Zeshan Login 2FA is a WordPress plugin that adds two-factor authentication to login pages. It addresses password-only vulnerabilities by requiring a second factor against bots and credential-stuffing attacks that target WordPress sites continuously.
The plugin implements standard TOTP based on RFC 6238. Users set it up by visiting their profile page, scanning a QR code with an authenticator application, confirming a code, and saving backup codes. It generates the secret key locally on the server without external dependencies. Supported authenticator applications include Google Authenticator, Authy, Microsoft Authenticator, 1Password, and any other TOTP-compatible app. At login a user enters their password followed by a six-digit code from the app. Ten backup codes are provided to prevent lockouts.
It is delivered as a free plugin listed in the official WordPress.org directory and installed through the standard WordPress plugin installer. The maker is identified as zeshan495. No paid tiers or external services are required for the described functionality.
Zeshan Login 2FA sits in PulseGate's Security & compliance platforms category. It focuses on protecting WordPress admin logins from password-only attacks using only a single factor. It is built as a B2B product for wordPress site administrators. Zeshan Login 2FA costs nothing to use. It runs on the web, and it can be self-hosted.
Behind Zeshan Login 2FA is zeshan495, and the product first shipped in 2026. Key capabilities include TOTP 2FA, QR Code Setup, and Backup Codes.
Latest indexed changes and source events
Zeshan Login 2FA verified by the PulseGate indexer