跳至主要內容
WordPress.org

Taiwan 正體中文

  • 佈景主題目錄
  • 外掛目錄
  • 最新消息
  • 技術支援
  • 關於我們
  • 團隊
  • 取得 WordPress
取得 WordPress
WordPress.org

Plugin Directory

Cypress North Password Policy

  • 提交外掛
  • 我的最愛
  • 登入
  • 提交外掛
  • 我的最愛
  • 登入

Cypress North Password Policy

由 cypressnorth 開發
下載
  • 詳細資料
  • 使用者評論
  • 安裝方式
  • 開發資訊
技術支援

外掛說明

Cypress North Password Policy enforces a strong, modern password policy on your WordPress site. Defaults align with NIST 800-63B guidance: length over composition rules, denylist screening, breach-corpus checks, and rate-limited login. Every setting is admin-configurable.

What you get

  • A password rule engine that validates on user registration, password reset, and profile updates — covering minimum length, character requirements, breach-corpus check via the Have I Been Pwned k-anonymity API, denylist of common passwords, edit-distance check against the current password, and a per-user history check.
  • Layered failed-login lockout: separate thresholds per IP and per username, with rolling windows and auto-release. Generic “invalid credentials” error responses so locked state is not disclosed to attackers.
  • A soft-force interstitial that catches users at next login when their password is expired, breached, or below the active policy — they cannot escape without choosing a compliant new password.
  • Daily email summary for administrators when attack rates spike.
  • Per-user notification emails on password change, lockout, and expiration warnings.
  • GDPR exporter + eraser that integrate with WordPress’s built-in Personal Data tools.
  • Audit log of every relevant event (login failures, lockouts, password changes, compliance state transitions) viewable in the admin.
  • Cleanup cron that trims old failed-attempt rows on a configurable schedule.
  • WP-CLI wp cnpp unlock command to release a stuck IP or username without opening the admin.
  • Multisite-aware: super-admin can globally configure or delegate per-site management.

Designed to coexist with WordPress core

The plugin uses WordPress’s own password hashing (wp_hash_password) and never stores plaintext. The built-in zxcvbn strength meter is left intact. All integration is via documented WP filters and actions — deactivating the plugin removes its behavior cleanly.

External services

This plugin connects to an API to check for known breached passwords.

The Have I Been Pwned API (api.pwnedpasswords.com) receives only the first five characters of a SHA-1 hash — k-anonymity. No personally identifying information leaves the site and no plain text is transmitted. The check can be disabled entirely from Settings → Password Policy → Policy.

This service is provided by Have I Been Pwned (https://haveibeenpwned.com/) : terms of use , privacy policy

Privacy

This plugin processes data necessary to enforce account security. The full privacy disclosure is contributed to Tools → Privacy Policy Guide when the plugin is active.

What is collected

  • Failed login attempts (IP, username attempted, timestamp).
  • Lockout events (identifier, lockout-until timestamp).
  • Password-change audit-log rows.
  • Per-user: timestamp of last password change, compliance flag, a small queue of one-way hashes of previous passwords, and the most recent HIBP breach-check result (if enabled).

Lawful basis

Legitimate interest in preventing brute-force credential attacks, plus regulatory and contractual obligations around password hygiene where applicable.

Retention

  • Failed-attempt rows: pruned daily by cron, default kept for the duration of the lockout window (typically 24 hours).
  • Audit-log rows: default 90 days, configurable.
  • Per-user compliance and history data: kept while the user account exists; removed via the GDPR eraser on request.

Third parties

The Have I Been Pwned API (api.pwnedpasswords.com) receives only the first five characters of a SHA-1 hash — k-anonymity. No personally identifying information leaves the site. The check can be disabled entirely from Settings → Password Policy → Policy.

Exporter + eraser

The plugin registers with WordPress’s built-in Personal Data tools (Tools → Export Personal Data, Tools → Erase Personal Data). Exports return four groups (failed attempts, lockouts, password-change events, compliance state). Erasure removes the password-change audit rows and every plugin-specific user_meta entry; lockout and failed-attempt rows are retained with the username field redacted so aggregate-attack statistics remain intact but the rows can no longer be linked to the individual.

螢幕擷圖

Login Protection tab — failed-attempt thresholds and lockout durations.
Login Protection tab — failed-attempt thresholds and lockout durations.
Policy tab — length, character, history, and breach-check rules.
Policy tab — length, character, history, and breach-check rules.
Notifications tab — per-event toggles and attack-digest schedule.
Notifications tab — per-event toggles and attack-digest schedule.
Audit Log tab — searchable list of every relevant event.
Audit Log tab — searchable list of every relevant event.
Tools tab — HIBP connectivity test and manual unlock controls.
Tools tab — HIBP connectivity test and manual unlock controls.
Soft-force interstitial — what a non-compliant user sees on next login.
Soft-force interstitial — what a non-compliant user sees on next login.

安裝方式

  1. Upload the cn-password-policy folder to /wp-content/plugins/, or install via the WordPress plugin directory.
  2. Activate the plugin through the Plugins menu in WordPress.
  3. Visit Settings → Password Policy to review the defaults and adjust thresholds, lockout windows, notification recipients, and trusted-proxy configuration.

On multisite, network-activate the plugin to install the custom tables on every existing site. New sites created later get the tables automatically.

常見問題集

Does this plugin store plaintext passwords?

No. WordPress core stores password hashes; this plugin stores additional one-way hashes of prior passwords for the password-history check, computed with the same wp_hash_password function core uses. No plaintext is persisted.

Does the HIBP breach check send my password over the network?

No. The Have I Been Pwned check uses k-anonymity: the plugin sends only the first five characters of the SHA-1 hash of the password to api.pwnedpasswords.com, and matches the returned suffix list locally. The plaintext never leaves your site. If the HIBP API is unreachable, the rule fails open so password changes are not blocked by an outage.

Does it replace WordPress’s built-in zxcvbn strength meter?

No. WordPress’s strength meter continues to work as before. This plugin enforces its rules at form submission rather than redrawing the meter.

Does it include two-factor authentication?

No. 2FA is a separate concern and is handled by purpose-built plugins. This plugin focuses strictly on password strength, lockout, and the surrounding compliance flows.

How does the lockout interact with the WordPress login form?

When a threshold is crossed, the user receives the same generic “invalid credentials” error that any other failed login produces — the locked state is deliberately not disclosed. Admins unlock locked IPs or usernames from Settings → Password Policy → Tools, or via WP-CLI.

Is there a WP-CLI command?

Yes, one: wp cnpp unlock --ip=<ip> and/or --user=<id-or-login> releases an active lockout and clears the failed-attempts counter for the supplied identifier. Both flags can be combined in one invocation. A broader CLI surface (stats, settings export, log query) is on the roadmap for a future release.

Does it support WooCommerce or BuddyPress checkout/registration flows?

Not in 1.0. Both plugins use their own registration and password-change paths that don’t fire the core WordPress filters this plugin hooks into. Explicit integration is planned for 2.0.

How do I translate the plugin?

A POT template ships in languages/cn-password-policy.pot. Once the plugin is listed on WordPress.org, translations are accepted via translate.wordpress.org. The plugin declares Text Domain: cn-password-policy and Domain Path: /languages so WordPress’s translation loader picks up .mo files automatically.

使用者評論

這個外掛目前沒有任何使用者評論。

參與者及開發者

以下人員參與了開源軟體〈Cypress North Password Policy〉的開發相關工作。

參與者
  • cypressnorth

將〈Cypress North Password Policy〉外掛本地化為台灣繁體中文版

對開發相關資訊感興趣?

任何人均可瀏覽程式碼、查看 SVN 存放庫,或透過 RSS 訂閱開發記錄。

變更記錄

1.0.0

  • Initial release.
  • NIST-aligned password rule engine with HIBP breach checking, denylist screening, edit-distance check, and per-user history.
  • Layered failed-login lockout (per-IP and per-username) with rolling windows, auto-release, and admin-controlled manual unlock.
  • Soft-force interstitial covering expired, breached, and below-policy passwords.
  • Per-event notification dispatcher with daily attack-detection digest for admins.
  • Audit log viewer.
  • GDPR exporter and eraser integrated with WordPress core Privacy tools.
  • Multisite super-admin gating with delegated per-site management toggle.
  • Uninstall path that respects the admin’s data-removal preference (default off — security plugins should not silently delete the audit trail).
  • wp cnpp unlock WP-CLI command.

中繼資料

  • 版本 1.0.0
  • 最後更新 5 天前
  • 啟用安裝數 少於 10 次
  • WordPress 版本需求 6.0 或更新版本
  • 已測試相容的 WordPress 版本 7.0.2
  • PHP 版本需求 8.1 或更新版本
  • 語言
    English (US)
  • 標籤:
    login protectionpasswordsecurity
  • 進階檢視

評分

這個項目尚無任何評論記錄。

Your review

查看全部使用者評論

參與者

  • cypressnorth

技術支援

使用者可在技術支援論壇提出意見反應或使用問題。

檢視技術支援論壇

  • 關於我們
  • 最新消息
  • 主機代管
  • 隱私權
  • 展示網站
  • 佈景主題目錄
  • 外掛目錄
  • 區塊版面配置目錄
  • Learn
  • 技術支援
  • 開發者資源
  • WordPress.tv ↗
  • 共同參與
  • 活動
  • 贊助基金會 ↗
  • Five for the Future
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org

Taiwan 正體中文

  • 查看我們的 X (之前的 Twitter) 帳號
  • 造訪我們的 Bluesky 帳號
  • 造訪我們的 Mastodon 帳號
  • 造訪我們的 Threads 帳號
  • 造訪我們的 Facebook 粉絲專頁
  • Visit our Instagram account
  • Visit our LinkedIn account
  • 造訪我們的 TikTok 帳號
  • Visit our YouTube channel
  • 造訪我們的 Tumblr 帳號
程式碼,如詩
The WordPress® trademark is the intellectual property of the WordPress Foundation.