WP-OTP
With WP-OTP you can easily set up 2 Factor Authentication with One Time Passwords for your WordPress login. This extra layer makes your WordPress site a lot more secure.
Consider an alternative
WP-OTP shows warning signs in 2026 — compare the alternatives below before installing. It runs on 100+ sites, is rated 4/5 and was last updated 6 years ago, and scores 33/100 on our health check.
- Small user base (100+ active installs)
- No update in 5 years
- Only tested up to WordPress 5.6 (latest is 7.1)
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where WP-OTP stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| 2FA | >100 |
| login | >100 |
| otp | >100 |
| totp | >100 |
| two factor | >100 |
Version adoption
Share of active sites per release.
Rating breakdown
★★★★★★★★★★ 4 from 9 reviews
About WP-OTP
From the official readme · v0.6.1Description
With WP-OTP you can easily set up 2 Factor Authentication with One Time Passwords for your WordPress login.
This extra layer makes your WordPress site a lot more secure.
The new stealth mode allows for invisible OTP code entry, making your login screen look like any other, no extra OTP code input field.
Getting started
After installing and activating the plugin, every user can enable WP-OTP on their profile page.
It’s as easy as scanning the provided QR Code or entering the OTP secret to any OTP generator app.
Then just activate it by entering the generated OTP and voilà, all set up.
Now, the login requires an OTP code to succeed.
Each user gets their own secret key to authenticate with, giving them control over their login security.
Development
This plugin is completely open source and a work of passion.
If you would like to be part of it and join in, make your way over to the project page now.
Also, if you have an idea you would like to see in this plugin or if you’ve found a bug, please let me know.
Configuration
WP_OTP_STEALTH: Set this totrueto enable stealth OTP mode.
Filters
There are a multitude of filters to be adjusted.
wp_otp_qr_code_provisioning_uri: URI for online QR Code rendering (must contain{PROVISIONING_URI}placeholder for QR Code data).wp_otp_login_form_text: Text for input field on the login screen.wp_otp_login_form_text_sub: Subtext for the input field on the login screen.wp_otp_login_form_invalid_code_text: Error text for an invalid code input on the login screen.wp_otp_code_expiration_window: Set the window of code verification expiration.wp_otp_recovery_codes_count: Number of recovery codes to generate.wp_otp_recovery_codes_length: Length of the recovery codes.wp_otp_secret_length: Length of the secret key.
Minimum requirements
WordPress 4.6, PHP 7.4.
Donate / Support
All donations are much appreciated, thank you 🙏
Get professional support for this plugin with a Tidelift subscription
Tidelift helps make open source sustainable for maintainers while giving companies assurances about security, maintenance, and licensing for their dependencies.
Security
To report a security vulnerability, please use the Tidelift security contact. Tidelift will coordinate the fix and disclosure.
Installation
You can either use the built in WordPress installer or install the plugin manually.
For an automated installation:
- Go to ‘Plugins -> Add New’ on your WordPress Admin page.
- Search for the ‘WP OTP’ plugin.
- Install by clicking the ‘Install Now’ button.
- Activate the plugin on the ‘Plugins’ page in your WordPress Admin.
For a manual installation:
- Upload the ‘wp-otp’ folder to the plugins directory of your WordPress installation.
- Activate the plugin on the ‘Plugins’ page in your WordPress Admin.
Frequently asked questions
What if I lose my OTP authenticator?
No problem! When activating WP-OTP, you will also get a list of recovery codes that you can use instead of entering the OTP from your authenticator app. Be sure to regenerate them when you run out though, or better yet, reconfigure your WP-OTP to get a new secret and a new set of recovery codes.
Can I reset my OTP secret key?
Yes, just click the Reconfigure button on the profile page.
Why is there no OTP input field on the login form?
Your site admin has either disabled the plugin or enabled stealth mode. This means that you will need to add your OTP (or recovery) code at the end of your password.
Changelog
Minimum requirements are now WP 4.6 and PHP 7.4, supporting PHP 8.0!
0.6.1
- Fix nonce issue when saving profile.
0.6.0
- Require at least PHP 7.4 and update all code.
- Allow for PHP 8.0.
- Bump dependencies.
0.5.1
- Fix activation and deactivation hooks.
0.5.0
- Require at least PHP 7.2.
- Update OTPHP to 10.0.
- Add native QR code rendering.
- Harden security by adhering to WordPress Code Sniffer.
0.4.1
- Fix nullable return type when checking if OTP is enabled.
0.4.0
- Drop all custom i18n and rely on translate.wordpress.org.
- Minimum requirements are now WP 4.6 and PHP 7.1.
- Update OTPHP to 9.1.
- Tested for WP 5.3.
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best WP-OTP alternatives
All 2FA plugins →FAQ
WP-OTP: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Sep 29, 2026
Is WP-OTP free?
Yes. WP-OTP is free to download and use from the official WordPress.org plugin directory.
Is WP-OTP safe to use in 2026?
WP-OTP shows warning signs in 2026 — compare the alternatives below before installing. It runs on 100+ sites, is rated 4/5 and was last updated 6 years ago, and scores 33/100 on our health check.
How many websites use WP-OTP?
WP-OTP is active on 100+ WordPress websites and has been downloaded 11,424 times since it launched in November 2016. It was downloaded 95 times in the last 30 days.
Does WP-OTP work with WordPress 7.1?
WP-OTP is officially tested up to WordPress 5.6.21, while the latest release is 7.1.2. It may still work, but try it on a staging site first.
What PHP version does WP-OTP need?
WP-OTP requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was WP-OTP last updated?
The latest version, 0.6.1, was released on February 18, 2021 (6 years ago).
Who makes WP-OTP?
WP-OTP is developed and maintained by noplanman.
What are the best alternatives to WP-OTP?
The most popular alternatives to WP-OTP are Wordfence Security (5M+ installs), Really Simple Security (3M+ installs) and Limit Login Attempts Securi… (1M+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card