Make your WordPress login extra secure with One Time Passwords.
As of April 2026, WP-OTP is a WordPress 2FA plugin with 100 active installations and a 4/5 rating from 9 reviews. It has been downloaded 11K+ times in total. Requires WordPress 4.6+ and PHP 7.4+. Available on WordPress.org since 2016. Last updated 5 years ago — may have compatibility concerns. Top alternative: Wordfence Security – Firewall, Malware….
With WP-OTP you can easily set up 2 Factor Authentication with One Time Passwords for your WordPress login.
This extra layer makes your WordPress site a lot more secure.
The new stealth mode allows for invisible OTP code entry, making your login screen look like any other, no extra OTP code input field.
After installing and activating the plugin, every user can enable WP-OTP on their profile page.
It’s as easy as scanning the provided QR Code or entering the OTP secret to any OTP generator app.
Then just activate it by entering the generated OTP and voilà, all set up.
Now, the login requires an OTP code to succeed.
Each user gets their own secret key to authenticate with, giving them control over their login security.
This plugin is completely open source…
| WordPress | 4.6+ requiredTested up to 5.6.17 |
| PHP | 7.4+ required |
Plugin data sourced from WordPress.org. Analysis and metrics by PluginSift.