Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →WordPress encourages strong passwords with a generator and strength meter, but its core software does not let administrators set a custom password policy that every user must follow. To enforce minimum length, composition rules, or forced changes, use a maintained password-policy plugin or an external identity provider—and check that it covers every way accounts can be created or updated. Require a second factor for administrators and other privileged users, too.
What WordPress can—and cannot—enforce on its own
WordPress.org recommends passwords of at least 20 characters, preferably longer, and says each account should have a unique password. It advises avoiding names, dates, dictionary words, and generic terms, and recommends using a password manager. Its guidance also says new and reset accounts receive a generated password with 24 characters, including numbers, letters, capitals, and special characters. See WordPress.org’s password best practices.
WordPress provides useful prompts, not a configurable site-wide password standard. The profile password form displays a strength meter, and the generated-password control helps users choose a strong value. The wp_get_password_hint() API supplies a filterable hint; its default text calls for at least twelve characters and a mix of upper- and lowercase letters, numbers, and symbols. That default hint is not the same as an enforced rule, and it is shorter than WordPress.org’s 20-character recommendation.
For a requirement such as “all users must use at least 20 characters,” or rules that vary by role, install a maintained password-policy plugin or use an external identity provider. Core’s strength meter can help users make a good choice, but it does not reject every password that fails a custom policy.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minute#1 Best Overall
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Set a policy users can follow
Choose a standard that prioritizes length and uniqueness, and explain how to meet it without making account access difficult. A practical policy should tell users to:
- Use a unique password for every WordPress account, ideally generated and stored by a password manager.
- Choose at least 20 characters, in line with WordPress.org’s recommendation.
- Avoid personal details, common words, predictable patterns, and passwords reused on other sites.
- Use the WordPress-generated password or another password-manager-generated value rather than trying to memorize a complex string.
Keep WordPress’s generated-password control and strength meter visible in new-user, profile-change, and password-reset flows. Where the interface needs more explanation, customize the password hint with wp_get_password_hint() so the instruction is clear and consistent with the policy you actually enforce.
Rank #2
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T120. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T120 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-C port : Insert the T120 security key into the USB-C port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
Choose an enforcement method that covers your site
A password-policy plugin can add rules that WordPress core does not expose, such as minimum length, character composition, role targeting, expiry, reporting, and prompts to change a password at login. Plugin directories describe these kinds of features, but a listing does not establish that a particular plugin covers every workflow your site uses. Review current documentation, compatibility, maintenance, and support before deployment; available feature descriptions include the listings for WP Password Policy Manager and Password Policy Manager.
Compare candidates against the account flows that exist on your site, not just the administrator profile screen:
Rank #3
- ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
- ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
- ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
- ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
- ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!
- Coverage: Check administrator-created accounts, user profile changes, lost-password resets, registration or membership forms, REST/API integrations, and any front-end account form.
- Policy depth: Verify that the plugin supports the requirements you need, such as minimum length, character rules, password history, expiry, breached-password screening, or role-specific policies. Do not assume a feature is included unless its current documentation says so.
- User experience: Look for clear validation messages, compatibility with password managers, generated-password support, and a predictable forced-reset process.
- Maintenance and trust: Check the update history, compatibility with your WordPress release, developer reputation, and support arrangements.
- Authentication strength: Treat password rules as one layer. For privileged accounts, also use 2FA, passkeys, or hardware security keys.
If account authentication is managed by an external identity provider, confirm that its password policy applies to the WordPress users and login paths you intend to protect. A rule enforced only in one sign-in route will not protect accounts that can still authenticate another way.
Make existing weak passwords change safely
Enabling a policy usually governs future password changes; it may not automatically identify or replace every existing weak password. If users need to update old credentials, use the plugin’s documented forced-change flow or coordinate a controlled administrative reset. Confirm how the chosen method handles users who sign in through front-end forms or an identity provider.
Rank #4
- ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
- ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
- ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
- ✅ PIN PROTECTION – Locking your device means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
- ✅ EASY LOG IN – No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!
Avoid putting wp_set_password() in code that runs on every request. WordPress’s API reference says the function should be used sparingly and is intended for single-time application; careless use can create an endless reset loop. WordPress 6.8’s changelog states that passwords are hashed with bcrypt by default, but that does not remove the need to manage reset flows carefully.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Add a second factor for privileged accounts
A strong password is not the only protection an administrator account needs. The WordPress Developer Handbook recommends enabling two-factor authentication (2FA) for administrators and other privileged users through a reputable plugin or identity provider. Its 2025 guidance says WordPress core does not ship 2FA, so a plugin or SSO/identity-provider integration is needed. Passkeys and hardware security keys are phishing-resistant options; choose an implementation that supports the sign-in methods your users actually use. See the WordPress security hardening guidance.
Best Value
- Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
- USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
- FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
- Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
- Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
For a plugin-based setup, test enrollment, recovery, account replacement, and the administrator login before making 2FA mandatory. For an identity-provider setup, confirm that WordPress accounts cannot bypass the provider through a separate login path.
Layer defenses against automated password guessing
Password rules do not stop repeated login attempts by themselves. WordPress’s security guidance also recommends layered protections:
- Apply rate limiting at the web server or edge so repeated authentication attempts are slowed or blocked.
- Consider a CAPTCHA or turnstile on appropriate login flows, weighing the added friction and accessibility impact.
- Keep WordPress core, themes, and plugins updated.
- Monitor authentication anomalies so repeated failures or unusual access patterns can be investigated.
- Protect XML-RPC or disable it if your site does not need it.
These controls complement strong, unique passwords and 2FA; none replaces the others.
Quick Recap
Roll out the policy without locking users out
- Write down the standard. State the minimum length, uniqueness requirement, disallowed choices, and password-manager recommendation. Align custom rules with the message users see.
- Test the plugin or identity-provider policy. Use a staging site or test accounts to verify administrator-created users, profile edits, resets, registration, front-end forms, and API-driven account changes.
- Test the recovery path. Confirm forced password changes, 2FA enrollment and recovery, and any alternate sign-in route before applying requirements broadly.
- Enable the policy and communicate it. Give users a clear explanation and let them know how to generate, store, and reset a password.
- Review it over time. Recheck plugin compatibility and updates, review authentication alerts, and verify that new account forms or integrations have not bypassed the policy.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

