Pro · 2FA
WP Security Ninja
Make stolen passwords much less useful
Two-factor authentication for WordPress without a separate 2FA plugin. Require an authenticator app or email code for the roles you choose, with a grace period so your team is not locked out overnight.
- ✓ Authenticator apps
- ✓ Email codes
- ✓ Role or opt-in
Watch the walkthrough
Enable two-factor authentication, choose roles, and test the login flow.
How to Set Up 2FA in WordPress with WP Security Ninja
2FA the way real teams roll it out
Force 2FA for selected roles, or leave roles unchecked for opt-in only. Users can enable 2FA from their profile when you allow it.
- ✓ Required roles with optional grace period (default 14 days)
- ✓ Opt-in mode when you are not ready to require everyone
- ✓ Set grace period to 0 when required roles must enroll immediately
Authenticator app or email
Support the methods your users can actually complete. App setup includes a QR code plus a manual secret key. Email codes use Security Ninja’s shared email template for a consistent look.
- ✓ Time-based authenticator apps (Google Authenticator, Authy, and similar)
- ✓ Email verification codes when you allow that method
- ✓ Users pick app or email when both are allowed, and the preference is remembered
Admin control when someone gets stuck
Lost phone, new device, or a temporary exception? Admins can help without turning 2FA off for the whole site.
- ✓ Per-user Bypass 2FA checkbox on the WordPress profile
- ✓ Reset 2FA for one user from their profile
- ✓ Reset all users’ 2FA from Security Ninja Tools when you need a clean restart
Part of complete login hardening
2FA pairs with failed-login limits and rename login, the full Pro login protection suite.
- ✓ Brute-force limits
- ✓ Custom login URL
- ✓ Custom intro and enter-code text on the 2FA screen
Customer reviews
4.9 / 5 from 258 reviews
Excellent Plugin
“Security Ninja has everything and more of what you’d want in a security plugin. Some examples are the firewall, limited login attempts, malware scanner, logs, and alerts.”
So Glad to Find This
“WP Security Ninja Review I've been using WP Security Ninja for several weeks now, and I must say, it has exceeded all my expectations.”
Works well as a base security plugin
“WP Security Ninja stands out with a balanced and clear mix of features. It works well as an all-in-one solution but remains simple enough to combine with tools like Patchstack with…”
Amazingly user-friendly security plugin
“Thank you, Security Ninja! Your plugin is easy to use, provides clear reports of activity, and includes built-in tools that make security a lightweight task.”
Frequently asked questions
How do I add two-factor authentication to WordPress?+
Install Security Ninja Pro, open the 2FA settings, choose authenticator app and/or email codes, pick which roles must enroll, set a grace period if you need one, then have each user complete setup from their profile. Test one admin login before you require everyone.
What is two-factor authentication (2FA)?+
2FA adds a second step after the password. Even if someone steals or guesses a password, they still need a short code from an authenticator app or email before they can sign in.
Why should WordPress sites use 2FA?+
WordPress logins are a common target for password stuffing and brute-force attempts. A second factor makes stolen passwords much less useful, especially for administrators and editors.
Is 2FA included in Free?+
No. Two-factor authentication is a Security Ninja Pro feature.
Which 2FA methods does Security Ninja support?+
Authenticator apps (time-based one-time codes) and email codes. You choose which methods are allowed. When both are enabled, users pick one at login and that preference is remembered.
Can I require 2FA only for administrators?+
Yes. Choose which roles are required. Leave all roles unchecked if you want opt-in only, with no one forced to enroll.
What if a user loses their phone or authenticator app?+
An administrator can reset that user’s 2FA from their WordPress profile so they can enroll again. For special cases, admins can also enable Bypass 2FA on the profile. If email 2FA is allowed, that can be an alternate method.
Will my team get locked out the day I turn it on?+
Not if you use the grace period. Required-role users can skip setup for a set number of days (14 by default). Set it to 0 only when you want immediate enrollment.
Add 2FA to your WordPress logins
Pro includes 2FA, login limits, rename login, Cloud Firewall, and malware scanning.
Get Pro