BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off β†’
SecondGate icon
Actively maintained Tested with WP 7.1 #95 in 2FA

SecondGate

Passkeys, 2FA, brute-force protection, and country blocking, with real crawlers auto-verified and exempted. No account required, ever.

Active installs<10New
Downloads Β· 30d116β–Ό -34.8% vs prev. 30d
Ratingβ€”0 reviews
Health score64/100Good
All-time downloads187Since Aug 2026
Support resolvedβ€”No recent threads
RequiresWP 6.0PHP 7.2+
Downloads Β· 7d17β–² +13.3% week over week
Our verdict

Solid choice

SecondGate is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 4 weeks ago, and scores 64/100 on our health check.

  • Actively developed β€” last update 4 weeks ago
  • Tested with the latest WordPress (7.1)
  • Small user base (<10 active installs)
  • Very few reviews so far

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

81725Aug 23Sep 10Sep 28
Yesterday3
Daily average (1y)5
Peak day34Aug 23, 2026
Last 12 months195

Download spikes usually follow a new release β€” each site that auto-updates counts as a download.

Rankings

Where SecondGate stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
2FA >100 408 Best 2FA plugins β†’
geo block >100 572 Best geo block plugins β†’
passkeys #33 103 Best passkeys plugins β†’
security >100 10,000 Best security plugins β†’
two factor authentication >100 423 Best two factor authentication plugins β†’

About SecondGate

From the official readme Β· v1.1.8.1

Description

This plugin’s free tier is permanent: passkeys, 2FA, brute-force protection, and country blocking are all included, with no artificial limitation and no time-limited trial.

At a glance

  • Passkeys (WebAuthn) β€” Face ID, Touch ID, Windows Hello, or a hardware key, bound to your exact domain so it can’t be phished
  • Standard TOTP two-factor authentication β€” works with Google Authenticator, Authy, 1Password, Bitwarden, and any other standard authenticator app
  • Trusted devices β€” skip the 2FA prompt on a recognised device for 30 days, one click to forget it
  • Brute-force login protection β€” automatic IP and username lockout after repeated failed attempts, never locking out the real account owner
  • Country blocking β€” blacklist or whitelist, 166 countries, IPv4 + IPv6, matched locally against downloaded range data, no third-party lookup at request time
  • Verified crawler exemption β€” Googlebot, Bingbot, and other real search crawlers are automatically exempt from every block, confirmed via reverse+forward DNS rather than a fakeable user-agent string, so a blocking rule doesn’t accidentally catch a genuine crawler

Why it works differently under the hood

Every check runs locally, on your own server. No API keys, no third-party accounts, no telemetry sent anywhere. Country IP range data is downloaded once a day from public sources and matched against visitors entirely on your own site β€” nothing about your traffic is ever sent to us or anyone else.

Two-factor authentication is generated and verified entirely on your own server too. TOTP codes and passkey credentials never leave your site.

The one thing worth knowing about crawler verification

Blocking traffic by country is only safe if it can’t accidentally catch Google. Most plugins check this by trusting whatever a visitor’s browser claims to be β€” but any visitor can set their User-Agent to say “Googlebot,” which means that check can be bypassed by anyone, and doesn’t actually protect your SEO the way it looks like it does.

This plugin verifies real crawlers properly instead: a reverse-DNS lookup on the connecting IP, confirming the hostname belongs to the crawler’s real network, then a forward-DNS lookup confirming that hostname resolves back to the same IP. That’s the method Google’s own documentation recommends for verifying a crawler is genuine β€” not a name anyone could fake.

External Services

This plugin connects to two external sources, both required for the plugin to function, both with no account or API key:

GitHub (raw.githubusercontent.com) β€” for downloading country IP range data used by country blocking. A plain GET request for a static public file, fetched once daily and matched locally afterward. No data about your site or its visitors is sent as part of this request.

DNS lookups (not an HTTP call to any specific company) β€” when a visitor’s browser claims to be a known search crawler (Googlebot, Bingbot, etc.), this plugin performs a standard reverse+forward DNS lookup on that visitor’s IP, using your server’s normal DNS resolver, to verify the claim is real before exempting it from blocking. This is the same kind of lookup any web server does routinely; no data about your site or its visitors is sent anywhere as part of it.

Two-factor authentication makes no external service calls whatsoever β€” TOTP codes and passkey verification happen entirely on your own server.

GitHub’s terms: https://docs.github.com/en/site-policy/github-terms/github-terms-of-service

Installation

  1. Upload the plugin files to /wp-content/plugins/secondgate, or install directly through the WordPress plugins screen.
  2. Activate the plugin through the ‘Plugins’ screen in WordPress.
  3. Go to Settings β†’ IP Block to configure country blocking, and Settings β†’ 2FA & Login Security for two-factor authentication settings.
  4. Each user sets up their own 2FA/passkey individually from their own profile page (Users β†’ your name β†’ Two-Factor Authentication).

Frequently asked questions

Is this actually free, or is there a premium version?

The features listed above are free, permanently, with no artificial limitation. A separate paid product, SecondGate Pro, exists as its own standalone plugin sold independently β€” it is never required for this plugin to work, and nothing in this plugin is disabled, nagged, or time-limited to push you toward it.

Does this need an API key or account, for anything?

No. Nothing in this plugin requires an account, an API key, or any third-party sign-up.

Is my server behind Cloudflare or a load balancer β€” will blocking still work correctly?

By default this plugin only trusts your server’s real connecting IP address (REMOTE_ADDR), which a visitor cannot forge. If you’re behind a proxy or CDN that rewrites the visitor’s real IP into a header, you can explicitly enable and select that header in Advanced settings β€” off by default, since trusting the wrong header by default is a well-documented vulnerability class in software that does IP-based blocking.

Will this affect SEO?

No β€” blocking only affects visitors from blocked sources viewing the site. Real search crawlers (Googlebot, Bingbot, and others) are automatically exempt from every blocking mechanism in this plugin, verified via reverse+forward DNS rather than trusting a user-agent string that anyone could fake β€” so a country rule that would normally apply is designed not to catch a genuine crawler.

What if I lose my phone and can’t get a 2FA code?

Use one of the backup codes generated when you first set up two-factor authentication, then set up 2FA again on your new device.

Is this a full security firewall, like Wordfence or Sucuri?

No β€” this plugin covers authentication (passkeys, 2FA, brute-force protection) and geo-blocking. It is not a web application firewall and does not scan for malware.

Does this work with WordPress Multisite?

This has not been tested on Multisite. It’s built and tested against standard single-site WordPress installs.

Changelog

Every entry below is a real, dated, one-line summary. The full detail for each, exactly what was found, how it was confirmed, and what testing backs it, lives on Pro’s security testing methodology page (this plugin shares real, tested code with Pro, and most fixes here are direct ports of the same real bugs found and fixed there), which has no length limit and is the authoritative record.

1.1.8.1

Real, complete fix, closed at both layers, not just documented: a cached page could later be served, unchanged, to a visitor who should now be blocked, if the block list changed after the cache was created. Now sets DONOTCACHEPAGE (reaching WordPress-plugin-based caches) AND sends a real Cache-Control header via nocache_headers() (reaching CDNs, reverse proxies, and server-level caches too, since that’s genuine HTTP protocol semantics, not a WordPress-only convention), whenever any blocking mechanism is active, for every visitor, not just a blocked one. Confirmed with real tests. Worth the honest trade-off: no page can be cached by any layer as long as blocking is configured, a deliberate choice, since a stale, wrongly-served page is worse than a slower one.

1.1.8

Two real, confirmed race conditions ported from Pro (brute-force lockout and daily stats, both fixed with real file locking after a real multi-process test confirmed the original code lost increments under concurrent load); the deny-list capped for consistency.

1.1.7

A step-by-step modal wizard added over the existing 2FA setup flow. Three real bugs found and fixed through hands-on testing: a false unsaved-changes browser prompt, stale cached JS/CSS after an update, and a setup flag not clearing on the faster path.

1.1.6

Ported the new-country login alert fix from Pro’s Session Guard work; the underlying detection mechanism didn’t exist here at all until this version, a full port, not a redirected function call.

1.1.5

A real gap found and fixed: the 2FA security-notification email used the raw connecting IP instead of this plugin’s own trusted-proxy-aware resolver, even though it was available. Independent static analysis run against this plugin’s own code.

1.1.4

The optional per-request log moved from a predictable, unprotected file path to options storage. All inline script/style output converted to WordPress’s own enqueue APIs.

Full changelog on WordPress.org β†’

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own β€” no account needed.

Active installs badge Rating badge Health score badge

Best SecondGate alternatives

All 2FA plugins β†’
Alternatives
Rank Plugin Active installs Rating Updated Health
1 Wordfence Security – Firewall, Malware Scan, and Login Security Wordfence Security Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by… by Mark Maunder 5M+ β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜… 4.7 (5K) 3 weeks ago 96
2 Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) Really Simple Security Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA)… by Really Simple Plugins 3M+ β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜… 4.9 (8.9K) 2 weeks ago 97
3 Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention Limit Login Attempts Security WordPress login security with brute force protection, Two-factor authentication (2FA/MFA)… by WPChef 1M+ β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜… 4.8 (1.5K) 6 days ago 91
4 Two Factor Two Factor Enable Two-Factor Authentication (2FA) using time-based one-time passwords (TOTP), email… by WordPress.org 100K+ β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜… 4.8 (208) 2 days ago 88
5 WP 2FA – Two-factor authentication for WordPress WP 2FA – Two-factor authentication for WordPress Get better WordPress login security; add two-factor authentication (2FA) for all your users… by Melapress 100K+ β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜… 4.7 (179) 2 months ago 80
6 WP Hide & Security Enhancer WP Hide & Security Enhancer Protect your website by concealing vulnerable WordPress traces, plugins, themes… by nsp-code 50K+ β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜… 4.3 (275) 6 days ago 92
7 Security Plugin, Firewall & Malware Scanner with Auto Removal Security Plugin, Firewall & Malware Scanner with Auto Remov… Protect WordPress from malware, hackers, brute-force attacks & suspicious traffic. Includes… by CleanTalk Inc 40K+ β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜… 4.8 (391) 3 hours ago 92
8 Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning Shield Security Smart WordPress security that blocks bots automatically, guides you to what matters, and… by Paul 30K+ β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜… 4.8 (1K) 1 week ago 94
9 Two Factor Authentication Two Factor Authentication Secure WordPress login with Two Factor Authentication - supports WP, Woo + other login… by David Anderson / Team Updraft 20K+ β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜… 4.4 (77) 2 months ago 83
10 Login With Ajax – Fast Logins, 2FA, Redirects Login With Ajax – Fast Logins, 2FA, Redirects Add beautiful login forms with smooth AJAX login/registration effects, 2FA support, custom… by Marcus (aka @msykes) 10K+ β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜… 4.6 (166) 4 months ago 62

FAQ

SecondGate: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org Β· checked Sep 29, 2026

Is SecondGate free?

Yes. SecondGate is free to download and use from the official WordPress.org plugin directory.

Is SecondGate safe to use in 2026?

SecondGate is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 4 weeks ago, and scores 64/100 on our health check.

How many websites use SecondGate?

SecondGate is active on <10 WordPress websites and has been downloaded 187 times since it launched in August 2026. It was downloaded 116 times in the last 30 days.

Does SecondGate work with WordPress 7.1?

Yes. The developer has tested SecondGate up to WordPress 7.1.2, the latest release. It requires WordPress 6.0 or newer.

What PHP version does SecondGate need?

SecondGate requires PHP 7.2 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was SecondGate last updated?

The latest version, 1.1.8.1, was released on September 3, 2026 (4 weeks ago).

Who makes SecondGate?

SecondGate is developed and maintained by SecondGateWP.

What are the best alternatives to SecondGate?

The most popular alternatives to SecondGate are Wordfence Security (5M+ installs), Really Simple Security (3M+ installs) and Limit Login Attempts Securi… (1M+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages β€” with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org β€” no credit card
Sarah is here to help!
Hi there! πŸ‘‹ Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! πŸ‘‹ Need help finding what you're looking for?

We'll use this to continue our conversation

Just now βœ“ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.