{ "name": "Two Factor Extended", "slug": "two-factor-extended", "version": "1.0.0", "download_url": "https://git.robotstxt.es/ROBOTSTXT/two-factor-extended/releases/download/1.0.0/two-factor-extended-1.0.0.zip", "requires": "6.7", "requires_php": "8.2", "tested": "6.9", "last_updated": "2026-02-17", "author": "javiercasares, ROBOTSTXT", "author_profile": "https://www.robotstxt.es/", "homepage": "https://git.robotstxt.es/ROBOTSTXT/two-factor-extended", "description": "Extends the WordPress Two Factor plugin with advanced role-based controls, forced 2FA methods, and enhanced administrative features for single-site and Multisite installations.", "changelog": "

1.0.0 - 2026-02-17

", "sections": { "description": "Two Factor Extended is a comprehensive extension for the WordPress Two Factor plugin that provides administrators with enterprise-level controls over two-factor authentication across their site.

Core Features:Security: Grade A security audit, comprehensive security hardening, CSRF protection, XSS prevention, SQL injection protection.

Quality Assurance: 28 unit tests, WCAG 2.1 Level AA compliant, WordPress Coding Standards compliant, PHP 8.2-8.5 compatible.", "changelog": "

1.0.0 - 2026-02-17

", "installation": "
  1. Install the Two Factor plugin (required dependency)
  2. Upload and activate Two Factor Extended plugin
  3. Go to Settings → Two Factor Extended
  4. Configure grace period (7-14 days recommended)
  5. Set role-based 2FA requirements
  6. Configure provider visibility per role
  7. Monitor compliance via Compliance tab
  8. Review audit logs via Audit Log tab
", "faq": "

Does this plugin replace the Two Factor plugin?

No, Two Factor Extended is an extension that works alongside the Two Factor plugin. Both plugins must be installed and activated.

Is this compatible with WordPress Multisite?

Yes! Two Factor Extended fully supports WordPress Multisite with network-wide settings and site-level overrides.

Which PHP versions are supported?

Two Factor Extended requires PHP 8.2 or higher.

Can users bypass the 2FA requirements?

No. When a 2FA method is marked as required for a user's role, they cannot disable or remove it.

" }, "banners": { "low": "", "high": "" }, "icons": { "1x": "https://git.robotstxt.es/ROBOTSTXT/two-factor-extended/raw/branch/main/assets/icon-128x128.png", "2x": "https://git.robotstxt.es/ROBOTSTXT/two-factor-extended/raw/branch/main/assets/icon-256x256.png", "svg": "https://git.robotstxt.es/ROBOTSTXT/two-factor-extended/raw/branch/main/assets/icon.svg" } }