WordPress plugin

Force password reset in WordPress

Force password reset in WordPress for one user, a whole role or everyone but admins, and expire passwords on a schedule.

WordPress 5.8+ · Multisite ready

Force password reset in WordPress: users list with reset status
Total users, reset required and no reset required counts
Policy

A WordPress password policy that runs itself

Minimum strength, first-login-only mode, a custom notice and where users land afterwards.

  • Weak
  • Medium
  • Strong
  • First login only
WordPress password policy settings with minimum strength
No way around it

A flagged user cannot skip the reset

Every other way in is closed until the new password is set.

REST API

Requests get a 403 until the password is changed.

App passwords

Application passwords are rejected wherever they are used.

XML-RPC

XML-RPC logins fail for flagged users.

admin-ajax

Ajax requests receive a 403 instead of passing through.

Password expiry

WordPress password expiry, done safely

Maximum age

Set the days a password lasts. 0 turns expiry off.

Per-role policy

Every non-administrator, or only the roles you pick.

Warning email

A heads-up N days before a password expires.

Daily sweep

Batched, so large user lists never time out.

Admins never expire

A nightly job can never lock out the only admin.

Multisite

Network compatible, and can be network activated.

Pricing

Force password reset in WordPress, free

Free
$0
  • Force reset per user, in bulk or for everyone
  • Password expiry with warning emails
  • Minimum password strength
  • Email notifications with merge tags
  • Multisite compatible
Get it free
FAQ

Forcing password resets

Is there a free version?

Yes. Everything on this page is in the free plugin.

Can I force a reset for all users at once?

Yes. One action forces a reset for every non-administrator, and another clears it.

Are administrators affected?

Admins cannot be forced to reset by other admins, and are never expired by the scheduled sweep, so nobody gets locked out.

How do I turn on password expiry?

Go to Settings → Password Reset → Password Expiry Policy and set Password Maximum Age in days.

Can a flagged user get round it with the REST API or an application password?

No. REST and admin-ajax requests get a 403, application passwords are rejected, and XML-RPC logins fail.

Does it work on multisite?

Yes. It is network compatible and can be network activated.

Will existing users be locked out when I turn on expiry?

No. Existing users get the full maximum age from the moment expiry starts, and the warning email still reaches them first.

Make every password current