Linux 软件免费装
Banner图

Passwords Evolved

开发者 carlalexander
celsobessa
更新时间 2021年3月22日 05:02
捐献地址: 去捐款
PHP版本: 5.6 及以上
WordPress版本: 5.7
版权: GPLv3
版权网址: 版权信息

标签

security authentication bcrypt password hashing argon2 argon2i argon2id password enforcement libsodium leaked password compromised password hibp have i been pwned

下载

.1.1.1 1.1.0 1.1.1 1.1.2 1.1.3 1.1.4 1.2.0 1.3.0

详情介绍:

The goal of this plugin is to shore up the WordPress authentication using standard security practice recommendations. At this time, the plugin improves WordPress authentication by doing the following: Enforcing uncompromised passwords This plugin prevents someone from using passwords that have appeared in data breaches. Whenever someone logs into a WordPress site, it'll verify their password using the Have I been pwned? API. If their password appeared in a data breach, the plugin will prevent them from logging in until they reset their password. By default, this level of enforcement is only done on an account that has the "administrator" role. You can change which roles have their passwords enforced from the settings page. For people that have a role where there's no password enforcement, the plugin will show a warning when they log in with a compromised password. The enforcement of uncompromised password also extends to when someone resets or changes their password. That said, in those situations, using an uncompromised password is mandatory. Someone will never be able to reset or change their password to one that's appeared in a security breach. (As long as the plugin is able to contact the API.) Using stronger password hashing The plugin also encrypts passwords using either the bcrypt and Argon2 hashing functions. These are the strongest hashing functions available in PHP. Argon2 is available natively starting with PHP 7.2, but the plugin can also encrypt passwords on older PHP versions using the libsodium compatibility layer introduced in WordPress 5.2. You don't have to do anything to convert your password hash to a stronger encryption standard. The plugin will take care of converting it the next time that you log in after installing the plugin. If you decide to remove the plugin, your password will continue working and remain encrypted until you reset it. It's also worth noting that using a stronger hashing function is only important in the advent of a data breach. A stronger password hashing function makes decrypting the passwords from the data breach a lot harder to do. This combined with the enforcement of uncompromised passwords will help ensure that those passwords are never decrypted. (Or at least without significant effort.)

更新日志:

1.3.0 Released: 2021-03-21 1.2.0 Released: 2020-01-03 1.1.4 Released: 2019-05-07 1.1.3 Released: 2018-04-29 1.1.2 Released: 2018-03-21 1.1.1 Released: 2018-03-06 Improved how the API client and password generator handled if the API was online or not. 1.1.0 Released: 2018-03-01 Reworked plugin to use the new version of the HIBP API (Have I been pwned? API) which supports k-anonymity. This allows the plugin to be used in production now. 1.0.0 Released: 2017-08-24 Initial release