Require certain users to change their passwords on a regular basis.
As of April 2026, Expire Passwords is a WordPress admin plugin with 500 active installations and a 4.9/5 rating from 9 reviews. It has been downloaded 26K+ times in total. Requires WordPress 4.0+ and PHP false+. Available on WordPress.org since 2015. Last updated 9 years ago — may have compatibility concerns. Top alternative: Loginizer.
Did you find this plugin helpful? Please consider leaving a 5-star review.
Harden the security of your site by preventing unauthorized access to stale user accounts.
This plugin is also ideal for sites needing to meet certain industry security compliances – such as government, banking or healthcare.
In the plugin settings you can set the maximum number of days users are allowed to use the same password (90 days by default), as well as which user roles will be required to reset their passwords regularly (non-Administrators by default).
Languages supported:
Development of this plugin is done on GitHub. Pull requests welcome. Please see issues reported there before going to the plugin forum.
| WordPress | 4.0+ requiredTested up to 4.7.33 |
| PHP | false+ required |
Props @fjarrett
Plugin data sourced from WordPress.org. Analysis and metrics by PluginSift.