Starting in the fourth quarter of 2026, any FatLab client can have WordPress two-factor authentication added to their website at no charge. It does not matter which plan you are on. Open a support request, tell us you want it, and we will take care of the rest: installing it, configuring it, testing it, and walking your team through setup.
Two-factor authentication, usually shortened to 2FA, means logging in takes two things: your password and a short code from your phone or email. Someone who steals your password still cannot get in without the second piece.
We bought a license for a professional 2FA tool that we can use across the sites we look after, and we have branded it as FatLab, so the setup screens your team sees point back to us rather than to a software vendor they have never heard of. This post explains why we are doing it, what happened on one client's site this summer that pushed us to do it now, and what 2FA can and cannot protect you from.

Why we are offering 2FA for free
The honest answer is that it helps us as much as it helps you.
When a client's website gets compromised, we clean it up. We find what got in, remove it, close the door, restore anything that was damaged, and deal with the fallout with Google and the site's visitors. We cover that work for our clients, and it is not quick. Anything that makes a compromise less likely is time well spent, for both of us.
"If a client's site gets hacked, it's our problem to fix, so every login we lock down is a cleanup we never have to do," is how I would put it. "Charging a setup fee for something that protects our own time never made sense to me. I'd much rather make it easy to say yes."
What happened on one client's site this summer
This is the story that moved 2FA from "we should do this" to "we are doing this now." We are not naming the organization, but every detail here comes from our own notes on the incident.
A staff member at a small nonprofit we support emailed us in a hurry: their homepage had been replaced with a Turkish gambling page.
It had not, exactly. What we found was more deliberate. The attacker set the site to show a gambling affiliate page only to Google's crawlers, while regular visitors still saw the real website. This SEO spam technique, called cloaking, is designed to hijack a site's search reputation without anyone noticing. Staff saw it only because the site's content delivery network cached the version served to Google and briefly handed it to real visitors too.
The malware even kept a list of decoys: security scanners, SEO tools, performance testers, and uptime monitors. Each one was served the clean site on purpose, which is why routine automated checks saw nothing wrong.
How the attacker got in
This is the part that matters for this post. The site wasn't hacked through a vulnerable plugin. Nearly five days before the spam appeared, someone created a new administrator account from inside a legitimate administrator's logged-in session. Days later, the attacker began logging in to that new account from VPN connections in Europe, installed two file manager plugins as tools, and used them to plant the cloaking code.
We never established exactly how the attacker got that initial access. A stolen password, a hijacked session, or something on a device are all possible, and that uncertainty is common in real incidents. It was not a failing on the client's part.
What we did
We had the site clean about twenty minutes after the report came in: the malicious code removed, the rogue account deleted, every login session ended, every password reset, and the cache purged. Google re-crawled the clean homepage about ninety minutes later. When we followed up in Search Console over the next week, there was no measurable search damage. The day the spam went live, the site posted its highest click count of the week.
The next day we went back through the whole site a second time, working from the attacker's activity in the server logs rather than from what we could see on disk. That second pass found a second file manager plugin still active that the first pass had missed. It is the lesson we took from the whole incident: removing the tool you know about is not the same as removing the attacker's tools.
What we recommended afterward
Two things. First, remove an old administrator account that nobody needed anymore. Second, turn on two-factor authentication for every administrator. The client said yes to both.
We offered their team a choice between an authenticator app and email codes, and they chose email. That is a perfectly good choice, and I will explain why below.
Why WordPress two-factor authentication works
A password is a single secret, and single secrets leak. They get reused across sites, phished, guessed, and stolen in breaches unrelated to your website.
The scale of that leakage is hard to overstate. The breach-tracking service Have I Been Pwned now lists more than 17.8 billion compromised accounts. In a 2019 Google and Harris Poll survey, 65 percent of Americans said they reuse passwords across some or all of their accounts. Verizon's 2026 Data Breach Investigations Report found that people are more than four times as likely to use a password that has already been compromised as one that is merely weak.
WordPress login pages are under constant pressure from exactly that supply of stolen passwords. Wordfence reported blocking more than 55 billion password attacks against WordPress sites in 2024 alone, from nearly 136 million distinct IP addresses.
Two-factor authentication breaks the chain. A 2023 Microsoft study of business accounts found that MFA reduced the risk of compromise by 99.22 percent overall, and by 98.56 percent even for accounts whose passwords had already leaked. That second number is the one I would underline. Even when an attacker already has the right password, the second factor stops them almost every time.
It is also the first step government guidance recommends for small organizations. CISA, the federal cybersecurity agency, tells small businesses to require MFA wherever possible and to start with administrator accounts. Its own summary is blunt: any MFA is better than none.
What 2FA does not protect against
I want to be straight about this, because overselling a security control is how people end up surprised.
It does not fix vulnerable plugins. Most WordPress compromises still come through vulnerable plugins and themes, not logins (our overview of common WordPress security threats covers the full picture). Patchstack recorded 11,334 new WordPress vulnerabilities in 2025, 91 percent of them in plugins. We handle that risk through the other work we do every day: keeping plugins, themes, and WordPress itself updated, rolling back updates that break things, and filtering malicious traffic before it reaches your site. You can see that work on your site's care card in DogHouse.
It does not stop a hijacked session. 2FA protects the login moment. If an attacker steals a session that is already logged in, for example through malware on a computer that copies browser cookies, they skip the login entirely. Verizon's 2026 report found that 73 percent of ransomware victims had an infostealer infection or leaked credentials in the year before the attack. Keeping the devices you use to manage your website clean matters as much as anything we do on the server.
It protects the login screen, not every way into WordPress. Features like application passwords and some programmatic connections authenticate separately. When we set up 2FA, we also review who has administrator access and check for application passwords that shouldn't be there, because the login screen is only one door.
In the story above, we cannot say for certain that 2FA would have stopped that particular attacker, because we never learned whether they had a password or a live session. What we can say is that it closes the most common door, it closes it for good, and it costs your team a few seconds at login.
How WordPress 2FA works on your site
When we switch WordPress 2FA on, each person gets a seven-day grace period from their next login to set it up. The setup screens are branded as FatLab and walk you through it step by step. You have two options for the second step.
Option 1: An authenticator app (recommended)
An app on your phone, or a password manager you already use, generates a six-digit code that changes every 30 seconds. Google Authenticator, Microsoft Authenticator, Authy, 1Password, and Bitwarden all work. The code is generated on the device, so it works without a signal or an internet connection. This is the stronger option, and if your team already uses a password manager, it is almost no extra effort.
Option 2: A code by email
A one-time code arrives in your inbox when you log in. No app, no phone setup. This is the right choice for people who would otherwise avoid 2FA altogether.
It is also the weaker option, and I will not pretend otherwise. Your email inbox is usually also where your password reset links go, so someone who controls your email controls both halves. That is why NIST's federal guidance doesn't accept email as a second factor at all, and CISA ranks it as the weakest option on its list.
But a password plus an email code is still far stronger than a password alone, and a 2FA method your team actually uses beats a better one they abandon after a week. Before we turn email codes on, we confirm your site reliably sends mail so a delivery problem doesn't turn into a lockout.
What we do not offer: text messages
We do not use text-message codes. Phone numbers can be hijacked by convincing a mobile carrier to move them to a new SIM card. The FBI's Internet Crime Complaint Center logged 971 SIM-swapping complaints and more than $17 million in losses in 2025 alone. An authenticator app avoids that risk entirely.
Backup codes and trusted devices
Right after setup, you get single-use backup codes. Keep them in your password manager, not on the same phone as your authenticator app. They are the difference between a minor inconvenience and being locked out.
On a computer you use regularly, you can choose to trust the device, and it will not ask for a code again for about a month. Only do that on a machine that is yours and that nobody else uses.
If you ever do get locked out of WordPress, use a backup code, ask your site administrator to reset your 2FA, or contact us. We will verify your identity and reset it for you.
We have put all of this, step by step, on our two-factor authentication guide, which is also where the "learn more" links on your login screens point.

How to request 2FA for your site
Open a support request in DogHouse or email us, and tell us you would like two-factor authentication. It helps to know whether you want it on administrator accounts only or for everyone who logs in, but we can talk that through with you.
From there, we install and configure it, test the full login flow ourselves, and send your team plain-language instructions before we switch anything on. Nobody gets locked out on day one.
There is no charge, and it does not matter which plan you are on. If you want to understand how 2FA fits alongside everything else we do to protect your site, our managed WordPress security services page lays it out, and our guide to WordPress brute force attacks covers the login attacks 2FA is designed to stop.
Frequently Asked Questions
Does WordPress two-factor authentication cost anything?
No. Two-factor authentication is free for every FatLab client, on any plan. We cover the software license and the setup.
Do I have to use it?
No. It is available on request, and we recommend it, especially for administrator accounts. If you want it, open a support request, and we will set it up.
Will my whole team have to use 2FA?
That is your choice. We can require it only for administrators, for specific roles, or for everyone who logs in to your site. Most organizations start with administrators.
What if I lose my phone?
Use one of your backup codes to log in, then set up your authenticator app again on your new phone. If you have run out of backup codes, your site administrator or our team can reset 2FA on your account after confirming who you are.
Is a code by email really secure?
It is less secure than an authenticator app, because your email inbox is often also where password resets go. It is still far more secure than a password alone, and we would rather you use email codes than skip 2FA entirely.
Does 2FA mean my site cannot be hacked?
No. 2FA protects your login, which is one of the most common ways in. Vulnerable plugins, compromised computers, and stolen sessions are separate risks, which is why we pair 2FA with updates, monitoring, firewall protection, and regular reviews of who has access to your site.