WordPress OSINT, maintenance or security needs? Reach out!
TLDWP

Plugin: two-factor-authentication (Used by 38 domains)

Two Factor Authentication

Secure WordPress login with this two factor authentication (TFA / 2FA) plugin. Users for whom it is enabled will require a one-time code in order to log in. From the authors of UpdraftPlus – WP’s #1 backup/restore plugin, with over two million active installs.

Are you completely new to TFA? If so, please see our FAQ.

Features (please see the “Screenshots” for more information):

  • Supports standard TOTP + HOTP protocols (and so supports Google Authenticator, Authy, and many others).
  • Displays graphical QR codes for easy scanning into apps on your phone/tablet
  • TFA can be made available on a per-role basis (e.g. available for admins, but not for subscribers)
  • TFA can be turned on or off by each user
  • TFA can be required for specified user levels, after a defined time period (e.g. require all admins to have TFA, once their accounts are a week old) (Premium version), including forcing them to immediately set up (by redirecting them to the page to do so)
  • Supports front-end editing of settings, via [twofactor_user_settings] shortcode (i.e. users don’t need access to the WP dashboard). (The Premium version allows custom designing of any layout you wish).
  • Site owners can allow “trusted devices” on which TFA codes are only asked for a chosen number of days (instead of every login); e.g. 30 days (Premium version)
  • Encrypt the TFA-generating secret keys using an on-disk encryption key, so that an attacker would need to break into both your WordPress database and your files in order to break TFA codes (as well as breaking a user’s password in order to use them)
  • Works together with “Theme My Login” (both forms and widgets)
  • Includes support for the WooCommerce and Affiliates-WP login forms
  • Includes support for Ultimate Membership Pro
  • Includes support for CozmosLabs Profile Builder
  • Includes support for Ultimate Member login forms (Premium version)
  • Includes support for Elementor Pro login forms (Premium version)
  • Includes support for bbPress login forms (Premium version)
  • Includes support for Easy Digital Downloads login forms (Premium version)
  • Includes support for RegistrationMagic login forms (Premium version)
  • Includes support for login forms from the Gravity Forms User Registration add-on (Premium version)
  • Includes support for login forms (shortcode forms only) from Paid Memberships Pro (Premium version)
  • Includes support for any and every third-party login form (Premium version) without any further coding needed via appending your TFA code to the end of your password
  • Does not mention or request second factor until the user has been identified as one with TFA enabled (i.e. nothing is shown to users who do not have it enabled)
  • WP Multisite compatible (plugin should be network activated)
  • Simplified user interface and code base for ease of use and performance
  • Added a number of extra security checks to the original forked code
  • Alert users if someone appears to have found out their password, as indicated by successfully entering a password but repeatedly entering an incorrect TFA code.
  • Emergency codes for when you lose your phone/tablet (Premium version)
  • When using the front-end shortcode (Premium version), require the user to enter the current TFA code correctly to be able to activate TFA
  • Works together with “WP Members” (shortcode form)
  • Administrators can access other users’ codes, and turn them on/off when needed (Premium version)

Why use TFA / 2FA ?

Read this! https://www.wired.com/2012/08/apple-amazon-mat-honan-hacking/

How Does TFA / 2FA Work?

This plugin uses the industry standard TFA / 2FA algorithm TOTP or HOTP for creating One Time Passwords. These are used by Google Authenticator, Authy, and many other OTP applications that you can deploy on your phone etc.

A TOTP code is valid for a certain time. Whatever program you use (i.e. Google Authenticator, etc.) will show a different code every so often.

Plugin Notes

This plugin began life in early 2015 as a friendly fork and enhancement of Oscar Hane’s “two factor auth” plugin.

DomainExposuresHeadersLast Checked
g*n*u*a*d.de (WP 6.8.5) A 2026-05-16 08:09:34
t*a*a*i*.de (WP 6.9.4) F 2026-05-13 11:08:05
e*p*r*t*x*.com (WP 6.9.4) B 2026-05-12 18:24:41
s*o*.v*r*p*n*h*f.at (WP 6.9.4) F 2026-05-12 16:27:46
f*r*i*a*i*a.to F 2026-05-12 08:13:49
s*h*u*l*.de (WP 6.0.9) ⚠️ F 2026-05-12 01:50:19
j*v*m*s*o*l*n*.com (WP 6.9.4) F 2026-05-10 20:11:25
c*l*e*t*d*r*n*i*n*s.com B 2026-05-09 23:02:42
s*i*h*.eu F 2026-05-09 20:00:44
z*c*e*f*e*.store (WP 6.9.4) F 2026-05-09 14:34:48
l*y*l*e*z*n*.com (WP 6.4.1) ⚠️ F 2026-05-09 07:14:25
l*x*c*e*t*o*.com (WP 6.8.3) D 2026-05-09 04:16:20
w*b*o*p*u*.com D 2026-05-08 22:30:59
w*x*a*o*l*.site (WP 6.9.4) D 2026-05-08 16:22:56
p*o*e*t*v*q*a*i*y*o*u*i*n*.com F 2026-05-08 12:40:52
m*c*f*e*c*s*.com (WP 6.9.4) F 2026-05-07 20:11:13
f*a*w*r*d*n*.com F 2026-05-07 16:32:30
s*h*u*l*.com (WP 6.0.9) ⚠️ F 2026-05-07 11:33:59
s*n*y*l*n*s.com (WP 6.9.4) F 2026-05-06 17:50:29
k*f*e*c*s*.de (WP 6.9.4) F 2026-05-04 05:05:15
e*u.u*t*m*1*1.com 🔓 C 2026-05-03 22:39:05
m*d*e*.d*t*r*a*v*r*g*.se (WP 6.8.5) F 2026-05-03 11:05:32
a*n*t*m*r*n*e.com F 2026-05-03 00:59:38
u*b*n*a*a*t*o*k*.com (WP 6.9.4) F 2026-05-02 01:18:39
n*g*l*e*u*y.com 🔓 F 2026-05-01 13:32:27
f*e*s*y*e*e*s*i.com (WP 6.9.4) F 2026-04-30 21:39:07
b*s*t*l.net (WP 6.9.4) F 2026-04-30 17:11:47
c*s.l*r*d*.com (WP 6.9.4) F 2026-04-26 23:50:47
k*n*h*.com F 2026-04-26 15:37:11
t*a*a*i*.com (WP 6.9.4) F 2026-04-25 17:21:28
f*a*w*r*d*o.com F 2026-04-25 12:06:41
a*n*t*m*r*n*e.fr F 2026-04-25 12:03:20
d*d*k*o*.store (WP 6.9.4) F 2026-04-25 08:26:01
w*x*a*l*n*t.com D 2026-04-20 13:30:02
a*u*r*u*m*s*.com (WP 6.9.4) F 2026-04-19 20:24:50
s*a*r*z*c*d*m*.com D 2026-04-18 19:01:25
k*i*z*c*e*.com (WP 6.9.4) F 2026-04-17 12:16:55
o*i*e*-*t*c*t.com F 2026-04-17 10:16:10
c*t*j*r*u*p*i*s.com (WP 6.1.10) ⚠️ F 2026-04-12 00:14:34

Top 50 Plugins

Plugin Count
elementor 1,721,105
contact-form-7 1,685,294
elementor-pro 999,304
woocommerce 786,554
revslider 599,384
jetpack 452,954
js_composer 415,749
wp-rocket 316,029
essential-addons-for-elementor-lite 273,477
gravityforms 253,022
complianz-gdpr 233,053
instagram-feed 217,924
cookie-law-info 214,766
google-site-kit 208,279
google-analytics-for-wordpress 207,615
sitepress-multilingual-cms 207,409
header-footer-elementor 204,164
elementskit-lite 193,554
bluehost-wordpress-plugin 188,313
gutenberg-core 156,721
gutenberg 154,225
cookie-notice 134,382
wpforms-lite 129,474
the-events-calendar 123,907
astra-sites 120,822
gtranslate 120,541
litespeed-cache 120,096
popup-maker 112,422
woocommerce-payments 110,228
tablepress 97,979
coblocks 97,532
all-in-one-seo-pack 91,440
astra-addon 90,261
honeypot 89,704
wp-smushit 89,582
LayerSlider 88,978
bb-plugin 88,239
duracelltomi-google-tag-manager 87,158
premium-addons-for-elementor 83,317
akismet 83,190
cleantalk-spam-protect 81,961
mailchimp-for-wp 81,116
megamenu 80,003
woocommerce-gateway-stripe 79,195
fusion-builder 76,704
formidable 75,232
ewww-image-optimizer 73,968
gravityformsrecaptcha 73,146
smart-slider-3 73,145
wp-pagenavi 72,189

Top 50 Themes

Theme Count
hello-elementor 586,319
Divi 493,535
astra 411,315
Avada 119,968
flatsome 117,032
generatepress 110,901
pub 108,048
oceanwp 79,829
kadence 73,971
enfold 68,268
salient 64,353
h4 55,377
twentyseventeen 54,074
bb-theme 53,829
twentytwentyfour 52,480
cocoon-master 51,035
betheme 49,803
blocksy 47,624
dt-the7 43,668
twentytwentyfive 42,467
neve 37,346
Avada-Child-Theme 35,891
gox 32,235
twentytwentyone 32,055
bridge 31,862
woodmart 31,423
lightning 29,188
twentytwenty 29,181
swell 27,115
Impreza 24,772
twentytwentythree 24,425
bricks 24,393
Newspaper 21,625
twentytwentytwo 20,164
epik-redesign 19,414
uncode 18,009
pro 17,590
twentysixteen 17,501
storefront 17,162
extendable 16,272
sydney 16,178
Total 14,023
yith-wonder 13,972
voxel 13,866
themify-ultra 12,752
hello-theme-child-master 12,405
hestia 12,206
twentynineteen 12,120
yootheme 12,020
factory-templates-4 11,860