As of April 2026, DoLogin Security is a WordPress 2fa-login plugin with 7.0K+ active installations and a 4.5/5 rating from 13 reviews. It has been downloaded 163K+ times in total. Requires WordPress 4.0+ and PHP false+. Available on WordPress.org since 2019. Downloads are up 18% this week.
In one click, your WordPress login page will be pretected with the smart brute force attack protection! Any login attempts more than 6 in 10 minutes (default value) will be limited.
Limit the number of login attempts through both the login and the auth cookies.
Two-factor Authentication login.
Text SMS message passcode for 2nd step verification support.
Cloudflare Turnstile (better than Google reCAPTCHA).
GeoLocation (Continent/Country/City) or IP range to limit login attempts.
Passwordless login link.
Support Whitelist and Blacklist.
GDPR compliant. With this feature turned on, all logged IPs get obfuscated (md5-hashed).
WooCommerce Login supported.
XMLRPC gateway protection.
Call the function $link = function_exists( 'dologin_gen_link' ) ? dologin_gen_link( 'yo…
Extremely functional without extras or ads. Please keep giving us updates.
this plugin works very well
The Verify 2FA options and the SMS Auth have stopped working, that’s why I only give it two stars. I wait for a solution or if not I do not recommend anyone to install the plugin.
Passwordless login link option is simply amazing. Love this plugin.
This is a lightweight plugin that should be first on your list.
One request tho: would be nice to see a distinction made between successful logins, and unsuccessful logins and blocked logins.
| WordPress | 4.0+ requiredTested up to 6.8.5 |
| PHP | false+ required |
Plugin data sourced from WordPress.org. Analysis and metrics by PluginSift.