| 开发者 | cypressnorth |
|---|---|
| 更新时间 | 2026年9月1日 05:08 |
| PHP版本: | 8.1 及以上 |
| WordPress版本: | 7.1 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
wp cnpp unlock command to release a stuck IP or username without opening the admin.wp_hash_password) and never stores plaintext. The built-in zxcvbn strength meter is left intact. All integration is via documented WP filters and actions — deactivating the plugin removes its behavior cleanly.
cn-password-policy folder to /wp-content/plugins/, or install via the WordPress plugin directory.No. WordPress core stores password hashes; this plugin stores additional one-way hashes of prior passwords for the password-history check, computed with the same wp_hash_password function core uses. No plaintext is persisted.
No. The Have I Been Pwned check uses k-anonymity: the plugin sends only the first five characters of the SHA-1 hash of the password to api.pwnedpasswords.com, and matches the returned suffix list locally. The plaintext never leaves your site. If the HIBP API is unreachable, the rule fails open so password changes are not blocked by an outage.
No. WordPress's strength meter continues to work as before. This plugin enforces its rules at form submission rather than redrawing the meter.
No. 2FA is a separate concern and is handled by purpose-built plugins. This plugin focuses strictly on password strength, lockout, and the surrounding compliance flows.
When a threshold is crossed, the user receives the same generic "invalid credentials" error that any other failed login produces — the locked state is deliberately not disclosed. Admins unlock locked IPs or usernames from Settings → Password Policy → Tools, or via WP-CLI.
Yes, one: wp cnpp unlock --ip=<ip> and/or --user=<id-or-login> releases an active lockout and clears the failed-attempts counter for the supplied identifier. Both flags can be combined in one invocation. A broader CLI surface (stats, settings export, log query) is on the roadmap for a future release.
Not in 1.0. Both plugins use their own registration and password-change paths that don't fire the core WordPress filters this plugin hooks into. Explicit integration is planned for 2.0.
A POT template ships in languages/cn-password-policy.pot. Once the plugin is listed on WordPress.org, translations are accepted via translate.wordpress.org. The plugin declares Text Domain: cn-password-policy and Domain Path: /languages so WordPress's translation loader picks up .mo files automatically.
wp cnpp unlock WP-CLI command.