{"repo":"carlalexander/passwords-evolved","free":true,"listed":false,"github":"https://github.com/carlalexander/passwords-evolved","clone":"git clone https://github.com/carlalexander/passwords-evolved.git","description":"WordPress password authentication for the modern era","language":"PHP","stars":106,"topics":["wordpress","security","bcrypt","password-enforcement","authentication"],"license":"GPL-3.0","category":"auth-billing-email","readme_excerpt":"Passwords Evolved A reimagining of WordPress authentication using modern security practices. Requirements PHP = 5.6 What does this plugin do? The goal of this plugin is to shore up the WordPress authentication using standard security practice recommendations. At this time, the plugin improves WordPress authentication by doing the following: Enforcing uncompromised passwords This plugin prevents someone from using passwords that have appeared in data breaches. Whenever someone logs into a WordPress site, it'll verify their password using the Have I been pwned? API. If their password appeared in a data breach, the plugin will prevent them from logging in until they reset their password. By default, this level of enforcement is only done on an account that has the \"administrator\" role. You can change which roles have their passwords enforced from the settings page. For people that have a role where there's no password enforcement, the plugin will show a warning when they log in with a compromised password. The enforcement of uncompromised password also extends to when someone resets or changes their password. That said, in those situations, using an uncompromised password is mandatory. Someone will never be able to reset or change their password to one that's appeared in a security breach. (As long as the plugin is able to contact the API.) Using stronger password hashing The plugin also encrypts passwords using either the bcrypt and Argon2 hashing functions. These are the stron","default_branch":null,"files":null,"tree":[],"storefront":"/r/carlalexander","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/carlalexander/passwords-evolved/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}