WP Force Password
This plugin is ideal for security reasons, provides password update reminders.
Use with caution
WP Force Password works, but test it on a staging site before relying on it in 2026. It runs on 100+ sites and was last updated 4 months ago, and scores 53/100 on our health check.
- Small user base (100+ active installs)
- Very few reviews so far
Daily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where WP Force Password stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| expiry-password | #12 |
| force-password | #23 |
| password | #84 |
Version adoption
Share of active sites per release.
About WP Force Password
From the official readme · v2.4Description
This plugin is ideal for security reasons, provides password update reminders.
In the plugin settings, you can set Password Reset Days, and Select User roles will be required to reset their password regularly.
If the user password has expired this plugin redirects the login user to the admin screen profile.php page and the front end login lost password page wp-login.php to force change their password.
And also notice is displayed informing they must require to change their password to continue using this website.
Features of the Free WP Force Password plugin:
* Add password reset days
* Select user roles to allow the change expiry password
* Enable/Disable reset password feature for any user
* Force users to update expiry password
* Reminder email notification for password expired
Pro Features:
– Enable force password reset for all user based on the user regsitration date
Upgrade to Pro
Unlock powerful customization with the **Pro version**:
- WP Force Password PRO version
- Enable force password reset for all user based on the user regsitration date.
- Priority support and regular feature updates
Explore more here:
Documentation
Support
How can I disable notifications based on the WordPress environment
This plugin use wp_get_environment_type() to retrieve the current environment type.
the WP_ENVIRONMENT_TYPE in the wp-config.php file to disable the notification for all the environments except the production.
The type can be set via the WP_ENVIRONMENT_TYPE in wp-config.php file.
Possible values are ‘local’, ‘development’, ‘staging’, and ‘production’. If not set, the type defaults to ‘production’.
Refrence url
Installation
Installation Steps
- Upload the folder to
/wp-content/plugins/directory - Activate the plugin through the ‘Plugins’ menu in WordPress
- Go to the admin WP Force Password Menu to enable plugin options
Frequently asked questions
How to use the WP Force Password plugin?
In the plugin settings, you can set Password Reset Days, and Select User roles will be required to reset their password regularly. ex: wp-admin > WP Force Password
How we can enable or disable the force password reset feature for any user?
Admin can edit any user profile or any user have an option on the profile page to enable or disable the force password reset feature. In the plugin settings, the only selected user roles can use enable or disable the force password reset feature. ex: wp-admin > profile.php > Enable Force Password
How to update the expiry password?
If the user’s password has been expired then after login it will automatically redirect to the admin screen profile page to see change expiry password notification then update the expiry password. ex: wp-admin > profile.php > New Password and in the site, front end login lost password page to see change expiry password notification then update the expiry password. ex: wp-login.php?action=lostpassword
How to change the expiry password notification message?
Admin can set the expiry password notification message, via the plugin setting page added password change notification message otherwise it will show the default message. ex: wp-admin > WP Force Password > Expiry Password Change Notification Message
How can I disable notifications based on the WordPress environment
This plugin use wp_get_environment_type() to retrieve the current environment type. The WP_ENVIRONMENT_TYPE in the wp-config.php file to disable the notification for all the environments except the production. The type can be set via the WP_ENVIRONMENT_TYPE in wp-config.php file. Possible values are ‘local’, ‘development’, ‘staging’, and ‘production’. If not set, the type defaults to ‘production’. Refrence url : https://developer.wordpress.org/reference/functions/wp_get_environment_type/
Changelog
Checked compatibility with WordPress 7.0.
2.4
Checked compatibility with WordPress 7.0.
Security improvements for redirects, settings sanitization, and form handling.
2.3
New Release
2.2
Checked compatibility with wordpress 6.8
Introduce paid version of plugin force password pro to enhance the functionality.
2.1
Stable Release
2.0
Stable Release
1.2.3
Stable Release
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
FAQ
WP Force Password: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Sep 30, 2026
Is WP Force Password free?
Yes. WP Force Password is free to download and use from the official WordPress.org plugin directory.
Is WP Force Password safe to use in 2026?
WP Force Password works, but test it on a staging site before relying on it in 2026. It runs on 100+ sites and was last updated 4 months ago, and scores 53/100 on our health check.
How many websites use WP Force Password?
WP Force Password is active on 100+ WordPress websites and has been downloaded 10,168 times since it launched in November 2020. It was downloaded 377 times in the last 30 days.
Does WP Force Password work with WordPress 7.1?
WP Force Password is officially tested up to WordPress 7.0.6, while the latest release is 7.1.2. It may still work, but try it on a staging site first.
What PHP version does WP Force Password need?
WP Force Password requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was WP Force Password last updated?
The latest version, 2.4, was released on June 2, 2026 (4 months ago).
Who makes WP Force Password?
WP Force Password is developed and maintained by Galaxy Weblinks.
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card



