BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
Safety Passwords icon
Actively maintained Tested with WP 7.1 #1 in enforce secure passwords

Safety Passwords

Require stronger passwords and prevent password reuse.

Active installs<10New
Downloads · 30d90▲ +91.5% vs prev. 30d
Rating5/51 reviews
Health score71/100Good
All-time downloads2.6KSince May 2024
Support resolved—No recent threads
RequiresWP 5.0PHP 7.4+
Downloads · 7d60▲ 5.5× week over week
Our verdict

Solid choice

Safety Passwords is a solid plugin choice in 2026, with a few things worth checking first. Is rated 5/5 and was last updated 3 days ago, and scores 71/100 on our health check.

  • Actively developed — last update 3 days ago
  • Tested with the latest WordPress (7.1)
  • Small user base (<10 active installs)
  • Very few reviews so far

Daily downloads

81726Jul 6Aug 19Oct 3
Yesterday5
Daily average (1y)2
Peak day35Oct 1, 2026
Last 12 months734

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where Safety Passwords stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
enforce secure passwords #23 169 Best enforce secure passwords plugins →
force secure passwords #59 412 Best force secure passwords plugins →
secure password validation #80 706 Best secure password validation plugins →
secure passwords #60 1,788 Best secure passwords plugins →
user passwords >100 4,735 Best user passwords plugins →

Rating breakdown

★★★★★★★★★★ 5 from 1 reviews

  • 5★100.0%
  • 4★0.00%
  • 3★0.00%
  • 2★0.00%
  • 1★0.00%

About Safety Passwords

From the official readme · v1.5

Description

Safety Passwords helps protect WordPress accounts by checking new passwords. Each password must meet the minimum length set by the site administrator and contain an uppercase letter, a lowercase letter, a number, and a special character. Users cannot reuse a password already in their history.

The administrator can also require a password change after a chosen number of days. Users see a countdown on their profile and a reminder in the admin bar during the last seven days. If the password expires, the plugin asks them to change it or use the password recovery form. Set the reset interval to 0 to turn off periodic resets and reminders.

Installing Safety Passwords as a must-use (MU) plugin is recommended. It loads automatically, and WordPress does not show a Plugins-screen control to deactivate it. A filesystem administrator can still remove the loader. See Installation below.

On WordPress multisite, network administrators manage one set of settings for the current network. Install it as MU or network activate it; activation on an individual site is not supported. WordPress shares an account’s password across networks, so a password reset on one network affects that account everywhere. See the multisite FAQ for which accounts each network checks.

The plugin can also record events with the Stream plugin.

Developers and contributors can find setup instructions on GitHub.

Override settings with PHP constants

PHP constants override saved settings; the settings page shows their effective values:

  • SAFETY_PASSWORDS_MIN_LEN: integer or whole-number string for minimum length; the settings field accepts 1-24.
  • SAFETY_PASSWORDS_RESET_INTERVAL: integer or whole-number string for days between required resets; the settings field accepts 0-999, and 0 disables periodic resets and reminders.
  • SAFETY_PASSWORDS_RP_ON_REGISTRATION: true, 'true', 1, or '1' enables a reset after registration; false, 'false', 0, or '0' disables it.

WordPress wp_validate_boolean() interprets the registration constant; other strings such as 'off' or 'no' evaluate to true. The numeric constants accept whole-number strings without changing the settings ranges; decimal strings are not converted to integers.

Installation

Must-use installation (recommended)

Place the release package’s safety-passwords directory in /wp-content/plugins/. Create /wp-content/mu-plugins/ if it does not exist, then create /wp-content/mu-plugins/safety-passwords-loader.php containing:

<?php require_once WP_PLUGIN_DIR . '/safety-passwords/safety-passwords.php';

WordPress loads this file automatically. If you cannot manage site files, ask your site administrator or hosting provider to set up the loader.

Standard installation

Place the release package’s safety-passwords directory in /wp-content/plugins/ and activate Safety Passwords from the Plugins screen. On multisite, network activate it rather than activating it on an individual site. The first normal WordPress request completes setup; no manual command is needed.

Frequently asked questions

What happens when a password expires?

The periodic check starts a required reset and attempts one recovery email. Later checks keep the reset pending, even if that email fails; they do not retry the email. A successful reset or profile password change clears the pending state and renews the period. Before expiry, the profile shows a countdown and the admin bar shows a reminder in the final seven days. After expiry, they ask for a password change without a countdown; if a reset is already pending, they point to the recovery form. An interval of 0 disables periodic resets and these reminders.

How does this work on multisite?

Settings apply to the current network. Only network administrators with manage_network_options can change them. On a single-network installation, periodic and manual checks include every account, even one without site membership. On a multi-network installation, each network checks accounts with membership on at least one of its sites, including inactive sites. It excludes accounts assigned only to another network or to no site. Passwords and password history belong to the WordPress account globally, so a reset of an account shared by networks affects it everywhere. The plugin keeps one…

When should I use Initialize / repair?

Normally, no manual action is needed. The first eligible request records current password history, grants administrator capabilities, and schedules checks. A changed plugin version triggers automatic setup on the next eligible request, including after file, Composer, or CI deployment, if the new code loads against the target database. Failed setup retries with bounded delays. Eligible requests also repair missing or duplicate periodic events. A code change that requires a fresh full initialization must advance the plugin version marker. The settings page shows its diagnostic panel only while…

When do periodic checks run?

Periodic resets use WP-Cron. WordPress requests or an external cron trigger are needed for them to run on time. Automatic setup and schedule repair also require the plugin to load; they cannot run while the site is idle. Standard plugin deactivation removes the periodic schedule and invalidates setup state for later activation.

How do I remove or restore an MU installation?

Remove the MU loader and deactivate any separately active standard copy. Removing the loader does not run deactivation, so manually remove the safety_passwords_periodically_reset event from the network’s main site and any legacy subsites. Saved settings and password history remain. If the same-version loader returns, its retained setup marker does not trigger a full history pass. Run Initialize / repair or wp safety init --url= to include current passwords for accounts added during the gap. Password changes made while the code was absent cannot be reconstructed.

What happens when an administrator changes a password with WP-CLI?

With the plugin loaded, wp user update with a password and wp user reset-password complete any pending reset, renew the period, and record the saved password in history. These administrative changes bypass password strength and reuse checks; WP-CLI warns on stderr when a password is changed. Later changes through web forms still check password history. Changes made with the plugin skipped cannot update its history or reset state, and WP-CLI changes made before version 1.5 are not repaired automatically.

What is recorded in logs?

The plugin integrates with Stream. Current password reset logs use fixed failure categories and aggregate periodic reset and reminder counts, without account identifiers or WordPress error details. wp safety check-users likewise logs only aggregate counts and reports Success: Done. Older Stream records may contain details from previous versions. Site operators should review those records privately under their retention policy; updating the plugin does not remove them.

Are older WordPress versions supported?

Background reset emails and silent reset links also work on WordPress 5.0 through 5.6, where the login-page recovery function is unavailable during periodic checks.

Can I install from a source checkout?

The release package includes runtime dependencies. If installing from a source checkout instead, run composer install --no-dev --no-scripts in plugin-dir/ before WordPress loads the plugin.

Changelog

1.5

  • Complete ordinary and must-use setup on normal requests, automatically repair scheduling, and retain current-network policy.
  • Correct password expiry notices, repeated reset handling, constant overrides, and privacy-safe logging.
  • Track standard WP-CLI password changes in history and expiry state, with an explicit strength and reuse bypass warning.
  • Test WordPress 7.1.2 with PHP 8.5 and 8.2; retain PHP 7.4 and WordPress 5 compatibility.

1.4.2

  • Dependencies updated.

1.4.1

  • Put currently used passwords to the stop list on activation.

1.4

  • Previously used password are not allowed to use again.

1.3

  • Fatal error on cron event fixed in php 8. https://github.com/hokoo/safety-passwords/issues/6
  • Text of a log message fixed.
  • php.ini added for local dev.
  • error log watcher git fixed for local dev.

1.2

  • Stream plugin integration fixed. https://github.com/hokoo/safety-passwords/issues/11

Full changelog on WordPress.org →

Screenshots

Settings page
Settings page
Settings are overridden by PHP constants
Settings are overridden by PHP constants
Password change notification
Password change notification
Password change urgency notification
Password change urgency notification
Seamless password change form
Seamless password change form
Weak password is not allowed
Weak password is not allowed

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

FAQ

Safety Passwords: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Oct 4, 2026

Is Safety Passwords free?

Yes. Safety Passwords is free to download and use from the official WordPress.org plugin directory.

Is Safety Passwords safe to use in 2026?

Safety Passwords is a solid plugin choice in 2026, with a few things worth checking first. Is rated 5/5 and was last updated 3 days ago, and scores 71/100 on our health check.

How many websites use Safety Passwords?

Safety Passwords is active on <10 WordPress websites and has been downloaded 2,604 times since it launched in May 2024. It was downloaded 90 times in the last 30 days.

Does Safety Passwords work with WordPress 7.1?

Yes. The developer has tested Safety Passwords up to WordPress 7.1.2, the latest release. It requires WordPress 5.0 or newer.

What PHP version does Safety Passwords need?

Safety Passwords requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was Safety Passwords last updated?

The latest version, 1.5, was released on October 1, 2026 (3 days ago).

Who makes Safety Passwords?

Safety Passwords is developed and maintained by iTRON.

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.