wp2shell: more than a month later. Confirm 6.8.6, 6.9.5, 7.0.2. Patched is not clean.

Read the advisory

Pro · 2FA

WP Security Ninja

Make stolen passwords much less useful

Two-factor authentication for WordPress without a separate 2FA plugin. Require an authenticator app or email code for the roles you choose, with a grace period so your team is not locked out overnight.

  • ✓ Authenticator apps
  • ✓ Email codes
  • ✓ Role or opt-in
Make stolen passwords much less useful

Watch the walkthrough

Enable two-factor authentication, choose roles, and test the login flow.

How to Set Up 2FA in WordPress with WP Security Ninja

2FA the way real teams roll it out

Force 2FA for selected roles, or leave roles unchecked for opt-in only. Users can enable 2FA from their profile when you allow it.

  • ✓ Required roles with optional grace period (default 14 days)
  • ✓ Opt-in mode when you are not ready to require everyone
  • ✓ Set grace period to 0 when required roles must enroll immediately
2FA setup docs

Authenticator app or email

Support the methods your users can actually complete. App setup includes a QR code plus a manual secret key. Email codes use Security Ninja’s shared email template for a consistent look.

  • ✓ Time-based authenticator apps (Google Authenticator, Authy, and similar)
  • ✓ Email verification codes when you allow that method
  • ✓ Users pick app or email when both are allowed, and the preference is remembered
User setup docs

Admin control when someone gets stuck

Lost phone, new device, or a temporary exception? Admins can help without turning 2FA off for the whole site.

  • ✓ Per-user Bypass 2FA checkbox on the WordPress profile
  • ✓ Reset 2FA for one user from their profile
  • ✓ Reset all users’ 2FA from Security Ninja Tools when you need a clean restart
Bypass and recovery docs

Part of complete login hardening

2FA pairs with failed-login limits and rename login, the full Pro login protection suite.

  • ✓ Brute-force limits
  • ✓ Custom login URL
  • ✓ Custom intro and enter-code text on the 2FA screen
Login protection overview

Customer reviews

4.9 / 5 from 258 reviews

Leave a review

Excellent Plugin

“Security Ninja has everything and more of what you’d want in a security plugin. Some examples are the firewall, limited login attempts, malware scanner, logs, and alerts.”

Cord VartyCord Varty

So Glad to Find This

“WP Security Ninja Review I've been using WP Security Ninja for several weeks now, and I must say, it has exceeded all my expectations.”

revtrevrevtrev

Works well as a base security plugin

“WP Security Ninja stands out with a balanced and clear mix of features. It works well as an all-in-one solution but remains simple enough to combine with tools like Patchstack with…”

bubdevbubdev

Amazingly user-friendly security plugin

“Thank you, Security Ninja! Your plugin is easy to use, provides clear reports of activity, and includes built-in tools that make security a lightweight task.”

joshuarbealjoshuarbeal

See all 258 reviews

Frequently asked questions

How do I add two-factor authentication to WordPress?+

Install Security Ninja Pro, open the 2FA settings, choose authenticator app and/or email codes, pick which roles must enroll, set a grace period if you need one, then have each user complete setup from their profile. Test one admin login before you require everyone.

What is two-factor authentication (2FA)?+

2FA adds a second step after the password. Even if someone steals or guesses a password, they still need a short code from an authenticator app or email before they can sign in.

Why should WordPress sites use 2FA?+

WordPress logins are a common target for password stuffing and brute-force attempts. A second factor makes stolen passwords much less useful, especially for administrators and editors.

Is 2FA included in Free?+

No. Two-factor authentication is a Security Ninja Pro feature.

Which 2FA methods does Security Ninja support?+

Authenticator apps (time-based one-time codes) and email codes. You choose which methods are allowed. When both are enabled, users pick one at login and that preference is remembered.

Can I require 2FA only for administrators?+

Yes. Choose which roles are required. Leave all roles unchecked if you want opt-in only, with no one forced to enroll.

What if a user loses their phone or authenticator app?+

An administrator can reset that user’s 2FA from their WordPress profile so they can enroll again. For special cases, admins can also enable Bypass 2FA on the profile. If email 2FA is allowed, that can be an alternate method.

Will my team get locked out the day I turn it on?+

Not if you use the grace period. Required-role users can skip setup for a set number of days (14 by default). Set it to 0 only when you want immediate enrollment.

Add 2FA to your WordPress logins

Pro includes 2FA, login limits, rename login, Cloud Firewall, and malware scanning.

Get Pro

Larger screenshot