BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
BuildWithHumza Application Password Audit icon
Actively maintained Tested with WP 7.1 #7 in application-passwords

BuildWithHumza Application Password Audit

See every application password, active session and user account that can reach your site, with unused and stale access flagged.

Active installs<10New
Downloads · 30d107• 0% vs prev. 30d
Rating—0 reviews
Health score64/100Good
All-time downloads100Since Sep 2026
Support resolved—No recent threads
RequiresWP 6.0PHP 7.4+
Downloads · 7d31▼ -64.4% week over week
Our verdict

Solid choice

BuildWithHumza Application Pass… is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 2 weeks ago, and scores 64/100 on our health check.

  • Actively developed — last update 2 weeks ago
  • Tested with the latest WordPress (7.1)
  • Small user base (<10 active installs)
  • Very few reviews so far

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

81725Sep 26Oct 1Oct 7
Yesterday3
Daily average (1y)9
Peak day34Sep 26, 2026
Last 12 months107

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where BuildWithHumza Application… stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
application-passwords >100 1,427 Best application-passwords plugins →
last login >100 1,723 Best last login plugins →
security audit >100 1,667 Best security audit plugins →
sessions >100 4,721 Best sessions plugins →
user management >100 8,022 Best user management plugins →

About BuildWithHumza Application Password Aud…

From the official readme · v1.0.0

Description

WordPress hides application passwords on each user’s own profile page. If your site has twenty users, checking them all means opening twenty profiles. There is no screen anywhere in WordPress that answers the obvious question:

Who, and what, can get into this site right now?

BuildWithHumza Application Password Audit adds that screen under Tools. It is read-only apart from two deliberate revoke buttons, and it never sends anything anywhere.

Why application passwords matter

An application password is a permanent key. It is created once for a script, a mobile app, a backup service or an integration, it works over the REST API, and it never expires on its own. Changing your WordPress password does not revoke it. Most site owners have no idea how many exist, who created them, or whether anything is still using them.

This plugin lists every one of them, site-wide, with the date it was created, the date it was last used, and the IP address it was last used from.

What the report shows

  • Application passwords for every user, with created date, last used date and last IP
  • Active login sessions per user, so you can see who is currently signed in somewhere
  • Last login for every user, recorded from the moment you activate the plugin
  • Roles, with accounts that can fully control the site clearly marked
  • Remote management tools that hold standing access: MainWP, UpdraftCentral, ManageWP and Wordfence
  • Warning flags on anything that looks abandoned

The flags are the point

A list of twenty application passwords tells you nothing. The plugin marks the ones worth acting on:

  • Application passwords that have never been used at all
  • Application passwords unused for over 90 days
  • Administrators who have not logged in for over 90 days
  • Administrators with no recorded login since tracking began

Flagged rows sort to the top, so you read the risk first instead of scrolling.

What you can do from the screen

  • Sign a user out of every device at once
  • Revoke a single application password without disturbing the others
  • Export the whole report as CSV for a handover document or a security review

Remote access detection

A connected management dashboard is standing access just like a user account, and it survives a password change. The plugin reports whether MainWP Child, UpdraftPlus, ManageWP Worker and Wordfence are active, and where the pairing is readable it shows whether the site is connected and which WordPress user connected it.

Where a connection genuinely cannot be read, the plugin says so and explains why rather than guessing. Wordfence Central keeps its state in its own database table, so that one is reported as undetermined on purpose.

Who this is for

  • Freelancers and agencies finishing a project or inheriting a site. Export the report and you have written evidence of exactly what access existed.
  • Site owners checking that no former contractor, old staff account or forgotten integration still has a way in.
  • Anyone who has ever created an application password and then forgotten about it.

Honest limitations

WordPress does not store login history, so no plugin can show you logins from before it was installed. This one starts recording when you activate it and displays “Not seen since [date]” rather than claiming a long-standing user has never logged in. Give it a few weeks before the login warnings mean much. Application password data is read from WordPress core and is accurate immediately.

The report loads the first 500 users by default because it is meant to be read by a person. Larger sites can raise that with the bwh_apa_user_limit filter.

Privacy

This plugin makes no external requests, loads no remote scripts and includes no tracking or analytics. It stores one timestamp per user and one option recording when tracking began. Uninstalling deletes both.

Installation

  1. Install through Plugins > Add New, or upload the folder to /wp-content/plugins/.
  2. Activate it.
  3. Go to Tools > Access Audit.

Viewing the report requires the list_users capability. Revoking a session or an application password additionally requires permission to edit that particular user, so an editor cannot revoke an administrator’s access.

Frequently asked questions

What is a WordPress application password?

It is a separate password used by apps and scripts to reach your site over the REST API, added in WordPress 5.6. It bypasses the normal login form, it does not expire, and changing your account password does not revoke it. That combination is why they are worth auditing.

How do I see all application passwords in WordPress?

WordPress core only shows them on each user’s individual profile screen. This plugin collects them from every user onto one page under Tools, along with when each was last used.

Why does a user show “Not seen since” a date?

WordPress does not record login times, so the plugin collects them itself from the moment you activate it. Anyone who has not logged in since then shows that message until they next log in. It is not a claim that they have never logged in.

Is it safe to revoke an application password?

Revoking one stops whatever was using it, so an integration relying on it will begin to fail. That is usually the intent. Check the last used column first: a password that has never been used is almost always safe to remove.

Does this slow down my site?

No. The only thing running on the front end is one timestamp write when somebody logs in. The report is built on demand when you open the page.

How is this different from an activity log plugin?

An activity log answers “what happened?” This answers “what is true right now?” They complement each other. An activity log will not tell you that an application password created eight months ago has never once been used.

Can I change the 90 day threshold?

Yes. Use the bwh_apa_stale_login_days and bwh_apa_unused_password_days filters.

Does it work on multisite?

It reports on the site you run it from. Network-wide reporting is not in this version.

Changelog

First release.

1.0.0

  • First release.
  • Site-wide application password report with created date, last used date and last IP.
  • Active session counts per user, with sign out everywhere.
  • Last login tracking and stale access flags.
  • Remote management detection for MainWP, UpdraftPlus, ManageWP and Wordfence.
  • CSV export.

Full changelog on WordPress.org →

Screenshots

The report under Tools: summary tiles, then the flagged accounts sorted to the top with the application passwords each one holds.
The report under Tools: summary tiles, then the flagged accounts sorted to the top with…
Every flag spelled out on the row it belongs to, with an administrator marked critical and an editor marked review.
Every flag spelled out on the row it belongs to, with an administrator marked critical…
The remote access section showing which management dashboards are connected and who connected them.
The remote access section showing which management dashboards are connected and who…

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best BuildWithHumza Application Pa… alternatives

All application-passwords plugins →

FAQ

BuildWithHumza Application Password…: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Oct 8, 2026

Is BuildWithHumza Application Pass… free?

Yes. BuildWithHumza Application Pass… is free to download and use from the official WordPress.org plugin directory.

Is BuildWithHumza Application Pass… safe to use in 2026?

BuildWithHumza Application Pass… is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 2 weeks ago, and scores 64/100 on our health check.

How many websites use BuildWithHumza Application Pass…?

BuildWithHumza Application Pass… is active on <10 WordPress websites and has been downloaded 100 times since it launched in September 2026. It was downloaded 107 times in the last 30 days.

Does BuildWithHumza Application Pass… work with WordPress 7.1?

Yes. The developer has tested BuildWithHumza Application Pass… up to WordPress 7.1.3, the latest release. It requires WordPress 6.0 or newer.

What PHP version does BuildWithHumza Application Pass… need?

BuildWithHumza Application Pass… requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was BuildWithHumza Application Pass… last updated?

The latest version, 1.0.0, was released on September 26, 2026 (2 weeks ago).

Who makes BuildWithHumza Application Pass…?

BuildWithHumza Application Pass… is developed and maintained by Mohammad Humza.

What are the best alternatives to BuildWithHumza Application Pass…?

The most popular alternatives to BuildWithHumza Application Pass… are Application Passwords Manag… (100+ installs), Destino Access Audit (100+ installs) and BotCreds Agent Access (20+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.