Two-factor authentication on WordPress and hosting: how to turn it on right without locking yourself out
A practical guide to enabling two-factor login on WordPress and your hosting without risking you or your team getting locked out.
Two-factor authentication (2FA) is the cheapest, most effective barrier you can put between attackers and your site. It costs nothing, takes a few minutes to set up, and stops the vast majority of automated login attempts even if someone learns your password.
The catch is that many people set it up wrong and then lock themselves out: they change phones, lose the code, and suddenly can't get into their admin or their cPanel. The good news is it can be done right, with a few simple safety nets. In this article we show you exactly what to enable on WordPress and on your hosting, in what order, and how to make sure you never get shut out.
What 2FA is and why it's worth it, even for a small site
2FA means that on top of your password (something you know) you also need a second factor (something you have) to log in. Usually that's a six-digit code from an app on your phone that changes every thirty seconds.
Why does it matter even for a small brochure site? Because WordPress attacks are almost always automated. Bots scan the internet non-stop and try password lists against /wp-login.php. Nobody is attacking you personally - you're just an address on a list. With 2FA on, even if the bot guesses your password it still can't get in, because it doesn't have the code on your phone.
It's worth doing on two fronts: your WordPress admin account and your hosting account (cPanel, Plesk or your provider's panel). The second one often matters more, because that's where everything can be wiped.
Authenticator app vs SMS: which to pick
There are several ways to receive the second factor, and they aren't equal:
- Authenticator app (Google Authenticator, Microsoft Authenticator, Authy, 2FAS) - generates codes locally on your phone, no internet needed. This is the safest and recommended option.
- SMS - you get the code by text. It works, but it's weaker: the SIM can be cloned or your number ported by an attacker (SIM swapping), and you depend on signal.
- Hardware key (YubiKey) - the strongest, but rarely used for small sites.
Our recommendation for most businesses: an authenticator app on your phone, with SMS only as a fallback if at all. One important detail: TOTP apps rely on your phone's exact time. If you set your phone's clock manually and it drifts, codes can be rejected. Keep the clock on automatic.
How to enable 2FA on WordPress, step by step
WordPress has no built-in 2FA, so you need a plugin. Good free options: Wordfence Login Security, Two-Factor (by WordPress contributors), or the security module in Solid Security.
The steps, whatever plugin you use:
- Install the plugin and open its 2FA settings.
- Open the authenticator app on your phone and scan the QR code shown.
- Enter the generated six-digit code to confirm it works.
- SAVE the recovery (backup) codes the plugin gives you.
If you have several users (client, colleagues, developer), enable 2FA on each account, not just yours. One admin account without 2FA cancels out everyone else's protection. Ideally, make 2FA mandatory for the Administrator and Editor roles.
Don't forget hosting: cPanel, panel and email
Many people secure only WordPress and leave the back door open. The hosting account is actually the master key: from there you can reset the WordPress password, reach the database, and delete files and backups.
Enable 2FA here too:
- On the hosting panel - cPanel, Plesk or your provider's own panel almost always have a Two-Factor Authentication option in the account security settings.
- On the provider account (where you pay and manage the domain) - here an account takeover means losing the domain.
- On the linked email - the inbox where password resets land. If someone gets into your email, they can reset everything else. It's often the weakest and most overlooked link.
Simple rule: secure in reverse order of power - email and provider first, then hosting, then WordPress.
The safety net: how NOT to lock yourself out
This is where most people slip. A few rules that save you:
- Save the recovery codes before you close the window. Put them in a password manager or print them and keep them physically. Without them, a lost phone means a lost account.
- Register two devices or two methods wherever you can (app + SMS backup).
- Use an app that backs up to the cloud (Authy or 2FAS) so you don't lose your codes when you change phones.
- Make sure someone you trust knows where the recovery codes are, for emergencies.
If you do get locked out of WordPress, you can disable it via FTP or File Manager (rename the 2FA plugin folder) or through the database. That's why hosting access has to stay working - it's your backup plan. On hosting, if you lose 2FA, the only real path is to contact your provider's support and prove you own the account.
How we approach security at MPO Web Studio
When we deliver a site, we don't hand it over with a single password scribbled on a note. We set up 2FA on WordPress and hosting from the start, save the recovery codes somewhere safe, and show you exactly how to log in yourself so you don't depend on anyone.
We work remotely, across the whole country, and clients often come to us after they've been locked out or hacked. Instead of reacting after it happens, it's far simpler to put the safety nets in place from day one.
If you'd like us to check together how exposed your site is and enable 2FA properly, without risking a lockout, send us a message on WhatsApp. We'll tell you honestly what's fine and what's worth fixing, with no empty promises.
Frequently asked questions
Does 2FA slow me down every time I log in?+
Barely. You enter a six-digit code from the app, which takes a few seconds. Many plugins also let you remember your device for a set number of days, so it doesn't ask for the code every time you log in from the same computer.
What happens if I lose or change my phone?+
If you saved your recovery codes, you log in with one of them and re-register the new phone. If you use an app with cloud backup (Authy, 2FAS), the codes restore automatically. That's why saving the recovery codes first is rule number one.
Do I have to pay for a 2FA plugin?+
No. Wordfence Login Security and the Two-Factor plugin are free and completely enough for most sites. Paid versions add features for large teams or advanced rules, but for a normal business site the free option is fine.
Is 2FA enough to be safe?+
It's the single most important measure, but not the only one. It works best combined with unique, long passwords, up-to-date plugins and WordPress, regular backups, and limiting login attempts. 2FA stops the vast majority of automated attacks, but real security means a few layers, not just one.
Should I enable 2FA for clients or colleagues who have access too?+
Yes, absolutely. A single admin account without 2FA cancels out the whole site's protection. Ideally you require 2FA for every account with an Administrator or Editor role, and give each of them their own recovery codes.
7 mistakes that drive clients away from your website
Leave your email and get the guide right here, instantly. No spam.
Want to see what your business's website could look like?
Message us on WhatsApp and we'll prepare a FREE demo website with your business name. See it first — decide after.