If you do exactly one thing to secure your site, this is it. Two-factor authentication on WordPress means a stolen password is no longer enough on its own — and stolen passwords are how most site compromises begin.
It also takes about ten minutes. The reason it gets skipped is almost always the same fear, so let us deal with that first.
"What if I lock myself out?"
This is a reasonable worry and it is entirely solvable. Every proper two-factor setup gives you recovery options, and the answer is to set them up at the same time rather than later.
Three safeguards, and you should have all three:
- Backup codes. Generated at setup, each usable once. Save them in your password manager or print them. Do not store them only on the phone running the authenticator
- A second administrator with their own two-factor set up, who can disable yours if needed
- File-level access. If everything fails, renaming the plugin folder via FTP disables two-factor entirely — see our guide to getting back into WordPress admin
With those in place, lockout is an inconvenience rather than a disaster.
Which method to use
Authenticator app — recommended
An app on your phone generates a six-digit code that changes every thirty seconds. Google Authenticator, Authy, 1Password and Bitwarden all do this.
It works offline, cannot be intercepted in transit, and is free. This is the sensible default for almost everyone.
Security key — strongest
A physical device you plug in or tap. Effectively immune to phishing, because the key verifies the site's identity before responding.
Worth it for high-value sites. The cost and the need to carry it make it a harder sell across a whole team.
Email codes — acceptable
Better than nothing, and a reasonable option for lower-privilege users. But it depends on your site being able to send email reliably, which many cannot — see our guide on email delivery problems. And if someone has compromised the email account, they have both factors.
SMS — the weakest option
Genuinely better than no second factor, but SIM-swapping attacks are real and phone networks are not a secure channel. Use it only where an app is not workable.
Setting it up
- Choose a plugin. Several well-maintained options exist, including WordPress's own two-factor plugin. Check it has been updated recently and supports app-based codes
- Set it up on your own account first and confirm you can log in with it before going further
- Save your backup codes somewhere that is not the phone running the authenticator
- Test a full logout and login in a private window
- Then roll it out to other privileged accounts
That second step matters. Enabling it site-wide before confirming your own setup works is how people end up locked out of their own site on a Friday afternoon.
Who needs it
Make it mandatory for administrators, editors and shop managers — anyone who can change the site, publish content, or see customer data.
For subscribers and customers on an ecommerce site, offer it rather than require it. Mandating it for shoppers costs you conversions, and their accounts are a smaller prize than an administrator's.
One administrator without two-factor undoes the protection for everyone. An attacker only needs the weakest privileged account.
This is worth being firm about with contractors and agencies. If someone has administrator access to your site, they are part of your security posture whether they think of themselves that way or not.
Rolling it out to a team
Some practical points that make this go smoothly.
Give people notice and a short written guide with screenshots — most resistance is uncertainty rather than objection. Set a deadline after which it is enforced, rather than leaving it optional indefinitely.
Make sure at least two people have working recovery access, so one person's lost phone is not a crisis. And have a documented process for when someone does lose their phone, because eventually someone will.
Also review your user list while you are at it. Rolling out two-factor is a natural moment to remove accounts belonging to people who left months ago — a task that otherwise never gets done.
What it does and does not protect against
It stops brute force attacks, credential stuffing using passwords leaked from other services, password spraying, and someone reusing a password they found in a breach dump. That is the large majority of login-based attacks.
It does not stop a vulnerable plugin being exploited, malware already present on the site, an attacker using a backdoor rather than the login page, or a session hijacked through cross-site scripting.
So it closes one category of attack completely, and leaves the others untouched. That is still an excellent return for ten minutes of work — but it belongs alongside prompt updates rather than instead of them.
Do not forget the other doors
WordPress admin is not the only way into your website. Enable two-factor on your hosting control panel, your domain registrar, the email account used for password resets, and your payment gateway.
The registrar and the reset email are the ones people miss. Both can be used to take control of everything else, regardless of how well your WordPress login is protected.
If you want it handled properly
Two-factor is one item on a short list of changes that deliver most of the practical security benefit. Our hardening checklist covers the rest in priority order.
If you would rather have the whole layer managed — two-factor, firewall, prompt patching, and alerts when a new administrator account appears — our security monitoring service covers it.
Get in touch and tell us how many people have admin access. That number is often the first thing worth fixing.
Get Shielded
We build, host, secure and monitor business websites — cleaning up hacks and keeping sites online for clients across the UK, USA, Australia and the UAE.