BuildWithHumza Application Password Audit
See every application password, active session and user account that can reach your site, with unused and stale access flagged.
Solid choice
BuildWithHumza Application Pass… is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 2 weeks ago, and scores 64/100 on our health check.
- Actively developed — last update 2 weeks ago
- Tested with the latest WordPress (7.1)
- Small user base (<10 active installs)
- Very few reviews so far
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where BuildWithHumza Application… stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| application-passwords | >100 |
| last login | >100 |
| security audit | >100 |
| sessions | >100 |
| user management | >100 |
About BuildWithHumza Application Password Aud…
From the official readme · v1.0.0Description
WordPress hides application passwords on each user’s own profile page. If your site has twenty users, checking them all means opening twenty profiles. There is no screen anywhere in WordPress that answers the obvious question:
Who, and what, can get into this site right now?
BuildWithHumza Application Password Audit adds that screen under Tools. It is read-only apart from two deliberate revoke buttons, and it never sends anything anywhere.
Why application passwords matter
An application password is a permanent key. It is created once for a script, a mobile app, a backup service or an integration, it works over the REST API, and it never expires on its own. Changing your WordPress password does not revoke it. Most site owners have no idea how many exist, who created them, or whether anything is still using them.
This plugin lists every one of them, site-wide, with the date it was created, the date it was last used, and the IP address it was last used from.
What the report shows
- Application passwords for every user, with created date, last used date and last IP
- Active login sessions per user, so you can see who is currently signed in somewhere
- Last login for every user, recorded from the moment you activate the plugin
- Roles, with accounts that can fully control the site clearly marked
- Remote management tools that hold standing access: MainWP, UpdraftCentral, ManageWP and Wordfence
- Warning flags on anything that looks abandoned
The flags are the point
A list of twenty application passwords tells you nothing. The plugin marks the ones worth acting on:
- Application passwords that have never been used at all
- Application passwords unused for over 90 days
- Administrators who have not logged in for over 90 days
- Administrators with no recorded login since tracking began
Flagged rows sort to the top, so you read the risk first instead of scrolling.
What you can do from the screen
- Sign a user out of every device at once
- Revoke a single application password without disturbing the others
- Export the whole report as CSV for a handover document or a security review
Remote access detection
A connected management dashboard is standing access just like a user account, and it survives a password change. The plugin reports whether MainWP Child, UpdraftPlus, ManageWP Worker and Wordfence are active, and where the pairing is readable it shows whether the site is connected and which WordPress user connected it.
Where a connection genuinely cannot be read, the plugin says so and explains why rather than guessing. Wordfence Central keeps its state in its own database table, so that one is reported as undetermined on purpose.
Who this is for
- Freelancers and agencies finishing a project or inheriting a site. Export the report and you have written evidence of exactly what access existed.
- Site owners checking that no former contractor, old staff account or forgotten integration still has a way in.
- Anyone who has ever created an application password and then forgotten about it.
Honest limitations
WordPress does not store login history, so no plugin can show you logins from before it was installed. This one starts recording when you activate it and displays “Not seen since [date]” rather than claiming a long-standing user has never logged in. Give it a few weeks before the login warnings mean much. Application password data is read from WordPress core and is accurate immediately.
The report loads the first 500 users by default because it is meant to be read by a person. Larger sites can raise that with the bwh_apa_user_limit filter.
Privacy
This plugin makes no external requests, loads no remote scripts and includes no tracking or analytics. It stores one timestamp per user and one option recording when tracking began. Uninstalling deletes both.
Installation
- Install through Plugins > Add New, or upload the folder to
/wp-content/plugins/. - Activate it.
- Go to Tools > Access Audit.
Viewing the report requires the list_users capability. Revoking a session or an application password additionally requires permission to edit that particular user, so an editor cannot revoke an administrator’s access.
Frequently asked questions
What is a WordPress application password?
It is a separate password used by apps and scripts to reach your site over the REST API, added in WordPress 5.6. It bypasses the normal login form, it does not expire, and changing your account password does not revoke it. That combination is why they are worth auditing.
How do I see all application passwords in WordPress?
WordPress core only shows them on each user’s individual profile screen. This plugin collects them from every user onto one page under Tools, along with when each was last used.
Why does a user show “Not seen since” a date?
WordPress does not record login times, so the plugin collects them itself from the moment you activate it. Anyone who has not logged in since then shows that message until they next log in. It is not a claim that they have never logged in.
Is it safe to revoke an application password?
Revoking one stops whatever was using it, so an integration relying on it will begin to fail. That is usually the intent. Check the last used column first: a password that has never been used is almost always safe to remove.
Does this slow down my site?
No. The only thing running on the front end is one timestamp write when somebody logs in. The report is built on demand when you open the page.
How is this different from an activity log plugin?
An activity log answers “what happened?” This answers “what is true right now?” They complement each other. An activity log will not tell you that an application password created eight months ago has never once been used.
Can I change the 90 day threshold?
Yes. Use the bwh_apa_stale_login_days and bwh_apa_unused_password_days filters.
Does it work on multisite?
It reports on the site you run it from. Network-wide reporting is not in this version.
Changelog
First release.
1.0.0
- First release.
- Site-wide application password report with created date, last used date and last IP.
- Active session counts per user, with sign out everywhere.
- Last login tracking and stale access flags.
- Remote management detection for MainWP, UpdraftPlus, ManageWP and Wordfence.
- CSV export.
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best BuildWithHumza Application Pa… alternatives
All application-passwords plugins →FAQ
BuildWithHumza Application Password…: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Oct 8, 2026
Is BuildWithHumza Application Pass… free?
Yes. BuildWithHumza Application Pass… is free to download and use from the official WordPress.org plugin directory.
Is BuildWithHumza Application Pass… safe to use in 2026?
BuildWithHumza Application Pass… is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 2 weeks ago, and scores 64/100 on our health check.
How many websites use BuildWithHumza Application Pass…?
BuildWithHumza Application Pass… is active on <10 WordPress websites and has been downloaded 100 times since it launched in September 2026. It was downloaded 107 times in the last 30 days.
Does BuildWithHumza Application Pass… work with WordPress 7.1?
Yes. The developer has tested BuildWithHumza Application Pass… up to WordPress 7.1.3, the latest release. It requires WordPress 6.0 or newer.
What PHP version does BuildWithHumza Application Pass… need?
BuildWithHumza Application Pass… requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was BuildWithHumza Application Pass… last updated?
The latest version, 1.0.0, was released on September 26, 2026 (2 weeks ago).
Who makes BuildWithHumza Application Pass…?
BuildWithHumza Application Pass… is developed and maintained by Mohammad Humza.
What are the best alternatives to BuildWithHumza Application Pass…?
The most popular alternatives to BuildWithHumza Application Pass… are Application Passwords Manag… (100+ installs), Destino Access Audit (100+ installs) and BotCreds Agent Access (20+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card


