
Email TFA Security & Risk Analysis
wordpress.org/plugins/email-tfaAdd an extra layer of security via two-factor authentication with email for WordPress logins.
Is Email TFA Safe to Use in 2026?
Generally Safe
Score 100/100Email TFA has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "email-tfa" plugin v1.0.3 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. Notably, all identified SQL queries utilize prepared statements, and the vast majority of output is properly escaped, minimizing the risk of cross-site scripting (XSS) vulnerabilities.
The plugin also demonstrates good security practices by implementing nonce checks on 11 occasions and capability checks on 2. The attack surface, while consisting of 9 shortcodes, currently shows no unprotected entry points, which is a positive sign. Taint analysis reveals no unsanitized paths or critical/high severity flows, further indicating a secure coding approach.
The plugin's vulnerability history is completely clean, with no recorded CVEs of any severity. This suggests a commitment to security by the developers or a lack of past discovery of vulnerabilities. Overall, "email-tfa" v1.0.3 appears to be a well-secured plugin, adhering to many best practices. The primary area of potential concern would be the existence of shortcodes, although currently, they are not identified as an attack vector, their presence always warrants vigilance as they can sometimes lead to input validation issues if not handled carefully.
Email TFA Security Vulnerabilities
Email TFA Code Analysis
Output Escaping
Data Flow Analysis
Email TFA Attack Surface
Shortcodes 9
WordPress Hooks 14
Maintenance & Trust
Email TFA Maintenance & Trust
Maintenance Signals
Community Trust
Email TFA Alternatives
Email OTP Login
email-otp-login
Adds OTP (One-Time Password) verification after login for enhanced security in WordPress. OTP is sent to the user's email.
All-In-One Security (AIOS) – Security and Firewall
all-in-one-wp-security-and-firewall
Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plugin designed especially for WordPress.
Wordfence Login Security
wordfence-login-security
Secure your website with Wordfence Login Security, providing two-factor authentication, login and registration CAPTCHA, and XML-RPC protection.
Titan Anti-spam & Security
anti-spam
Block spam comments, defend against login attempts, and strengthen site security with anti-spam, brute-force protection, and two-factor authentication …
IP & Country Blocker Lite
ip-blocker-lite
Advanced WordPress security plugin with IP/country blocking and two-factor authentication for comprehensive website protection.
Email TFA Developer Profile
3 plugins · 80 total installs
How We Detect Email TFA
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/email-tfa/assets/css/admin.css/wp-content/plugins/email-tfa/assets/js/admin.jsemail-tfa/assets/css/admin.css?ver=email-tfa/assets/js/admin.js?ver=HTML / DOM Fingerprints
<!-- Email TFA User Meta Field -->name="email_tfa_enabled"id="email_tfa_enabled"data-tfa-user-meta-id="email_tfa_enabled"[EMAIL_TFA_CODE][EMAIL_TFA_SUBJECT][EMAIL_TFA_BODY][EMAIL_TFA_USER_FIRST_NAME]