Two-Factor Authentication
Add an extra layer of login security with TOTP-based 2FA. Even if passwords are compromised, accounts stay protected.
Why Two-Factor Authentication Matters
Passwords alone aren't enough to protect your WordPress site. Data breaches expose billions of credentials, and attackers use sophisticated techniques to guess or steal passwords.
Two-factor authentication adds a second verification step that requires something you have (your phone) in addition to something you know (your password). Even if an attacker obtains your password, they can't access your account without the time-based code from your authenticator app.
Stops Password Attacks
Brute force attacks, phishing, and credential stuffing become ineffective when 2FA is enabled.
Industry Standard
TOTP (Time-based One-Time Password) is the same technology used by banks and major tech companies.
Time-Limited Codes
Codes expire every 30 seconds. Even if intercepted, they're useless within moments.
Works Offline
Authenticator apps generate codes locally. No SMS delays or cellular signal required.
Compatible Authenticator Apps
GuardPress's 2FA works with any TOTP-compatible authenticator app. Here are some popular options:
Google Authenticator
iOS & Android
Authy
iOS, Android, Desktop
Microsoft Authenticator
iOS & Android
1Password
All Platforms
Any app that supports TOTP (RFC 6238) will work with GuardPress. This includes password managers like Bitwarden, LastPass, and Dashlane.
How 2FA Setup Works
Setting up two-factor authentication using apps such as Google Authenticator, Authy, or Microsoft Authenticator. According to Microsoft, 2FA blocks 99.9% of automated attacks. We implemented takes less than a minute. Users can enable it from their WordPress profile.
Enable 2FA
The user navigates to their profile and clicks "Enable Two-Factor Authentication". A QR code is displayed.
Scan QR Code
Using their authenticator app, the user scans the QR code. This adds your site to their app and syncs the secret key.
Verify Code
The user enters the 6-digit code from their app to confirm setup. This ensures the app is synced correctly.
Save Recovery Codes
Backup codes are generated in case the user loses access to their authenticator app. These should be stored securely.
2FA Features
- Per-Role Enforcement: Require 2FA for administrators while keeping it optional for other roles, or enforce it site-wide.
- Grace Period: Give users a set number of days to enable 2FA before they're locked out.
- Recovery Codes: One-time backup codes ensure users can regain access if they lose their authenticator device.
- Trusted Devices: Option to remember devices for a set period to reduce friction for daily logins.
- Admin Override: Administrators can reset 2FA for users who've lost access to their authenticator.
- Branding: Your site name and logo appear in users' authenticator apps for easy identification.
- Login Form Integration: Clean, styled 2FA prompt that matches your WordPress login page.
- App Password Support: Generate application-specific passwords for tools that don't support 2FA.
Secure Your Logins Today
Get Two-Factor Authentication and all other GuardPress Pro features with a single license.