A fake page captures the real password
One convincing fake page, one paste — no malware needed.
Passwords get phished, reused, and dumped in breaches — some attackers arrive holding a correct one. MalCare's built-in 2FA adds the one thing a breach can't include: a code that lives 30 seconds, on your phone.






Phished, reused, or pulled from a breach dump — a stolen password makes an attacker's login identical to yours. Nothing about the attempt looks wrong.
One correct password, measured field by field against yours
An inspection bench. A reused password arrives already carrying acceptance stamps from a forum, a webmail account and a file store — it is not being guessed here, it is being used. Six fields of the attacker's login attempt are then measured against yours: username, password, endpoint, browser, attempt rate and time of day. Each field is drawn as a registration target whose left half is your impression and whose right half is the attacker's. On all six the halves meet flush, with zero deviation, so nothing about the attempt looks wrong. One field differs, and it is an absence rather than a mismatch: the second factor carries your impression and none from the attacker, because a stolen password cannot produce one. That ring never closes, which is why the password that opened everything else leaves this site shut.
Reused, so it has opened other accounts already. Here it isn't being guessed — it's being used.
yourstheirs
Six fields measured · zero deviation · nothing to flag
Your impression, and none from them — a stolen password can't make one. The ring never closes, so this site stays shut.
One convincing fake page, one paste — no malware needed.
The attacker only has to breach the weakest site you reused it on.
Passwords from old breaches circulate for years and get tried daily.
The second factor is the one thing a breach can't contain — a code that exists for 30 seconds, on your device only.
A six-digit code's whole life, one thirty-second window at a time
A tape of thirty-second windows runs left to right. Each window holds its own six-digit code. The windows behind the present are struck through and dimmed — those codes are spent and can never be used again. Exactly one window is live: it is drawn larger, marked now, and carries a bar showing how much of its thirty seconds is left. The windows ahead are empty ruled frames with no digits at all, because those codes have not been worked out yet; a brace beneath them reads not computed yet. Below the tape sits the breach dump itself — an email address and a stored password hash on each of four million rows. Everything in the dump was written down and kept. No window of the tape ever was, so there was never a moment at which the code could have been taken along with the password.
Every value in there was written down and kept. No window of that tape ever was.
Each user pairs once and is done. MalCare emails everyone the instructions.
The complete parts list for enrolling one user: three parts, seven actions, once
A drafting sheet titled: two-factor enrolment, everything the user does. Three parts are laid out on it, each numbered, drawn and dimensioned by what it costs the person. Part one is the code that arrives in the setup email, drawn as a scan target inside camera framing brackets; its dimension reads one scan. Part two is a field of six empty character boxes with a cursor in the first; its dimension reads six keystrokes. Part three is a confirmation checkmark; its dimension reads zero keystrokes, because it is applied for you once the pairing is confirmed. The title block in the corner totals the drawing: user actions seven, repeats zero, app any TOTP, sheet one of one. A footnote gives the alternate path — email one-time passcodes, if a phone is not an option.
Alternate path — email OTP, if a phone isn't an option.
From the setup email, in any TOTP app.
Once, to confirm the pairing.
A green checkmark lands next to your name in the dashboard. Email OTP is the fallback if a phone isn't an option.
Require 2FA for admins and editors, keep it optional for contributors — per user or per role, across every site you manage.
A policy line drawn across the WordPress role ladder: required above it, optional below, on every site at once
The five WordPress roles are stacked in capability order, each drawn as a bar whose length is how much that role can change: Administrator longest, then Editor, Author, Contributor and Subscriber shortest. One bright horizontal line is drawn across the ladder immediately below Editor, carrying a grip and a travel arrow to show it can be moved. Above the line, a brace reads required — 2 roles, 7 people, and a note that everyone above it is sent the setup email automatically. Below the line, a brace reads optional — 3 roles, 84 people. One contributor carries an individual override marker, sitting below the line but required anyway, because enforcement can be set per user as well as per role. Beneath the ladder the same line continues through a row of site plates, crossing every one of them at exactly the same height: one rule, forty sites, set in one place.
One contributor, required anyway — the line is per role, the mark is per user.
Four reasons 2FA stays off — each one answered by something on this page.
You can't — control lives off your site. Reset from the dashboard and you're back in, in minutes.
Setup is minutes per user, by email, on apps they already have. Enforce by role and start with admins.
Reset any user in two clicks from the dashboard. No wp-admin, no FTP, no ticket.
One extra field, carrying your brand — and bots never reach it.
The verification step is part of your product. Clients and members see your brand on it, not a plugin's.
The same verification card carrying a plugin's name, then carrying yours
Two-factor verification
Enter your security code
Verify
Powered by 2FA Plugin — upgrade to Pro ↗
One more step, Sam
Pop in the code from your authenticator
Continue to Fernway
Questions? hello@fernway.studio
A plugin prints its own name here. MalCare prints yours.
Most hacks come through vulnerable plugins, not logins — 2FA secures one door of several. It ships as one layer of MalCare's 7-layer security, on from day one.
Enforcement by role, team setup, white-label — talk it through before you switch anything on.
Two routes to the same switch: one on your own, one with an engineer
A route diagram. At one end, a plate reading: you, now — forty client sites to roll out. At the other, a plate reading: 2FA on, across every site. Two routes run between them and both arrive at that same plate. The first is labelled on your own and carries nothing along its length. The second is labelled with an engineer, available around the clock and with no obligation, and it carries three marked stops: enforcement by role, team setup, and white-label — the three decisions this page has spent its length on. Neither route is shorter than the other and neither ends anywhere different. The only difference is that one of them has the hard calls marked on it, and someone walking it with you.
Both routes end at the same switch — one of them has the hard calls marked on it.
2FA comes built into MalCare — enforced from one dashboard, branded as yours, reset from outside your site.