
Matoma Two-Factor Authentication Security & Risk Analysis
wordpress.org/plugins/2-factorMatoma Two-Factor Authentication extends the login process by a 2nd factor to achieve increased security. After the user name and password are request …
Is Matoma Two-Factor Authentication Safe to Use in 2026?
Generally Safe
Score 85/100Matoma Two-Factor Authentication has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "2-factor" plugin v1.0.3 presents a mixed security posture. On the positive side, it demonstrates good practices in SQL query handling, utilizing prepared statements exclusively, and has no recorded vulnerabilities in its history, suggesting a generally well-maintained codebase. The absence of dangerous functions, file operations, and critical or high severity taint flows is also a strong indicator of a secure foundation.
However, significant concerns arise from the attack surface. The plugin exposes two AJAX handlers, both of which lack authentication checks. This is a critical oversight that could allow unauthenticated users to trigger potentially sensitive actions. While the taint analysis did not reveal any issues, the presence of unprotected entry points is a primary risk. The limited number of capability checks (only 1) further exacerbates this risk, as it suggests insufficient granular control over who can perform certain actions.
In conclusion, while the plugin benefits from a clean vulnerability history and secure SQL handling, the unprotected AJAX endpoints represent a substantial security weakness. Addressing these entry points with proper authentication and capability checks should be the immediate priority to improve its overall security posture.
Key Concerns
- AJAX handlers without auth checks
- Limited capability checks
Matoma Two-Factor Authentication Security Vulnerabilities
Matoma Two-Factor Authentication Code Analysis
Output Escaping
Data Flow Analysis
Matoma Two-Factor Authentication Attack Surface
AJAX Handlers 2
WordPress Hooks 25
Maintenance & Trust
Matoma Two-Factor Authentication Maintenance & Trust
Maintenance Signals
Community Trust
Matoma Two-Factor Authentication Alternatives
Two Factor SMS
two-factor-sms
Add SMS support to "Two Factor" feature as a plugin
SMS Partner
sms-partner
Activer l'A2F ou la connexion via Numéro de téléphone sur votre WordPress grâce à SMS Partner
All-In-One Security (AIOS) – Security and Firewall
all-in-one-wp-security-and-firewall
Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plugin designed especially for WordPress.
Wordfence Login Security
wordfence-login-security
Secure your website with Wordfence Login Security, providing two-factor authentication, login and registration CAPTCHA, and XML-RPC protection.
Titan Anti-spam & Security
anti-spam
Block spam comments, defend against login attempts, and strengthen site security with anti-spam, brute-force protection, and two-factor authentication …
Matoma Two-Factor Authentication Developer Profile
1 plugin · 0 total installs
How We Detect Matoma Two-Factor Authentication
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/2-factor/css/mtm-2f.css/wp-content/plugins/2-factor/js/mtm-2f.js/wp-content/plugins/2-factor/js/mtm-2f.js2-factor/css/mtm-2f.css?ver=2-factor/js/mtm-2f.js?ver=HTML / DOM Fingerprints
mtm-2f-login-wrappermtm-2f-passkey-inputmtm-2f-login-formdata-user-iddata-noncedata-redirect-tomtm_2F_login_params