Require certain users to change their passwords on a regular basis.
Contributors: fjarrett
Tags: admin, login, membership, passwords, profile, security, users
Requires at least: 4.0
Tested up to: 4.7
Stable tag: 0.6.0
License: GPL-2.0
Did you find this plugin helpful? Please consider leaving a 5-star review.
Harden the security of your site by preventing unauthorized access to stale user accounts.
This plugin is also ideal for sites needing to meet certain industry security compliances - such as government, banking or healthcare.
In the plugin settings you can set the maximum number of days users are allowed to use the same password (90 days by default), as well as which user roles will be required to reset their passwords regularly (non-Administrators by default).
Languages supported:
- English
- Czech
- Español
Development of this plugin is done on GitHub. Pull requests welcome. Please see issues reported there before going to the plugin forum.
- Fix: Expiration not updating when resetting a password via email confirmation link.
Props @fjarrett
- Tweak: Indicate support for WordPress 4.7 and require at least 4.0.
- Fix: Selected user roles in plugin settings not always being honored.
- Fix: Destroy all sessions after login with an expired password.
Props @fjarrett
- New: Indicate support for WordPress 4.5.
- Tweak: Bring back PHP 5.2 compatibility.
Props @fjarrett
- New: Language support for Czech
- Tweak: Optimizations requiring PHP 5.3 or higher
- Fix: User role array error before options exist
- New: Language support for Español
Props @fjarrett
- Fix: Fatal undefined function error occuring in some cases (#3)
Props @fjarrett
- New: Disallow using the same password as before on reset (#1)
- Tweak: Use default if limit is set to greater than 365 days
Props @fjarrett
- Initial release
Props @fjarrett