Title: No Weak Passwords
Author: David Anderson / Team Updraft
Published: <strong>Novanm 19, 2012</strong>
Last modified: Dawout 13, 2026

---

Search plugins

![](https://s.w.org/plugins/geopattern-icon/no-weak-passwords.svg)

# No Weak Passwords

 By [David Anderson / Team Updraft](https://profiles.wordpress.org/davidanderson/)

[Download](https://downloads.wordpress.org/plugin/no-weak-passwords.1.0.2.zip)

 * [Details](https://hat.wordpress.org/plugins/no-weak-passwords/#description)
 * [Reviews](https://hat.wordpress.org/plugins/no-weak-passwords/#reviews)
 *  [Installation](https://hat.wordpress.org/plugins/no-weak-passwords/#installation)
 * [Development](https://hat.wordpress.org/plugins/no-weak-passwords/#developers)

 [Support](https://wordpress.org/support/plugin/no-weak-passwords/)

## Description

This plugin forbids any user to choose any password from the “common passwords list”
obtained from http://www.openwall.com/passwords/wordlists/, and requires any who
are already doing so to reset their passwords.

### License

Copyright 2012- David Anderson

MIT License:

Permission is hereby granted, free of charge, to any person obtaining
 a copy of
this software and associated documentation files (the “Software”), to deal in the
Software without restriction, including without limitation the rights to use, copy,
modify, merge, publish, distribute, sublicense, and/or sell copies of the Software,
and to permit persons to whom the Software is furnished to do so, subject to the
following conditions:

The above copyright notice and this permission notice shall be
 included in all 
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED “AS IS”, WITHOUT WARRANTY OF ANY KIND,
 EXPRESS OR IMPLIED,
INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR
PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS 
BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT,
TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE
USE OR OTHER DEALINGS IN THE SOFTWARE.

## Screenshots

[⌊The error message when a user tries to change his password to an easy one⌉⌊The
error message when a user tries to change his password to an easy one⌉[

The error message when a user tries to change his password to an easy one

[⌊The error message when a user with an existing easy password tries to log in⌉⌊
The error message when a user with an existing easy password tries to log in⌉[

The error message when a user with an existing easy password tries to log in

## Installation

Standard WordPress plugin installation:

 1. Search for “No Weak Passwords” in the WordPress plugin installer
 2. Click ‘Install’

## FAQ

### Where are the configuration settings?

There are none. If the plugin is active, then it is banning all of its known weak
passwords.

### What if one of my users is already using one of those passwords?

If they try to log in with one of these weak passwords, then they will not succeed,
and they will be told to use the ‘Lost Password’ procedure to obtain a new password.

### What passwords does this plugin ban?

The 3546 listed in the “common passwords list” as obtained from http://www.openwall.
com/passwords/wordlists/ on 16th November 2012.

### I’d like to change the policy; add some different words; forbid too-short passwords, etc.

Please either send a patch, or make a donation on my donation page, and I will be
glad to help. Otherwise, this plugin does all I wanted it to do and I’ve not got
time to develop it further without some compensation.

### Do you have any more interesting plugins?

Try [here](https://profiles.wordpress.org/davidanderson/#content-plugins) and [here](https://www.simbahosting.co.uk/s3/shop/).

## Reviews

![](https://secure.gravatar.com/avatar/4fa2a303e6e4b18ed3e8ae8c16e00cace0391c0a0fedc07b247fa6d038d298d8?
s=60&d=retro&r=g)

### 󠀁[Accepts weak passwords](https://wordpress.org/support/topic/accepts-weak-passwords/)󠁿

 [Arnd030](https://profiles.wordpress.org/arnd030/) Jiyè 15, 2023 1 reply

The plugin only refuses to accept weak passwords that are blacklisted: Your password
exists on a list of known easy-to-guess passwords, and hence was forbidden. Apart
from that, even very weak passwords are accepted! This, I am sorry to say, makes
this plugin useless.

![](https://secure.gravatar.com/avatar/c2e80d04a72543eca324ed331d17904774c713eb55532828d93202568336e4e4?
s=60&d=retro&r=g)

### 󠀁[Excellent idea](https://wordpress.org/support/topic/excellent-idea-14/)󠁿

 [Jerry Hudgins](https://profiles.wordpress.org/laureldigital/) Desanm 1, 2018

Well done; thanks.

 [ Read all 4 reviews ](https://wordpress.org/support/plugin/no-weak-passwords/reviews/)

## Contributors & Developers

“No Weak Passwords” is open source software. The following people have contributed
to this plugin.

Contributors

 *   [ David Anderson / Team Updraft ](https://profiles.wordpress.org/davidanderson/)

[Translate “No Weak Passwords” into your language.](https://translate.wordpress.org/projects/wp-plugins/no-weak-passwords)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/no-weak-passwords/),
check out the [SVN repository](https://plugins.svn.wordpress.org/no-weak-passwords/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/no-weak-passwords/)
by [RSS](https://plugins.trac.wordpress.org/log/no-weak-passwords/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.0.2 05/31/2017

 * COMPATIBILITY: Marked as compatible with WP 4.8
 * TWEAK: If no password given, then presume they are using some other login mechanism(
   and if they are not, WP will refuse the login anyway)

#### 1.0.1 04/19/2013

 * Marked as compatible with 3.6

#### 1.0.1 12/03/2012

 * Tweaked install instructions
 * Marked compatible with 3.1
 * Added link to new “use adminstrator password” plugin

#### 1.0 11/16/2012

 * First version

## Meta

 *  Version **1.0.2**
 *  Last updated **3 weeks ago**
 *  Active installations **400+**
 *  WordPress version ** 3.2 or higher **
 *  Tested up to **7.1**
 *  Language
 * [English (US)](https://wordpress.org/plugins/no-weak-passwords/)
 * Tags
 * [password strength](https://hat.wordpress.org/plugins/tags/password-strength/)
   [passwords](https://hat.wordpress.org/plugins/tags/passwords/)
 *  [Advanced View](https://hat.wordpress.org/plugins/no-weak-passwords/advanced/)

## Ratings

 4 out of 5 stars.

 *  [  3 5-star reviews     ](https://wordpress.org/support/plugin/no-weak-passwords/reviews/?filter=5)
 *  [  0 4-star reviews     ](https://wordpress.org/support/plugin/no-weak-passwords/reviews/?filter=4)
 *  [  0 3-star reviews     ](https://wordpress.org/support/plugin/no-weak-passwords/reviews/?filter=3)
 *  [  0 2-star reviews     ](https://wordpress.org/support/plugin/no-weak-passwords/reviews/?filter=2)
 *  [  1 1-star review     ](https://wordpress.org/support/plugin/no-weak-passwords/reviews/?filter=1)

[Your review](https://wordpress.org/support/plugin/no-weak-passwords/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/no-weak-passwords/reviews/)

## Contributors

 *   [ David Anderson / Team Updraft ](https://profiles.wordpress.org/davidanderson/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/no-weak-passwords/)

## Donate

Would you like to support the advancement of this plugin?

 [ Donate to this plugin ](https://david.dw-perspective.org.uk/donate)