Wordfence 9 adds passkey login, and unlike some security plugins that charge extra for it, Wordfence is including it free.
What happened
According to the Wordfence blog, passkeys let a user sign in with a fingerprint, face scan, device PIN, or password manager instead of typing a password. To turn it on, go to Wordfence, then Login Security, and toggle “Enable passkeys.” From there you can set passkeys as optional or required for specific user roles, and each user registers a passkey through their device’s built-in biometrics or a password manager. The feature works for the standard WordPress login and for WooCommerce store accounts, and users can register a passkey on more than one device so they aren’t locked out if they lose one.
Why it matters
Passwords get phished, reused, and stolen from other sites and then tried on yours. Passkeys are tied to the specific device and site they were created for, so a fake login page can’t trick a user into handing one over the way it can with a typed password. Wordfence’s founder put it plainly in the announcement: removing login friction, in this case, also removes a common way accounts get compromised. If you allow site owners to require passkeys instead of just offering them as an option, sign-in becomes both faster and harder to phish at the same time.
For a store or membership site with a lot of returning users, that friction reduction matters. Fewer forgotten passwords and reset emails means fewer people abandoning a purchase or login halfway through.
What to do
If you already run Wordfence, update to version 9 and turn on passkeys from Login Security. Consider making passkeys required for administrator and editor accounts first, since those carry the most risk if compromised, before opening it up to all users.
End of article