Expire User Passwords icon

Expire User Passwords

by Matt Miller

View on WordPress.org
74 Quality Score
Active Installs
16/30

3,000 active installs is a small user base, so you should not expect a large community of people running the same setup as you.

Update Freshness
23/25

Last updated in February 2026 and marked as tested up to WordPress 6.9.4, which signals very active and current maintenance.

User Rating
13/15

A score of 84/100 from only 5 ratings is a positive signal but the sample size is far too small to be statistically meaningful.

Support Health
8/15

0 of 0 support threads means there is simply no track record yet on the public forum for resolving user issues.

WP Compatibility
15/15

Tested on the latest WordPress release and requires PHP 8.1, so modern stacks are well covered but older PHP 7.x hosts will be locked out.

Scores higher than 33% of indexed plugins

About

Require certain users to change their passwords on a regular basis.

Active Installs 3k+
Rating ★★★★ 4.2/5
Last Updated 2026-02-17 9:27am GMT
Requires WordPress 4.0+
Tested Up To 6.9.7
Requires PHP 8.1+
✓ No known vulnerabilities

What It Does

Expire User Passwords forces selected user roles to rotate their passwords on a schedule you configure. When a password's maximum age is reached, the user is locked out of further dashboard or front-end activity until they set a new one. It does not enforce complexity rules, two-factor authentication, or login attempt limits.

Who It's For

This is a good fit for sites in regulated industries (healthcare, finance, government, education) where password rotation policies are mandated, or for membership and employee portals where admins want scheduled credential refreshes. It is most useful on sites with a small, stable set of controlled user roles rather than public-facing registrations.

Who Should Skip It

If you run a personal blog, a small business site, or any environment where mandatory password changes would frustrate members more than they help, skip this. Most general WordPress sites do not need scheduled expiry, and broader security suites already cover the related risks.

The Bottom Line

Expire User Passwords does one specific job and appears to do it well on a modern stack, with a recent update and clean compatibility profile. The downsides are the tiny install count, the near-empty support history, and the narrow feature set, which means it is best treated as a single-purpose tool inside a larger security strategy rather than a complete password security solution. Overall Quality Score: 75.67/100.

Tags

login membership passwords security users