Easily add Duo Security two-factor authentication to your WordPress website. Enable two-factor authentication for your admins and/or users.
As of April 2026, Duo Two-Factor Authentication is a WordPress login plugin with 3.0K+ active installations and a 3.7/5 rating from 39 reviews. It has been downloaded 186K+ times in total. Requires WordPress 4.1+ and PHP false+. Available on WordPress.org since 2011. Downloads are down 17% this week. Top alternative: WPS Hide Login.
Duo Security provides two-factor authentication as a service to protect against account takeover and data theft. Using the Duo plugin you can easily add Duo two-factor authentication to your WordPress website in just a few minutes!
Rather than relying on a password alone, which can be phished or guessed, Duo’s authentication service adds a second layer of security to your WordPress accounts. Duo enables your admins or users to verify their identities using something they have—like their mobile phone or a hardware token—which provides strong authentication and dramatically enhances account security.
Duo is easy to setup and use. With Duo there’s no extra hardware or complicated software to install, just sign up for Duo’s service and install the plugin. Then you can set which user rol…
Love having this plugin because it adds an excellent layer of much needed security
This used to be an awesome plugin. It offered seamless integration with Duo, blocking admin access to my site in the case of a password compromise or brute force attack.
Sadly, it recently just stopped working. No Duo verification page, no errors in the logs; and the only way to get back into my site was ssh in and delete the plugin.
Duo has apparently given up on the plugin, according to their github repo.
They should just pull this plugin from listings.
Best 2FA addon for WordPress – if it wasn’t so neglected. No updates for half a year, no PHP 8. Too bad. Could have been so great. Now it’s out.
I use Duo Security for many different apps and it works great. The negative reviews typically mean the person is not familiar with how to implement Duo Security correctly.
The configuration and integration was super easy and I am using this for my Office 365 and VPN access as well. It’s great to be able to use a single MFA for multiple application.
| WordPress | 4.1+ requiredTested up to 6.0.11 |
| PHP | false+ required |
Plugin data sourced from WordPress.org. Analysis and metrics by PluginSift.