to 2 questions per hour and 5 per day, kept lean so the AI stays useful. For more, contacting us directly works better for you and us.

Or skip the DIY entirely

Our Managed IT clients do not look these things up. One point of contact, a fixed monthly price, resolved within working hours.