Safety Passwords
Require stronger passwords and prevent password reuse.
Solid choice
Safety Passwords is a solid plugin choice in 2026, with a few things worth checking first. Is rated 5/5 and was last updated 3 days ago, and scores 71/100 on our health check.
- Actively developed — last update 3 days ago
- Tested with the latest WordPress (7.1)
- Small user base (<10 active installs)
- Very few reviews so far
Daily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where Safety Passwords stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| enforce secure passwords | #23 |
| force secure passwords | #59 |
| secure password validation | #80 |
| secure passwords | #60 |
| user passwords | >100 |
Rating breakdown
★★★★★★★★★★ 5 from 1 reviews
About Safety Passwords
From the official readme · v1.5Description
Safety Passwords helps protect WordPress accounts by checking new passwords. Each password must meet the minimum length set by the site administrator and contain an uppercase letter, a lowercase letter, a number, and a special character. Users cannot reuse a password already in their history.
The administrator can also require a password change after a chosen number of days. Users see a countdown on their profile and a reminder in the admin bar during the last seven days. If the password expires, the plugin asks them to change it or use the password recovery form. Set the reset interval to 0 to turn off periodic resets and reminders.
Installing Safety Passwords as a must-use (MU) plugin is recommended. It loads automatically, and WordPress does not show a Plugins-screen control to deactivate it. A filesystem administrator can still remove the loader. See Installation below.
On WordPress multisite, network administrators manage one set of settings for the current network. Install it as MU or network activate it; activation on an individual site is not supported. WordPress shares an account’s password across networks, so a password reset on one network affects that account everywhere. See the multisite FAQ for which accounts each network checks.
The plugin can also record events with the Stream plugin.
Developers and contributors can find setup instructions on GitHub.
Override settings with PHP constants
PHP constants override saved settings; the settings page shows their effective values:
SAFETY_PASSWORDS_MIN_LEN: integer or whole-number string for minimum length; the settings field accepts 1-24.SAFETY_PASSWORDS_RESET_INTERVAL: integer or whole-number string for days between required resets; the settings field accepts 0-999, and 0 disables periodic resets and reminders.SAFETY_PASSWORDS_RP_ON_REGISTRATION:true,'true',1, or'1'enables a reset after registration;false,'false',0, or'0'disables it.
WordPress wp_validate_boolean() interprets the registration constant; other strings such as 'off' or 'no' evaluate to true. The numeric constants accept whole-number strings without changing the settings ranges; decimal strings are not converted to integers.
Installation
Must-use installation (recommended)
Place the release package’s safety-passwords directory in /wp-content/plugins/. Create /wp-content/mu-plugins/ if it does not exist, then create /wp-content/mu-plugins/safety-passwords-loader.php containing:
<?php require_once WP_PLUGIN_DIR . '/safety-passwords/safety-passwords.php';
WordPress loads this file automatically. If you cannot manage site files, ask your site administrator or hosting provider to set up the loader.
Standard installation
Place the release package’s safety-passwords directory in /wp-content/plugins/ and activate Safety Passwords from the Plugins screen. On multisite, network activate it rather than activating it on an individual site. The first normal WordPress request completes setup; no manual command is needed.
Frequently asked questions
What happens when a password expires?
The periodic check starts a required reset and attempts one recovery email. Later checks keep the reset pending, even if that email fails; they do not retry the email. A successful reset or profile password change clears the pending state and renews the period. Before expiry, the profile shows a countdown and the admin bar shows a reminder in the final seven days. After expiry, they ask for a password change without a countdown; if a reset is already pending, they point to the recovery form. An interval of 0 disables periodic resets and these reminders.
How does this work on multisite?
Settings apply to the current network. Only network administrators with manage_network_options can change them. On a single-network installation, periodic and manual checks include every account, even one without site membership. On a multi-network installation, each network checks accounts with membership on at least one of its sites, including inactive sites. It excludes accounts assigned only to another network or to no site. Passwords and password history belong to the WordPress account globally, so a reset of an account shared by networks affects it everywhere. The plugin keeps one…
When should I use Initialize / repair?
Normally, no manual action is needed. The first eligible request records current password history, grants administrator capabilities, and schedules checks. A changed plugin version triggers automatic setup on the next eligible request, including after file, Composer, or CI deployment, if the new code loads against the target database. Failed setup retries with bounded delays. Eligible requests also repair missing or duplicate periodic events. A code change that requires a fresh full initialization must advance the plugin version marker. The settings page shows its diagnostic panel only while…
When do periodic checks run?
Periodic resets use WP-Cron. WordPress requests or an external cron trigger are needed for them to run on time. Automatic setup and schedule repair also require the plugin to load; they cannot run while the site is idle. Standard plugin deactivation removes the periodic schedule and invalidates setup state for later activation.
How do I remove or restore an MU installation?
Remove the MU loader and deactivate any separately active standard copy. Removing the loader does not run deactivation, so manually remove the safety_passwords_periodically_reset event from the network’s main site and any legacy subsites. Saved settings and password history remain. If the same-version loader returns, its retained setup marker does not trigger a full history pass. Run Initialize / repair or wp safety init --url= to include current passwords for accounts added during the gap. Password changes made while the code was absent cannot be reconstructed.
What happens when an administrator changes a password with WP-CLI?
With the plugin loaded, wp user update with a password and wp user reset-password complete any pending reset, renew the period, and record the saved password in history. These administrative changes bypass password strength and reuse checks; WP-CLI warns on stderr when a password is changed. Later changes through web forms still check password history. Changes made with the plugin skipped cannot update its history or reset state, and WP-CLI changes made before version 1.5 are not repaired automatically.
What is recorded in logs?
The plugin integrates with Stream. Current password reset logs use fixed failure categories and aggregate periodic reset and reminder counts, without account identifiers or WordPress error details. wp safety check-users likewise logs only aggregate counts and reports Success: Done. Older Stream records may contain details from previous versions. Site operators should review those records privately under their retention policy; updating the plugin does not remove them.
Are older WordPress versions supported?
Background reset emails and silent reset links also work on WordPress 5.0 through 5.6, where the login-page recovery function is unavailable during periodic checks.
Can I install from a source checkout?
The release package includes runtime dependencies. If installing from a source checkout instead, run composer install --no-dev --no-scripts in plugin-dir/ before WordPress loads the plugin.
Changelog
1.5
- Complete ordinary and must-use setup on normal requests, automatically repair scheduling, and retain current-network policy.
- Correct password expiry notices, repeated reset handling, constant overrides, and privacy-safe logging.
- Track standard WP-CLI password changes in history and expiry state, with an explicit strength and reuse bypass warning.
- Test WordPress 7.1.2 with PHP 8.5 and 8.2; retain PHP 7.4 and WordPress 5 compatibility.
1.4.2
- Dependencies updated.
1.4.1
- Put currently used passwords to the stop list on activation.
1.4
- Previously used password are not allowed to use again.
1.3
- Fatal error on cron event fixed in php 8. https://github.com/hokoo/safety-passwords/issues/6
- Text of a log message fixed.
- php.ini added for local dev.
- error log watcher git fixed for local dev.
1.2
- Stream plugin integration fixed. https://github.com/hokoo/safety-passwords/issues/11
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
FAQ
Safety Passwords: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Oct 4, 2026
Is Safety Passwords free?
Yes. Safety Passwords is free to download and use from the official WordPress.org plugin directory.
Is Safety Passwords safe to use in 2026?
Safety Passwords is a solid plugin choice in 2026, with a few things worth checking first. Is rated 5/5 and was last updated 3 days ago, and scores 71/100 on our health check.
How many websites use Safety Passwords?
Safety Passwords is active on <10 WordPress websites and has been downloaded 2,604 times since it launched in May 2024. It was downloaded 90 times in the last 30 days.
Does Safety Passwords work with WordPress 7.1?
Yes. The developer has tested Safety Passwords up to WordPress 7.1.2, the latest release. It requires WordPress 5.0 or newer.
What PHP version does Safety Passwords need?
Safety Passwords requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was Safety Passwords last updated?
The latest version, 1.5, was released on October 1, 2026 (3 days ago).
Who makes Safety Passwords?
Safety Passwords is developed and maintained by iTRON.
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card





