WPRemote Launches “Email 2FA” To Help Agencies Fight Rising Password Hacks
Save 4+ hours per site, every week.
Get a quick demo of how it works, and unlock an exclusive discount while you’re at it.
Over the past few months, we’re seeing something worrying.
There’s been a drastic rise in websites getting hacked because of stolen passwords. It’s starting to look like another shift in WordPress security, similar to the rise in vulnerabilities over the past year.
More agencies are now rolling out 2FA for client sites, but almost everyone we spoke to was facing the same problem.
Across a large portfolio, managing 2FA was taking up several hours every week, and non-billable ones at that: you had to get every client and user set up, add new users as they come in, help people who lose access, etc.
Agencies needed a smarter and simpler solution. We started working on it right away.
In less than a month, Email 2FA is now live. Agencies can use it for:
- Add 2FA to WordPress logins without setting up an authenticator app for every client.
- Enable it across multiple users and sites directly from WP Remote.
- See who’s protected and how — Email 2FA, Authenticator, pending setup, or disabled.
The big difference is that you can now roll out 2FA much more widely without turning it into another support job for your team.
How Email 2FA works
Once you enable Email 2FA for someone, very little changes for them.
They log into WordPress with their username and password as usual. We then send an 8-digit, one-time code to the email address already linked to their account. The code expires after 10 minutes.
That’s it. There’s no app for the client to install, no QR code to scan, and no separate setup for you to help them through.
Manage it across all your sites
WP Remote now shows the 2FA status of your WordPress users in one place. You can quickly see whether someone is using:
- Email 2FA
- Authenticator 2FA
- Waiting to finish setup
- or no 2FA at all
You can enable Email 2FA for one user, or make changes in bulk across users and sites.
And if someone already uses an authenticator app, nothing changes. You can leave them on it, switch them to Email 2FA later, or reset their authenticator setup if they lose access.
So you don’t have to force one method on every client. You can use whichever one makes sense for them.
Back to those 300 hacked sites
The customer we mentioned earlier manages hundreds of sites spread across different servers.
And all of them were showing the same attack pattern.
The team would change the affected wp-admin passwords, but new hacks kept appearing every few days. Eventually it became clear that changing passwords wasn’t enough.
Once 2FA was added to those logins, the repetitive hacks finally stopped. Their team has since gone a step further and now uses WP Remote SSO for its own wp-admin access as well.
That incident stuck with us because this agency already knew 2FA was important. The difficult part was actually getting it set up across hundreds of sites and users.
So if you too have been putting off 2FA because of the setup, now you can enable it with just a few clicks. And if there’s something else you’d like us to make easier, email us your feature requests here. We’re always listening!
Tags:
Share it:
You may also like
-
Website Uptime Monitoring: What to Check and How to Set It Up
If you’re handling site maintenance and need to know whether your WordPress site is available to visitors, Website uptime monitoring provides an independent way to check. It regularly tests your…
-
Website Monitoring Checklist 101: What to Check and How Often
If you’re responsible for WordPress maintenance and have just received an uptime alert, had a visitor report a broken form, or noticed a campaign page suddenly losing conversions, your site…
-
WP Remote MCP is Live: Ask your sites anything
You can now ask ChatGPT: “Which of my 100 sites need attention today?” And get the answer within seconds. WP Remote MCP is now officially live, and it gives your…
How do you manage your websites?
Managing multiple WordPress websites can be time consuming and error-prone. WP Remote will save you hours every day while providing you complete peace of mind.
Managing everything yourself
But it’s too time-consuming, complicated and stops you from achieving your full potential. You don’t want to put your clients’ sites at risk with inefficient management.
Putting together multiple tools
But these tools don’t work together seamlessly and end up costing you a lot more time and money.