PHP Native Password Hash
by Ayesh Karunaratne 5 (6 reviews)

PHP Native Password Hash

Makes WordPress use PHP's native password_hash() functions for portable, stronger, and time-attack safe bcrypt and Argon2 hashes.

PHP Native Password Hash ranks #5,200 among WordPress.org plugins with 1,000+ active installations, is #372 of 4,499 in the Security category, a 5/5 rating from 6 reviews, and was last updated Jun 10, 2024. Data from WordPress.org, refreshed twice daily — see methodology.

Tested up to WP 6.5.10 (Current: 7.1)
v3.0 Current Version v3.0
Updated 2 years ago Last Update on 10 Jun, 2024
Refreshed 7 hours ago Last Refreshed on
#372 of 4,499 in Security Top 10% by installs No update in over a year
View on WordPress.org
Rank
#5,200
No change
Active Installs
1K+
-49.5%
KW Avg Position
3.5
No change
Downloads
24.7K
+15 today
Support Resolved
0%
No change
Rating
100%
Review 5 out of 5
5 (6 reviews)

Next Milestone 2K

Total Progress 96.5%
1K+ 2K+
67
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 35 more installs to reach 2K+

Rank Changes

5,183 5,189 5,194 5,200 5,205 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
5,182 5,188 5,194 5,200 5,206 01-09-2026 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
Current #5,200
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 10 20 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
0 10 20 01-09-2026 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

5.0
6 reviews
Overall 100%
5
6 (100%)
4
0 (0%)
3
0 (0%)
2
0 (0%)
1
0 (0%)

Security History

Source: WPVulnerability

No known vulnerabilities on record for PHP Native Password Hash. Checked 1 month ago.

TL;DR

AI summary of the plugin's readme

This plugin is for WordPress site administrators and developers who need password hashes compatible with external or custom applications. It replaces WordPress's built-in password hashing with PHP's native password_hash() functions, using bcrypt or Argon2 for stronger, portable, and time-attack safe password storage.

  • Uses PHP's password_hash() functions
  • Supports bcrypt hashing algorithm
  • Supports Argon2 hashing algorithm
  • CSPRNG-generated password salts
  • Resistance against dictionary and rainbow table attacks
  • Iterated hashing for brute-force resistance
  • Mitigates time-attacks on password checks
  • Automatic transparent password rehashing

Frequently Asked Questions

Common questions about PHP Native Password Hash

Nope! This plugin is smart enough to identify an old password hash, capable to seamlessly validate it using the old algorithm, and update the hash with the new version automatically. Your users wouldn't notice a thing.
Password hashing is a one-way operation, and it's near impossible to extract the original password from the hash. This means we cannot undo the effect of this plugin. Your existing users will need to reset their passwords. However, your password hashes will remain safe. This plugin is does one specific thing and does it well. There should be no significant impact on using this plugin.
The easiest way would be to check your database from PHPMyAdmin or any other software in its line. Check if the password hash field in your users table has the format $2y$10.... Those who have not updated their hashes will have a different format. However, if the plugin is unable to override the password hashing algorithm from WordPress core, you will see a notification in your dashboard. If you do not see anything, you are golden.
To keep the plugin size minimal, this plugin does not offer a UI configuration page. You can set the password hashing algorithm with a configuration value set in wp-config.php file. Open your wp-config.php file at the root of your WordPress site, and find the line that says That's all, stop editing! Happy publishing. Above this line, you can configure the hashing algorithm you want this plugin to use. Note that a wrong configuration value means your users will not be able to log in until you fix this configuration option. It's not recommended that you set this configuration value unless you know what you are doing. define( 'WP_PASSWORD_HASH_ALGO', PASSWORD_ARGON2ID ); You can use the following values depending on your PHP version: - PHP 7.2 or later: PASSWORD_ARGON2I - PHP 7.3 or later: PASSWORD_ARGON2ID (recommended)
Alrighty folks, read carefully: This plugin can listen to a configuration option you specify and pass it along to the hashing process. Please make sure you are absolutely sure about the values you set here. If you set a value too easy to crack, you will open up a security vulnerability in your site. If you set a value too high, your server will take too much resources. This plugin does not make any effort to validate the configuration you set. If you do not configure a value, plugin will use the default value your PHP version comes with. If you would still like to configure these options, similar to the way you set the hashing algorithm, open the wp-config.php file for your WordPress site (at root of your WordPress installation), and right below the line that you configure hashing algorithm (see FAQ above), set your configuration values as well. Here is an example (not necessarily a recommendation): define( 'WP_PASSWORD_HASH_OPTIONS', ['memory_cost' => 2<<16, 'time_cost' => \PASSWORD_ARGON2_DEFAULT_TIME_COST, 'threads' => \PASSWORD_ARGON2_DEFAULT_THREADS]] ); The values you set here will be different based on the algorithm you set. You must set the WP_PASSWORD_HASH_ALGO configuration in order for this to be effective. See https://www.php.net/manual/en/password.constants.php for more examples and information. Existing password hashes will be updated the next time the user logs in. Existing hashes will be checked using the existing algorithm regardless of this configuration.
Pier to pier networking.

More plugins by Ayesh Karunaratne

Sign In / Register

You need to sign in or register to use this feature.