Passwords Evolved icon

Passwords Evolved

by Carl Alexander

View on WordPress.org
46 Quality Score
Active Installs
14/30

With only 1,000 active installs, this is a niche plugin with very limited adoption across the WordPress ecosystem.

Update Freshness
8/25

The plugin was updated on March 23, 2025, and is tested against WordPress 6.8.0, suggesting the developer is keeping pace with core releases despite the small user base.

User Rating
6/15

The perfect 100/100 rating comes from just 2 reviews, which is too small a sample to be statistically meaningful.

Support Health
8/15

There are zero support threads in the repository, which means either no issues exist or, more likely given the install count, the plugin has not been widely exercised under varied conditions.

WP Compatibility
11/15

Compatibility scores well at 75/100, reflecting the current WordPress 6.8.0 test and a low PHP 5.6 requirement that works on most hosting environments.

Scores higher than 2% of indexed plugins

About

A reimagining of WordPress authentication using modern security practices.

Active Installs 1k+
Rating ★★★★★ 5/5
Last Updated 2025-03-23 2:54am GMT
Requires WordPress 5.2+
Tested Up To 6.8.0
Requires PHP 5.6+
✓ No known vulnerabilities

What It Does

Passwords Evolved strengthens WordPress login security by enforcing modern password policies, blocking weak or compromised passwords using the Have I Been Pwned database, and rewriting default authentication behaviour to resist common attack vectors. In practice, it prevents users from choosing dictionary words, credential stuffing attempts, and other easily-guessed passwords at registration and password change time. It does not act as a firewall or malware scanner.

Who It's For

This plugin suits organizations that handle sensitive accounts and need stronger password controls than WordPress provides out of the box, such as healthcare portals, legal firms, membership communities, and educational platforms. It is also a reasonable fit for sites that want to enforce HIBP checks without configuring a full security suite. Smaller blogs and brochure sites with no user accounts will not get meaningful value from it.

Who Should Skip It

If you already run a full security suite like Wordfence, Really Simple Security, or Jetpack, which include password policy and breach-detection features, there is little reason to add this on top. Sites with no front-end user registration or no concerns about credential stuffing should skip it entirely.

The Bottom Line

Passwords Evolved does one thing, password hardening, and the concept is sound, but the 49.6/100 quality score reflects the realities of a 1,000-install plugin with only 2 ratings and no public support history. For most sites, a larger security suite like Wordfence or Really Simple Security delivers equivalent or better password protections with far more community vetting. Use this only if you specifically need HIBP-based password blocking and are comfortable with a small, single-purpose dependency.

Tags

authentication have-i-been-pwned password security