Founding offer 50% off all plans for the first 100 customers, and your renewal price is locked for life. 74 spots left Claim your spot
Turquoise abstract wavy W logo on a black background
Turquoise abstract wavy W logo on a black background
White WP PowerSuite logo on a black background
White WP PowerSuite logo on a black background

Summarize with AI:

On This Page
Last updated: 24/07/2026

Two-Factor Authentication (2FA)

Two-factor login for selected roles—extra proof beyond the password.

Overview

A Pro Security module that adds two-factor login for selected roles—email OTP and/or authenticator (TOTP). Empty role list means nothing is enforced. Optional grace period and trusted devices (off by default). Default can require application passwords for REST/XML-RPC for enforced roles—soft conflict with Disable Application Passwords (that requirement is disabled when DAP is on). Temporary Login token logins bypass 2FA by design; Magic Login may optionally bypass (default off). Social login is a separate auth path. Requires a valid WP PowerSuite license.

Solid black square
Solid black square
Who is this for?
  • Admin/editor hardening on production sites
  • Agency client sites with privileged roles
  • Compliance-minded memberships with role selection

Features

Role-based enforcement
Require 2FA only for the roles you select.
Email OTP and/or TOTP
Choose email codes, authenticator apps, or both.
Attempt limits
Cap verify attempts; configurable email code TTL.
Optional grace / trusted devices
Off by default for stricter setups.
API awareness
Optional application-password requirement for REST/XML-RPC on enforced roles.
Documented bypass paths
Temporary Login (and optional Magic Login) can skip 2FA.

Use Cases

  • Protect administrators
    Enforce TOTP for administrator (and maybe editor) only.
  • Agency client baselines
    Require 2FA on privileged roles before handoff.
  • Email OTP for less technical staff
    Offer email codes when authenticator apps are a support burden.

Frequently Asked Questions

Related Modules

Keep a clear record of important dashboard activity—who logged in, what changed, and when—so you can investigate issues or stay audit-ready without...
Disabled
Closes the old XML-RPC channel many password-guessing tools still target. Fine for most sites; skip if you rely on legacy apps or...
Disabled
Removes WordPress version from public HTML generator tags, feed generator output, and the admin footer. Does not change ver= on script and...
Disabled
Remove the dashboard screens that let anyone edit theme or plugin code from the browser—one less disaster if an account is compromised.
Disabled
Slow down password-guessing bots by locking out repeated failed logins for increasing cool-off periods—simple protection for your sign-in form.
Disabled
Blocks risky default usernames during registration so bots have fewer easy targets.
Disabled
Always open your dashboard and login screen over a secure https:// link. Anyone using the old http:// address is sent to the...
Disabled
Tell modern browsers to enforce sensible safety rules—like blocking sneaky scripts and iframe tricks—with strong defaults you can tighten further for HSTS...
Disabled
Disables WordPress application passwords site-wide: blocks REST/XML-RPC login with app tokens and hides the profile UI. Normal account passwords and logged-in REST...
Disabled
Stops old-style trackbacks and pingbacks that often bring spam or junk alerts.
Disabled
Founding Member Offer 74 of 100 spots left

Before you go, here's what you'd be leaving.

WP PowerSuite launched this month. The first 100 customers get 50% off and keep that renewal price permanently. When the offer closes on 31 August 2026, prices return to $79 / $239 / $399 and stay there.

  • 154 modules, all included on every plan
  • Renewal price locked for life
  • 14-day refund, one email, no questions
See founding pricing
26 founding members so far 23 days left