이 플러그인은 최근 3개의 주요 워드프레스 출시와 시험 되지 않았습니다. 워드프레스의 좀 더 최근 버전으로 이용할 때 더 이상 관리되지 않고 지원되지 않고 호환성 문제가 있을 수 있습니다.

Disallow Pwned Password

설명

Disallow WordPress and WooCommerce users using pwned passwords.

Goal

Spoiler Alert: User passwords never leave your server, not even in hashed form.

Although reusing passwords is solely users’ fault but when evil attackers brute forced users’ passwords, and stole all their personal information or spent users’ hard earn money through your site. Those lazy users blame you, the site owner/developer.

When processing requests to establish and change memorized secrets, verifiers SHALL compare the prospective secrets against a list that contains values known to be commonly-used, expected, or compromised. For example,…

  • Passwords obtained from previous breach corpuses

NIST Digital Identity Guidelines

This plugin’s solely purpose is to disallow WordPress and WooCommerce users reusing passwords listed in Have I Been Pwned database.

Usage

Activate and forget.

This plugin intercepts when:

  • creating new users on /wp-admin/user-new.php
  • changing other users’ passwords on /wp-admin/user-edit.php
  • changing your password on /wp-admin/profile.php
  • new user registration on /wp-login.php?action=rp

Additional interceptions if WooCommerce is installed:

Explain It Like I’m Five

  • Troy Hunt, a well-kown security expert, collected 6,493,641,194 (and counting) pwned passwords from previous security breaches
  • Pwned passwords stored as SHA-1 hashes on haveibeenpwned.com
  • Whenever WordPress / WooCommerce users attempt to change their passwords, this plugin hashes the user password
  • Take the first 5 characters from the hash
  • Ask haveibeenpwned.com for all pwned passwords with the same first 5 hash characters
  • Check how many times the user password appears on the have I been pwned database
  • Disallow the password change if it has been pwned

Users aged older than five could learn more from:

For Developers

Fork the plugin on GitHub.

스크린샷

FAQ

What are the minimum requirements?
  • PHP v7.0
  • WordPress v4.9.8
  • (Optional) WooCommerce v3.4.4
Did you just send all the passwords to someone else?

No. User passwords never leave your server, not even in hashed form.

How do you compare user passwords with the 6,493,641,194 pwned ones?

Curious users can learn more from:

Paranoia users should check the plugin implementation.

What to do if I don’t trust haveibeenpwned.com?

Troy Hunt is a well-kown security expert. You should trust him more than me (the plugin author). Anyways, you can replace the default API client with yours:

<?php

use Itineris\DisallowPwnedPasswords\HaveIBeenPwned\ClientInterface;
use League\Container\Container;

class YourCustomClient implements ClientInterface
{
    // Your implementation.
}

add_action('i_dpp_register', function (Container $container): void {
    $container->add(ClientInterface::class, YourCustomClient::class);
});

This plugin uses league/container. Learn more from its documents.

What to do if I don’t trust the plugin author?

Good question! You shouldn’t blindly trust any random security guide/plugin from the scary internet – including this one!

Review the plugin implementation.

I have installed this plugin. Does it mean my WordPress site is *unhackable*?

No website is unhackable.

To have a secure WordPress site, you have to keep all these up-to-date:

  • WordPress core
  • PHP
  • this plugin
  • all other WordPress themes and plugins
  • everything on the server
  • other security practices
  • your mindset

Strongly recommended:

  • WP Password Argon Two – Securely store WordPress user passwords in database with Argon2i hashing and SHA-512 HMAC using PHP’s native functions
  • WP Cloudflare Guard – Connecting WordPress with Cloudflare firewall, protect your WordPress site at DNS level. Automatically create firewall rules to block dangerous IPs
  • Two-Factor
  • wp-password-bcrypt
Can strong passwords been pwned?

Yes. Example:

How to disable WooCommerce password strength meter?

For testing only, use at your own risk!

add_action('wp_print_scripts', function () {
    wp_dequeue_script('wc-password-strength-meter');
}, 10000);
Will you add support for older PHP versions?

Never! This plugin will only works on actively supported PHP versions.

Don’t use it on end of life or security fixes only PHP versions.

Note: Current version supports PHP 7.0 because wordpress.org svn pre-commit hook rejects PHP 7.1+ syntax. However, you should not use PHP 7.0 because it has reached end of life since 10 January 2019.

It looks awesome. Where can I find some more goodies like this?
Besides wp.org, where can I give a ★★★★★ review?

Thanks! Glad you like it. It’s important to let my boss knows somebody is using this project. Please consider:

Where to report security related issues?

If you discover any security related issues, please email hello@itineris.co.uk instead of using the issue tracker.

후기

모든 2 평가 읽기

기여자 & 개발자

“Disallow Pwned Password”(은)는 오픈 소스 소프트웨어입니다. 다음의 사람들이 이 플러그인에 기여하였습니다.

기여자

“Disallow Pwned Password”(이)가 1 개 언어로 번역되었습니다. 기여해 주셔서 번역자님께 감사드립니다.

자국어로 “Disallow Pwned Password”(을)를 번역하세요.

개발에 관심이 있으십니까?

코드 탐색하기는, SVN 저장소를 확인하시거나, 개발 기록RSS로 구독하세요.

변경이력

Please see CHANGELOG for more information on what has changed recently.