Password bcrypt
Password bcrypt
Description
wp-password-bcrypt is a WordPress plugin to replace WP’s outdated and insecure
MD5-based password hashing with the modern and secure bcrypt.
It is written by roots.io people.
This plugin requires PHP >= 5.5.0 which introduced the built-in
password_hash and
password_verify functions.
See Improving WordPress Password Security
for more background on this plugin and the password hashing issue.
Installation
- Upload the plugin files to the
/wp-content/plugins/password-bcryptdirectory, or install the plugin through the WordPress plugins screen directly. - Activate the plugin through the ‘Plugins’ screen in WordPress
Faq
Manual installation as a must-use plugin
If you don’t use Composer, you can manually copy wp-password-bcrypt.php into your mu-plugins folder.
We do not recommend using this as a normal (non-MU) plugin. It makes it too easy to disable or remove the plugin.
Reviews
Works Perfectly
By Ward (YWard) on March 19, 2018
Simply the best
By Martin Hlavac (hlavacm) on November 15, 2017
Important plugin!
By Michal Danko (michaldanko) on September 17, 2017
Changelog
1.0.3
- Check for another password plugin.
1.0.2
- Added license file, excuse me.
1.0.1
- This is the WordPress-stlye version of the original roots wp-password-bcrypt plugin