BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
Google Authenticator icon
Actively maintained Tested with WP 7.1 #5 in authentication

Google Authenticator

Google Authenticator for your WordPress blog.

Active installs20K+10K+ tier
Downloads · 30d7.4K▼ -44.4% vs prev. 30d
Rating4.3/5135 reviews
Health score83/100Excellent
All-time downloads758.3KSince May 2011
Support resolved—No recent threads
RequiresWP 4.5PHP any
Downloads · 7d1.9K▲ +4.6% week over week
Our verdict

Safe pick

Yes — Google Authenticator is a safe, well-maintained plugin to use in 2026. It runs on 20K+ sites, is rated 4.3/5 and was last updated 1 month ago, and scores 83/100 on our health check.

  • Proven at scale on 20K+ active sites
  • Tested with the latest WordPress (7.1)

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

2K4K5.9KJun 29Aug 12Sep 26
Yesterday101
Daily average (1y)246
Peak day7,928Jul 28, 2026
Last 12 months89.6K

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where Google Authenticator stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
authentication #55 4,263 Best authentication plugins →
login >100 8,551 Best login plugins →
otp #25 384 Best otp plugins →
password #80 5,795 Best password plugins →
security >100 10,000 Best security plugins →

Version adoption

Share of active sites per release.

  • 0.5650.7%
  • 0.5431.0%
  • 0.558.9%
  • Other9.3%

Rating breakdown

★★★★★★★★★★ 4.3 from 135 reviews

  • 5★77.8%
  • 4★5.2%
  • 3★2.2%
  • 2★1.5%
  • 1★13.3%

About Google Authenticator

From the official readme · v0.56

Description

The Google Authenticator plugin for WordPress gives you two-factor authentication using the Google Authenticator app for Android/iPhone/Blackberry.

If you are security aware, you may already have the Google Authenticator app installed on your smartphone, using it for two-factor authentication on Gmail/Dropbox/Lastpass/Amazon etc.

The two-factor authentication requirement can be enabled on a per-user basis. You could enable it for your administrator account, but log in as usual with less privileged accounts.

If You need to maintain your blog using an Android/iPhone app, or any other software using the XMLRPC interface, you can enable the App password feature in this plugin,
but please note that enabling the App password feature will make your blog less secure.

Credits

Thanks to:

Miguel Mendez Z for responsibly disclosing a CSRF account lockout vulnerability.

Oleksiy for a bugfix in multisite.

Paweł Nowacki for the Polish translation

Fabio Zumbi for the Portuguese translation

Guido Schalkx for the Dutch translation.

Henrik.Schack for writing/maintaining versions 0.20 through 0.48

Tobias Bäthge for his code rewrite and German translation.

Pascal de Bruijn for his “relaxed mode” idea.

Daniel Werl for his usability tips.

Dion Hulse for his bugfixes.

Aldo Latino for his Italian translation.

Kaijia Feng for his Simplified Chinese translation.

Alex Concha for his security tips.

Jerome Etienne for his jquery-qrcode plugin.

Sébastien Prunier for his Spanish and French translation.

Installation

  1. Make sure your webhost is capable of providing accurate time information for PHP/WordPress, ie. make sure a NTP daemon is running on the server.
  2. Install and activate the plugin.
  3. Enter a description on the Users -> Profile and Personal options page, in the Google Authenticator section.
  4. Scan the generated QR code with your phone, or enter the secret manually, remember to pick the time based one.
    You may also want to write down the secret on a piece of paper and store it in a safe place.
  5. Remember to hit the Update profile button at the bottom of the page before leaving the Personal options page.
  6. That’s it, your WordPress blog is now a little more secure.

Frequently asked questions

Can I use Google Authenticator for WordPress with the Android/iPhone apps for WordPress?

Yes, you can enable the App password feature to make that possible, but notice that the XMLRPC interface isn’t protected by two-factor authentication, only a long password.

I want to update the secret, should I just scan the new QR code after creating a new secret?

No, you’ll have to delete the existing account from the Google Authenticator app on your smartphone before you scan the new QR code, that is unless you change the description as well.

I am unable to log in using this plugin, what’s wrong ?

The Google Authenticator verification codes are time based, so it’s crucial that the clock in your phone is accurate and in sync with the clock on the server where your WordPress installation is hosted. If you have an Android phone, you can use an app like ClockSync to set your clock in case your Cell provider doesn’t provide accurate time information Another option is to enable “relaxed mode” in the settings for the plugin, this will enable more valid codes by allowing up to a 4 min. timedrift in each direction.

I have several users on my WordPress installation, is that a supported configuration ?

Yes, each user has his own Google Authenticator settings.

During installation I forgot the thing about making sure my webhost is capable of providing accurate time information, I’m now unable to login, please help.

If you have SSH or FTP access to your webhosting account, you can manually delete the plugin from your WordPress installation, just delete the wp-content/plugins/google-authenticator directory, and you’ll be able to login using username/password again.

I don’t own a Smartphone, isn’t there another way to generate these secret codes ?

Yes, there is a webbased version here : https://gauth.apps.gbraad.nl/ Github project here : https://github.com/gbraad/gauth

Can I create backupcodes ?

No, but if you’re using an Android smartphone you can replace the Google Authenticator app with Authenticator Plus. It’s a really nice app that can import your existing settings, sync between devices and backup/restore using your sd-card. It’s not a free app, but it’s well worth the money.

Any known incompatabilities ?

Yes, the Man-in-the-middle attack/replay detection code isn’t compatible with the test/setup mode in the “Stop spammer registration plugin”, please remember to remove the “Check credentials on all login attempts” checkmark before installing my plugin.

Changelog

0.56

  • Fixed CSRF account lockout bug.

0.55

  • Improved PHP compatibility for PHP 7.4 through 8.5.
  • Fixed deprecated and strict runtime issues in plugin code.
  • Improved compatibility and safety of Base32 handling.

0.54

  • Fixed a bug in multisite.

0.53

  • Add a Polish translation

0.52

  • Add a Dutch translation
  • Add a Portuguese translation

0.51

  • Fix a regression that broke app passwords

Full changelog on WordPress.org →

Screenshots

The enhanced log-in box.
The enhanced log-in box.
Google Authenticator section on the Profile and Personal options page.
Google Authenticator section on the Profile and Personal options page.
QR code on the Profile and Personal options page.
QR code on the Profile and Personal options page.
Google Authenticator app on Android
Google Authenticator app on Android
Google Authenticator screenshot

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best Google Authenticator alternatives

All authentication plugins →
Alternatives
Rank Plugin Active installs Rating Updated Health
1 Limit Login Attempts Limit Login Attempts Limit rate of login attempts, including by way of cookies, for each IP. Fully customizable. by Automattic 300K+ ★★★★★★★★★★ 4.6 (202) 3 years ago 48
2 WPS Limit Login WPS Limit Login WPS Limit login limit connection attempts by IP address by NicolasKulka 100K+ ★★★★★★★★★★ 4.9 (83) 1 week ago 81
3 Two Factor Two Factor Enable Two-Factor Authentication (2FA) using time-based one-time passwords (TOTP), email… by WordPress.org 100K+ ★★★★★★★★★★ 4.8 (208) 6 months ago 60
4 WP-Members Membership Plugin WP-Members Membership Plugin The original WordPress membership plugin with content restriction, user login, custom… by Chad Butler 50K+ ★★★★★★★★★★ 4.6 (273) 3 weeks ago 89
6 miniOrange 2FA – Two Factor Authentication for WordPress (OTP, SMS, Email, Google Authenticator) miniOrange 2FA Free 2FA plugin for unlimited users with Passkey, Google Authenticator, Email/SMS OTP, Push… by miniOrange 10K+ ★★★★★★★★★★ 4.5 (385) 7 days ago 88
7 WP Limit Login Attempts WP Limit Login Attempts Limit rate of login attempts and block IP temporarily. Brute force attack protection. GDPR… by Arshid 10K+ ★★★★★★★★★★ 4.6 (300) 2 weeks ago 88
8 Login for Google Apps Login for Google Apps Simple secure login and user management through your Google Workspace for WordPress (using… by Syed Balkhi 10K+ ★★★★★★★★★★ 4.6 (64) 1 year ago 54
9 Login by Auth0 Login by Auth0 Login by Auth0 provides improved username/password login, Passwordless login, Social login… by Auth0 10K+ ★★★★★★★★★★ 3.1 (18) 2 years ago 34
10 Two Factor (2FA) Authentication via Email Two Factor (2FA) Authentication via Email Enable one-click login with this WordPress Two-Factor Authentication (2FA) plugin… by Sully 9K+ ★★★★★★★★★★ 5 (4) 2 weeks ago 83
11 WP SAML Auth WP SAML Auth SAML authentication for WordPress. by Pantheon Systems 7K+ ★★★★★★★★★★ 4.5 (8) 2 months ago 77

FAQ

Google Authenticator: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Sep 27, 2026

Is Google Authenticator free?

Yes. Google Authenticator is free to download and use from the official WordPress.org plugin directory.

Is Google Authenticator safe to use in 2026?

Yes — Google Authenticator is a safe, well-maintained plugin to use in 2026. It runs on 20K+ sites, is rated 4.3/5 and was last updated 1 month ago, and scores 83/100 on our health check.

How many websites use Google Authenticator?

Google Authenticator is active on 20K+ WordPress websites and has been downloaded 758,305 times since it launched in May 2011. It was downloaded 7,433 times in the last 30 days.

Does Google Authenticator work with WordPress 7.1?

Yes. The developer has tested Google Authenticator up to WordPress 7.1.2, the latest release. It requires WordPress 4.5 or newer.

When was Google Authenticator last updated?

The latest version, 0.56, was released on August 23, 2026 (1 month ago).

Who makes Google Authenticator?

Google Authenticator is developed and maintained by Ivan.

What are the best alternatives to Google Authenticator?

The most popular alternatives to Google Authenticator are Limit Login Attempts (300K+ installs), WPS Limit Login (100K+ installs) and Two Factor (100K+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.