Passwords? MFA with Passkeys?

With security threats on the rise in 2026, many customers are looking for ways to secure their logins. This includes incorporating password managers like Bitwarden, new login security with 2FA/MFA, and even passkeys. Does your website support the latest modern technology to allow customers to use these effectively? Let’s look at ways to support these in WordPress


MFA/2FA

Multi-factor Authentication sometimes known as two-factor authentication helps secure against password theft, credential reuse, cookie repeating attacks, and more like it. The default in WordPress doesn’t enable these at all leaving the default system vulnerable to password theft and credential attacks. Fortunately, there are many plugins which add support for these allowing you to use Google Authenticator, Authy, or others.

The WP 2FA plugin enables these features directly. You can install it from WordPress, enable the plugin, and follow the prompts to enable what suits your needs best. Requiring a new 2FA code on each login may seem excessive, but e-commerce sites may need even stricter security.


Passkeys

Before enabling passkeys, it is important to determine if they meet your needs. Passkeys are a sometimes controversial new security step towards ending the use of passwords. Compared to passwords, they can be much more secure. It’s also impossible to forget or misplace these as they are held by the device itself. Unfortunately, that is part of the problem. Windows, Android, Chrome, iOS/MacOS, and others all have their own passkeys implementation that doesn’t fully interoperate with the others. This can cause some confusion and even login failures when requirements vary between different websites and systems.

Solutions such as Bitwarden’s Passkeys support offer to help make this easier by storing passkeys in a vault similar to passowrds. This has become a popular open source way for Windows users to share passkeys between browsers and mobile devices. These can help reduce friction when moving over to the new passkeys systems in the next few years as some such as banks move to make passkeys mandatory.

For your website, WP 2FA can enable passkeys support for users visiting the site. Once enabled, the prompt to create or use a passkey will be automatically offered by the device the user is using. This will store the login to the site on that computer. If they need to use a mobile device, secondary computer such as laptop, tablet, etc, they will need to manage passkeys between their devices. This friction has kept some website developers from supporting passkeys. Enable them depending on your use case and security needs.


MFA? 2FA? Passkeys?

For many websites, enabling MFA/2FA will be a solid step towards security without enabling passkeys which many average users are only now becoming familiar with. This follows improved support for passkeys in iOS 27, updates to Windows, and browsers such as Chrome. The ability to share passkeys between devices is now built into many ecosystems with interoperability to follow. If your current needs require passkeys, having a [email protected] available to help with lost credentials may be a necessary step.

We hope this helps you secure your WordPress website. Please check back next week for more on WordPress, optimization, and more.

Facebook
Twitter
LinkedIn