Replaces wp_hash_password and wp_check_password with PHP 5.5's password_hash and password_verify.
As of April 2026, Password bcrypt is a WordPress hash plugin with 2.0K+ active installations and a 5/5 rating from 3 reviews. It has been downloaded 30K+ times in total. Requires WordPress 4.4+ and PHP false+. Available on WordPress.org since 2016. Last updated 9 years ago — may have compatibility concerns. Downloads are down 8% this week. Top alternative: Twitter Hash Tag Widget.
wp-password-bcrypt is a WordPress plugin to replace WP’s outdated and insecure
MD5-based password hashing with the modern and secure bcrypt.
It is written by roots.io people.
This plugin requires PHP >= 5.5.0 which introduced the built-in
password_hash and
password_verify functions.
See Improving WordPress Password Security
for more background on this plugin and the password hashing issue.
Awesome!
Simple solution of an important issue
Every WordPress installation needs password hashing with bcrypt. Thanks 🙂
| WordPress | 4.4+ requiredTested up to 4.5.33 |
| PHP | false+ required |
Plugin data sourced from WordPress.org. Analysis and metrics by PluginSift.