As of April 2026, Wordfence Login Security is a WordPress 2FA plugin with 70K+ active installations and a 4/5 rating from 25 reviews. It has been downloaded 1.2M+ times in total. Requires WordPress 4.7+ and PHP 7.0+. Available on WordPress.org since 2019. Last updated 1 year ago — may have compatibility concerns. Downloads are down 33% this week. Top alternative: Wordfence Security – Firewall, Malware….
Wordfence Login Security contains a subset of the functionality found in the full Wordfence plugin: Two-factor Authentication, XML-RPC Protection and Login Page CAPTCHA.
Are you looking for comprehensive WordPress Security? Check out the full Wordfence plugin.
Although I had 2FA set with the app, someone was able to hack my site, change my password, disable 2FA and install a malicious plugin.
Does not include the ability to limit login attempts, add password complexity requirements, or anything that would comprise modern security best practices. It’s strictly a 2FA plugin, which is done more simply and better by other plugins. It does work tho.
It is one of the few extensions that allows you to do this for free, I am very grateful to everyone at WordFence who works on this plugin. Thank you!
<font _mstmutation=”1″></font>The security of the admin panel is protected, thanks for such a shield against hacking
I have just installed it and look forward to complete its configuration soonest. From a brief outlook on the plugin functions they are sufficient and practical even for Woo users, if it is a case. I am only on a slighter disappointed side since the FIDO Trust Key option for 2FA isn’t on a list – for this I wish the developers to notice that this kind of security is simply ‘a Must’ these days for a reputable 2FA applications. Please add this function ASAP – even if in a paid plugin variation!
| WordPress | 4.7+ requiredTested up to 6.7.5 |
| PHP | 7.0+ required |
Plugin data sourced from WordPress.org. Analysis and metrics by PluginSift.