P4U Secure 2FA – WordPress Plugin

Secure your WordPress site with 2FA that is truly safe

Many free 2FA plugins store secret keys unencrypted in the database. In case of a data breach, your 2FA secret is just out on the street. P4U Secure 2FA is developed for owners, agencies and organizations that do not want to gamble with their security.

What makes P4U Secure 2FA different?

  • Military-grade encryption – TOTP secrets are stored with AES-256-GCM. Even in a full database breach, the secret is unusable.
  • Secure backup codes – 8 single-use codes per user, stored as bcrypt hashes and shown only once.
  • No session before the second factor – a session is only created after a valid code.
  • Replay & brute-force protection – a used code never works twice; after 5 failed attempts, a 15-minute lockout follows.
  • Local QR code generation – your secret never leaves the server, no external QR services.
  • Admin reset with grace period – user lost their phone? One click reset, all sessions destroyed and a configurable grace period (default 14 days) to set up again.
  • Blocks API bypasses – password-only login via XML-RPC/REST is rejected for 2FA users.
  • Enforceable per role – enforce 2FA for example for all administrators.

Works with all popular authenticator apps

Google Authenticator, Microsoft Authenticator, Authy, 1Password, FreeOTP, Aegis – P4U Secure 2FA follows the official RFC 6238 (TOTP) standard, so every app works instantly.

Included with your purchase

  • Directly downloadable plugin (.zip)
  • 1 year of free updates
  • Installation and configuration guide
  • if desired, free installation by Prospects4u

Requires WordPress 5.8+, PHP 7.4+ and the OpenSSL extension. Prices exclude VAT.

Additional information

Sale!

Original price was: € 69,00.Current price is: € 49,95.