Disable Application Passwords
View on WordPress.orgScores higher than 58% of indexed plugins
About
Activate this plugin to disable the Application Passwords feature that was added in WP v5.6.
What It Does
This plugin removes the Application Passwords feature introduced in WordPress 5.6, which allows external applications to authenticate via dedicated passwords. Once activated, the feature is disabled site-wide and no application passwords can be generated or used.
Who It's For
This is a niche security hardening tool aimed at administrators of regulated or high-security environments such as healthcare, finance, legal, and government sites where unused authentication surfaces must be eliminated to satisfy compliance auditors. It suits IT teams who want to lock down WordPress to only the authentication methods they explicitly permit.
Who Should Skip It
If you rely on integrations such as Zapier, mobile apps, Jetpack, or any third-party tool that uses Application Passwords to connect to your site, do not install this plugin, as it will break those connections. Small blogs and standard business sites with no compliance pressure have little reason to disable a feature they are not actively using.
The Bottom Line
Disable Application Passwords does one thing and does it well, earning a 77.28 overall quality score driven by flawless maintenance and ratings. It is a sensible addition to compliance-focused hardening stacks but is unnecessary and potentially harmful for sites that depend on Application Password integrations.
Related Plugins
Pick this instead if your goal is to restore the classic widget UI rather than harden authentication surfaces.
Choose this for a similar minimalist disable-style plugin if your concern is performance and GDPR cleanup from emoji scripts.
Select this if you want a broader toolkit that disables multiple WordPress features from a single interface, not just Application Passwords.
Pick this if comments are your unused attack surface rather than Application Passwords, especially on brochure or intranet sites.
Choose this if you want to restrict another authentication-adjacent surface, the REST API, for similar compliance-driven hardening.