Enhanced login security for WordPress by requiring the presentation of a One Time Password (OTP) from a registered Yubikey
As of April 2026, Yubikey is a WordPress MFA plugin with 40 active installations and a 5/5 rating from 1 reviews. It has been downloaded 995 times in total. Requires WordPress 5.2+ and PHP false+. Available on WordPress.org since 2008. Top alternative: Two Factor.
This plugin dramatically enhances the security of your WordPress website by adding Multi Factor Authentication (MFA) in the form of One Time Passwords (OTP)
using Yubikey USB Tokens. In addition to providing your username and password to login, this plugin requests an OTP code
generated by a Yubikey, validates this via an API and only grants access if this check passes. The requirement to use an OTP can be set on a user by user
basis and there is also a feature to require users above a certain privilege level to always use OTP.
This plugin connects to an API to validate the OTP tokens generated by your security key. This is required because storing the private keys
on the same web server as the site you wish to protect would be a security risk.
By default Yubico’s…
| WordPress | 5.2+ requiredTested up to 6.8.5 |
| PHP | false+ required |
Plugin data sourced from WordPress.org. Analysis and metrics by PluginSift.