Disallow Pwned Password
Disallow WordPress and WooCommerce users using pwned passwords.
Consider an alternative
Disallow Pwned Password shows warning signs in 2026 — compare the alternatives below before installing. It runs on 10+ sites, is rated 5/5 and was last updated 8 years ago, and scores 30/100 on our health check.
- Small user base (10+ active installs)
- Very few reviews so far
- No update in 7 years
- Only tested up to WordPress 5.0 (latest is 7.1)
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where Disallow Pwned Password stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| authentication | >100 |
| have-i-been-pwned | #28 |
| hibp | #8 |
| password | >100 |
| security | >100 |
Version adoption
Share of active sites per release.
Rating breakdown
★★★★★★★★★★ 5 from 2 reviews
About Disallow Pwned Password
From the official readme · v0.3.2Description
Disallow WordPress and WooCommerce users using pwned passwords.
Goal
Spoiler Alert: User passwords never leave your server, not even in hashed form.
Although reusing passwords is solely users’ fault but when evil attackers brute forced users’ passwords, and stole all their personal information or spent users’ hard earn money through your site. Those lazy users blame you, the site owner/developer.
When processing requests to establish and change memorized secrets, verifiers SHALL compare the prospective secrets against a list that contains values known to be commonly-used, expected, or compromised. For example,…
- Passwords obtained from previous breach corpuses
This plugin’s solely purpose is to disallow WordPress and WooCommerce users reusing passwords listed in Have I Been Pwned database.
Usage
Activate and forget.
This plugin intercepts when:
- creating new users on
/wp-admin/user-new.php - changing other users’ passwords on
/wp-admin/user-edit.php - changing your password on
/wp-admin/profile.php - new user registration on
/wp-login.php?action=rp
Additional interceptions if WooCommerce is installed:
WC_Form_Handler::process_reset_passwordon Home » My account » Lost passwordWC_Form_Handler::save_account_detailson Home » My account » Account detailsWC_Form_Handler::process_registrationon Home » My accountWC_Checkout::validate_checkouton Home » Checkout
Explain It Like I’m Five
- Troy Hunt, a well-kown security expert, collected 6,493,641,194 (and counting) pwned passwords from previous security breaches
- Pwned passwords stored as SHA-1 hashes on haveibeenpwned.com
- Whenever WordPress / WooCommerce users attempt to change their passwords, this plugin hashes the user password
- Take the first 5 characters from the hash
- Ask haveibeenpwned.com for all pwned passwords with the same first 5 hash characters
- Check how many times the user password appears on the have I been pwned database
- Disallow the password change if it has been pwned
Users aged older than five could learn more from:
- Have I Been Pwned’s FAQs
- Why SHA-1 was chosen in the Pwned Passwords
- I’ve [Troy Hunt] Just Launched “Pwned Passwords” V2 With Half a Billion Passwords for Download
- Validating Leaked Passwords with k-Anonymity
For Developers
Fork the plugin on GitHub.
Changelog
Please see CHANGELOG for more information on what has changed recently.
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best Disallow Pwned Password alternatives
All authentication plugins →FAQ
Disallow Pwned Password: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Oct 1, 2026
Is Disallow Pwned Password free?
Yes. Disallow Pwned Password is free to download and use from the official WordPress.org plugin directory.
Is Disallow Pwned Password safe to use in 2026?
Disallow Pwned Password shows warning signs in 2026 — compare the alternatives below before installing. It runs on 10+ sites, is rated 5/5 and was last updated 8 years ago, and scores 30/100 on our health check.
How many websites use Disallow Pwned Password?
Disallow Pwned Password is active on 10+ WordPress websites and has been downloaded 2,085 times since it launched in February 2019. It was downloaded 57 times in the last 30 days.
Does Disallow Pwned Password work with WordPress 7.1?
Disallow Pwned Password is officially tested up to WordPress 5.0.29, while the latest release is 7.1.2. It may still work, but try it on a staging site first.
What PHP version does Disallow Pwned Password need?
Disallow Pwned Password requires PHP 7.0 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was Disallow Pwned Password last updated?
The latest version, 0.3.2, was released on February 19, 2019 (8 years ago).
Who makes Disallow Pwned Password?
Disallow Pwned Password is developed and maintained by Itineris Limited.
What are the best alternatives to Disallow Pwned Password?
The most popular alternatives to Disallow Pwned Password are Limit Login Attempts (300K+ installs), WPS Limit Login (100K+ installs) and Two Factor (100K+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card

