Linux 软件免费装
Banner图

Password Strength Settings for WooCommerce

开发者 danielsantoro
更新时间 2023年7月6日 00:41
PHP版本: 4.6.0 及以上
WordPress版本: 7.9.0
版权: GPL
版权网址: 版权信息

标签

WooCommerce Security Users Passwords Accounts

下载

详情介绍:

What does this plugin do? WooCommerce has an integrated Password Strength Meter which forces users to use strong passwords. Sometimes this isn't desirable - with this plugin, you can choose between five password levels ranging from "Anything Goes" to "Strong Passwords Only". In addition, you can modify the colors and appearance of these custom messages, as well as modify or remove the password hint. For details on how the password strength is determined, please read the documentation here. What's New? Version 3.0.0 is a bit of a rewrite to bring the plugin up to modern coding standards. Functionality should not be impacted, but if it is, please reach out on the support forums. Version 3.0.1 is simply a hotfix declaring compatibility with WooCommerce HPOS. Since this plugin doesn't touch anything with the orders or order metadata, it shouldn't be impacted at all. However, if you notice any issues then please reach out via the contact form on my website. Notes While this does allow for user accounts to have weaker passwords, it's a good idea to still encourage strong password use - especially for administrators! Planned Features Upgrade Notice 3.0.0 This is a bit of a re-code to bring the plugin up to modern code standards. Functionality should not be impacted, but if it is, please reach out on the support forums. 2.2.2 This version has a change to jQuery required for WordPress 5.7. After installation, please test that the admin area works on your site. 2.2.1 This version fixes some broken text strings and shouldn't have any negative impact on your site. 2.2.0 This version adds localization options for various languages. There is also an update FAQ section on the plugin's homepage.

安装:

  1. Download the plugin & install it to your wp-content/plugins folder (or use the Plugins menu through the WordPress Administration section)
  2. Activate the plugin
  3. Navigate to WooCommerce > Settings > Accounts and edit the fields at the bottom. There, you can choose the strength of the required passwords as well as change the messaging that appears as a user enters their password, change colors, and change any password guidelines.
  4. Save and enjoy!

常见问题:

Q: What does each level do?

A: The levels range from 0 (lowest) to 4 (highest). As passwords are typed, the strength meter will dynamically update - this will disable the "Sign Up" button until the requirements have been met. It should be noted that Level 0 accepts any password, so messaging isn't shown (and therefore doesn't have admin fields).

Q: Where does this meter show up?

A: This should appear wherever the Password Strength Meter appears - in the "My Account" page or during Checkout.

Q: How is the password strength determined?

A: The password strength is determined by code in WordPress core, more specifically using a library called "zxcvbn", created by Dropbox. There's a more in-depth description of how this works in the plugin documentation.

Q: How can I require numbers, special characters, or a certain length?

A: This plugin doesn't allow for that functionality, because it's not part of the built-in WordPress password strength algorithms. Those restrictions have also been proven to be ineffective and frustrating for users. See How Password Strength is Determined.

Q: Why is my password marked as weak?

A: This is the most common question I get, and the short answer is I don't know, but you can likely figure it out with the guide on How Password Strength is Determined.

Q: This allows weak passwords during account creation in checkout - what gives?

A: This is unfortunately unavoidable. As of writing, WooCommerce doesn't validate the password strength in the checkout page, so while the strength meter will show it doesn't enforce it. This isn't something I'm able to work around, so share that you want validation on the password strength requirements in the official WooCommerce Ideas Board - once it's active in WooCommerce, it will automatically be active here. :)

Q: My site was recently hacked. Is this plugin vulnerable, or does it cause vulnerabilities?

A: No, this plugin does not create any vulnerabilities. It does create additional displays for the client-side (in the user's browser), but not server-side where vulnerabilities are found. It is using the Password Strength Meter that is already in WordPress, and doesn't store or handle any information - WordPress or WooCommerce are the only ones that see and manage passwords, not this plugin. For security advice, please check out this older but still valid security 101 guide I've written.

Q: Where can I go if I find an issue or want to recommend a feature?

A: If you experience any issues, please let the developer know. If you have ideas for future features or improvements, head over to GitHub to see if something is in development or to help contribute.

Q: Dang, this is pretty awesome. Where can I see some of your other stuff?

A: You can check out the Danny's personal site at DanielSantoro.com. He doesn't keep up with it as much as he'd like, but it's there.

更新日志:

2/22/2021 - Version 2.2.2 10/21/2020 - Version 2.2.1 8/21/2020 - Version 2.2.0 4/25/2019 - Version 2.1.0 2/9/2018 - Version 2.0.2 9/21/2017 - Version 2.0.1 8/25/2017 - Version 2.0.0 8/1/2017 - Version 1.2.0 4/5/2017 - Version 1.1.0 3/28/2017 - Version 1.0.2 9/28/2016 - Version 1.0.1 7/24/2016 - Version 1.0.0