Password Policy Manager
View on WordPress.orgScores higher than 61% of indexed plugins
About
Enforce strong passwords with expiry, reset, score checks, inactive user lock, and user password management using Password Policy Manager.
Security History
What It Does
Password Policy Manager lets WordPress administrators enforce password strength rules, set expiration windows, and lock out inactive user accounts from the dashboard. It adds configurable scoring criteria, scheduled password resets, and tools for managing credentials across the user base. In practice, an admin can require a minimum complexity level, force users to rotate passwords every N days, and automatically disable accounts that have been dormant for too long.
Who It's For
This plugin is a sensible fit for membership sites, internal company portals, educational platforms, and any WordPress install that holds multiple user accounts where password hygiene matters. It is especially relevant for site owners subject to compliance requirements around credential rotation and inactive account management. Smaller single-author blogs or brochure sites with no real user accounts will not get value from it.
Who Should Skip It
If your site has only one or two editors and no public registration, the enforcement features are overkill and add unnecessary friction. Site owners relying on an external identity provider such as SSO or Google Login should also skip this, as WordPress-level password rules do not apply to those login flows.
The Bottom Line
Password Policy Manager delivers a solid feature set for enforcing password rules, expiry, and inactive account policies, and the maintenance and compatibility signals are encouraging. The thin support history and small install base mean you are taking a modest bet on a lesser-known developer. If credential enforcement matters on your WordPress site, it is worth a try; if you need a long track record of community validation, look further.