BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
Password Reset with Code for WordPress REST API icon
Slowing down Tested up to 6.8.10 #2 in password reset

Password Reset with Code for WordPress REST API

A simple plugin that adds a password reset facility to the WordPress REST API using a code. The process is a two step process:

Active installs900+100+ tier
Downloads · 30d218▲ +3.8% vs prev. 30d
Rating5/510 reviews
Health score48/100Fair
All-time downloads19.5KSince May 2020
Support resolved—No recent threads
RequiresWP 4.6PHP 5.4+
Downloads · 7d74▲ +60.9% week over week
Our verdict

Use with caution

Password Reset with Code for Wo… works, but test it on a staging site before relying on it in 2026. It runs on 900+ sites, is rated 5/5 and was last updated 1 year ago, and scores 48/100 on our health check.

  • Small user base (900+ active installs)
  • No update in over a year
  • Only tested up to WordPress 6.8 (latest is 7.1)

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

4812Jul 4Aug 17Oct 1
Yesterday8
Daily average (1y)9
Peak day55Mar 3, 2026
Last 12 months3.4K

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where Password Reset with Code fo… stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
password reset #16 1,517 Best password reset plugins →
wp-api >100 10,000 Best wp-api plugins →

Version adoption

Share of active sites per release.

  • 0.0100.0%

Rating breakdown

★★★★★★★★★★ 5 from 10 reviews

  • 5★100.0%
  • 4★0.00%
  • 3★0.00%
  • 2★0.00%
  • 1★0.00%

About Password Reset with Code for WordPress…

From the official readme · v0.0.17

Description

A simple plugin that adds a password reset facility to the WordPress REST API using a code. The process is a two step process:

  1. User requests a password reset. A code is emailed to their registered email address
  2. The user enters the code when setting a new password, which is only set if the code is valid and has not expired

It is also possible to check the validity of a code without resetting the password which enables the possibility of setting the password by other means, or having a two stage process for checking the code and resetting the password if desired.

Default settings are to use an 8 digit code consisting of numbers, upper and lower case letters and special characters, which has a life span of 15 minutes, afterwhich a new code would need to be requested. By default a user can attempt to use or validate a code up to 3 times before automatically invalidating it.

Endpoints

The plugin adds two new endpoints to the REST API:

  • Endpoint: /wp-json/bdpwr/v1/reset-password
    — HTTP Verb: POST
    — Parameters (all required):
    — email

  • /wp-json/bdpwr/v1/set-password
    — HTTP Verb: POST
    — Parameters (all required):
    — email
    — password
    — code

  • /wp-json/bdpwr/v1/validate-code
    — HTTP Verb: POST
    — Parameters (all required):
    — email
    — code

Example Requests (jQuery)

Reset Password

$.ajax({
  url: '/wp-json/bdpwr/v1/reset-password',
  method: 'POST',
  data: {
    email: 'example@example.com',
  },
  success: function( response ) {
    console.log( response );
  },
  error: function( response ) {
    console.log( response );
  },
});

Set New Password

$.ajax({
  url: '/wp-json/bdpwr/v1/set-password',
  method: 'POST',
  data: {
    email: 'example@example.com',
    code: '1234',
    password: 'Pa$$word1',
  },
  success: function( response ) {
    console.log( response );
  },
  error: function( response ) {
    console.log( response );
  },
});

Validate Code

$.ajax({
  url: '/wp-json/bdpwr/v1/validate-code',
  method: 'POST',
  data: {
    email: 'example@example.com',
    code: '1234',
  },
  success: function( response ) {
    console.log( response );
  },
  error: function( response ) {
    console.log( response );
  },
});

Example Success Responses (JSON)

Reset Password

{
    "data": {
        "status": 200
    },
    "message": "A password reset email has been sent to your email address."
}

Set New Password

{
    "data": {
        "status": 200
    },
    "message": "Password reset successfully."
}

Validate Code

{
    "data": {
        "status": 200
    },
    "message": "The code supplied is valid."
}

Example Error Responses (JSON)

Reset Password

{
    "code": "bad_email",
    "message": "No user found with this email address.",
    "data": {
        "status": 500
    }
}

Set New Password

{
    "code": "bad_request",
    "message": "You must request a password reset code before you try to set a new password.",
    "data": {
        "status": 500
    }
}

Validate Code

{
    "code": "bad_request",
    "message": "The reset code provided is not valid.",
    "data": {
        "status": 500
    }
}

Filters

A number of WordPress filters have been added to help customise the process, please feel free to request additional filters or submit a pull request with any that you required.

Filter the length of the code

add_filter( 'bdpwr_code_length' , function( $length ) {
  return 4;
}, 10 , 1 );

Filter Expiration Time

add_filter( 'bdpwr_code_expiration_seconds' , function( $seconds ) {
  return 900;
}, 10 , 1 );

Filter the date format used by the plugin to display expiration times

add_filter( 'bdpwd_date_format' , function( $format ) {
  return 'H:i';
}, 10 , 1 );

Filter the reset email subject

add_filter( 'bdpwr_code_email_subject' , function( $subject ) {
  return 'Password Reset';
}, 10 , 1 );

Filter the email content

add_filter( 'bdpwr_code_email_text' , function( $text , $email , $code , $expiry ) {
  return $text;
}, 10 , 4 );

Filter maximum attempts allowed to use a reset code, default is 3, -1 for unlimmited

add_filter( 'bdpwr_max_attempts' , function( $attempts ) {
  return 3;
}, 10 , 4 );

Filter whether to include upper and lowercase letters in the code as well as numbers, default is false

add_filter( 'bdpwr_include_letters' , function( $include ) {
  return false;
}, 10 , 4 );

Filter the characters to be used when generating a code, you can use any string you want, default is 0123456789

add_filter( 'bdpwr_selection_string' , function( $string ) {
  return '0123456789';
}, 10 , 4 );

Filter the WP roles allowed to reset their password with this plugin, default is any, example below shows removing administrators

add_filter( 'bdpwr_allowed_roles' , function( $roles ) {

  $key = array_search( 'administrator' , $roles );

  if( $key !== false ) {
    unset( $roles[ $key ] );
  }

  return $roles;

}, 10 , 1 );

Filter to add custom namespace for REST API

add_filter( 'bdpwr_route_namespace' , function( $route_namespace ) {
  return 'xyz/v1';
}, 10 , 1 );

Credits

Frequently asked questions

Where do I report security bugs found in this plugin?

Please report security bugs found in the source code of the bdvs-password-reset plugin through the Patchstack Vulnerability Disclosure Program. The Patchstack team will assist you with verification, CVE assignment, and notify the developers of this plugin. Report a security vulnerability.

Changelog

switched to a cryptographically secure function to generate reset codes updated compatibility to 6.8.1

0.0.17

  • switched to a cryptographically secure function to generate reset codes
  • updated compatibility to 6.5

0.0.16

  • updated compatibility to 6.3
  • By default users with the administrator role are no longer able to reset their password using this plugin
  • The default length of the code that is generated has been increased from 4 to 8 characters
  • The default characters that are used to generate the code have been increased to include upper and lower case letters as well as special characters

0.0.15

  • updated compatibility to 6.1.1

0.0.14

  • updated compatibility to 5.9.3

0.0.13

  • updated to min version 4.6 to allow translations

0.0.12

  • resolved file include errors

Full changelog on WordPress.org →

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best Password Reset with Code for… alternatives

All password reset plugins →

FAQ

Password Reset with Code for WordPr…: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Oct 2, 2026

Is Password Reset with Code for Wo… free?

Yes. Password Reset with Code for Wo… is free to download and use from the official WordPress.org plugin directory.

Is Password Reset with Code for Wo… safe to use in 2026?

Password Reset with Code for Wo… works, but test it on a staging site before relying on it in 2026. It runs on 900+ sites, is rated 5/5 and was last updated 1 year ago, and scores 48/100 on our health check.

How many websites use Password Reset with Code for Wo…?

Password Reset with Code for Wo… is active on 900+ WordPress websites and has been downloaded 19,496 times since it launched in May 2020. It was downloaded 218 times in the last 30 days.

Does Password Reset with Code for Wo… work with WordPress 7.1?

Password Reset with Code for Wo… is officially tested up to WordPress 6.8.10, while the latest release is 7.1.2. It may still work, but try it on a staging site first.

What PHP version does Password Reset with Code for Wo… need?

Password Reset with Code for Wo… requires PHP 5.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was Password Reset with Code for Wo… last updated?

The latest version, 0.0.17, was released on June 5, 2025 (1 year ago).

Who makes Password Reset with Code for Wo…?

Password Reset with Code for Wo… is developed and maintained by dominic_ks.

What are the best alternatives to Password Reset with Code for Wo…?

The most popular alternatives to Password Reset with Code for Wo… are Clean Login (5K+ installs), Mx Custom Login Popup (10+ installs) and Melmium (<10 installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.