October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk3 min

Why `password_verify()` Returns False With the Correct Password

When PHP’s password_verify() returns false, verify the exact inputs and account hash first. Then check for inconsistent transformations, database truncation and bcrypt’s 72-byte limit.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If password_verify() returns false, first check the exact password string and complete stored hash passed to it—and confirm the hash belongs to the account you looked up. The function returns true only when those values match. Common places to investigate are a wrong database row or field, different password transformations at registration and login, a truncated hash, or bcrypt’s 72-byte input limit. The title alone does not identify which cause applies; that depends on your code, stored value, algorithm and PHP version.

What password_verify() checks

The function takes the password string and the hash created for it, then returns a boolean:

password_verify($password, $hash)

Pass the submitted password as the first argument and the complete stored hash as the second. PHP’s password hashes contain the algorithm, cost and salt information, so you do not need to store those separately for verification. Do not generate a new hash and compare the two hash strings: salts mean hashes of the same password can differ. Use the stored hash with password_verify(). The PHP manual also states that the function is safe against timing attacks. PHP: password_verify()

Check the login lookup and stored hash first

Verify that the database query returns the intended user and the correct password-hash field. An empty result, a different account, or a similarly named field can make verification fail even when the person typed the password they expect.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Check the full value returned by the database driver, not just what a formatted display shows. PHP notes that PASSWORD_DEFAULT may use a stronger algorithm over time, which can change hash length. Its manual recommends a database column that can expand beyond 60 bytes and says 255 bytes is a good choice. A truncated or altered hash will not be fixed by changing the verification call; inspect the actual schema and stored value to establish whether that happened. PHP: password_hash()

Compare registration and login inputs byte for byte

Trace how the password is handled when the account is created and when the user logs in. Both paths must use the intended password value, without applying different trimming, normalization, encoding conversion, prefixes or other transformations. Also check that login passes the stored password_hash() output directly to password_verify(), rather than hashing the submitted password again.

For debugging, inspect whether values are present and their types, plus the password’s byte length and the hash’s length. Avoid logging plaintext passwords or exposing live hashes. A displayed string or character count is not proof that the underlying byte sequences match, particularly when text contains multibyte characters.

If the hash uses bcrypt, check the 72-byte limit

PHP documents that PASSWORD_BCRYPT truncates the password parameter to a maximum of 72 bytes. This is a byte limit, not a visible-character limit: multibyte text can use more than one byte per character. If your application adds a secret or transforms the password before hashing, measure the resulting byte string on both registration and login. This documented limit is bcrypt-specific; do not assume it applies to every password-hashing algorithm. PHP: password_hash()

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use a safe debugging sequence

  1. Confirm the authentication query finds the intended account and returns its password-hash field.
  2. Check value presence and type, and compare password byte length and hash length without printing either secret.
  3. Trace registration and login side by side for differences in trimming, normalization, encoding, prefixes or extra hashing.
  4. Inspect the schema and the complete hash returned by the database driver; verify the column can hold the full value.
  5. Identify the hash algorithm and check its documented input behavior. If it is bcrypt, account for the 72-byte limit.
  6. Keep the verification pattern as password_verify($submittedPassword, $storedHash); do not manually salt or compare freshly generated hashes as strings.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

One separate security issue: leading NUL bytes

A PHP security advisory documents an edge case that caused an incorrect true, not the false result described here: on affected versions, a hash created from a password beginning with a NUL byte could verify an empty password. The advisory lists PHP versions below 8.1.28, 8.2.18 and 8.3.5 as affected, and identifies 8.1.28, 8.2.18 and 8.3.6 as patched releases for those branches. It was published April 11, 2024; these are advisory-specific historical versions, not a current upgrade recommendation. Check the current maintenance release for your PHP branch and patch accordingly, especially if your application accepts binary password input. PHP source repository security advisory

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.