Title: wp-bcrypt
Author: harrym
Published: <strong>iýun 5, 2014</strong>
Last modified: iýun 5, 2014

---

Search plugins

This plugin **hasn’t been tested with the latest 3 major releases of WordPress**.
It may no longer be maintained or supported and may have compatibility issues when
used with more recent versions of WordPress.

![](https://s.w.org/plugins/geopattern-icon/wp-bcrypt.svg)

# wp-bcrypt

 By [harrym](https://profiles.wordpress.org/harrym/)

[Download](https://downloads.wordpress.org/plugin/wp-bcrypt.1.0.1.zip)

 * [Details](https://tuk.wordpress.org/plugins/wp-bcrypt/#description)
 * [Reviews](https://tuk.wordpress.org/plugins/wp-bcrypt/#reviews)
 *  [Installation](https://tuk.wordpress.org/plugins/wp-bcrypt/#installation)
 * [Development](https://tuk.wordpress.org/plugins/wp-bcrypt/#developers)

 [Support](https://wordpress.org/support/plugin/wp-bcrypt/)

## Description

WordPress uses phpass to store passwords. Because WordPress has to work everywere,
it uses the portable version of phpass,
 which uses MD5 to hash passwords. MD5 is
not a very good hashing algorithm for passwords, because it’s relatively fast.

This plugin switches over to bcrypt, which is the algorithm recommended by phpass,
and is a much better option for password
 storage because it is much slower to produce.
This makes it much harder for an attacker who’s managed to access your hashed passwords
to obtain plain text passwords by brute-forcing, or by trying passwords from a dictionary.

**Note: this plugin requires PHP 5.3.0 or newer**

Be aware that if you use this plugin and then move to a host that does not support
bcrypt, you will need to reset any user
 account that you want to log in with.

## Installation

 1. Upload the `wp-bcrypt` directory to the `wp-content/plugins/` directory
 2. Activate the plugin through the ‘Plugins’ menu in WordPress

## FAQ

  How do you change the hashes?

Users’ hashes are changed to bcrypt when they first login in after the plugin is
activated. All of WordPress’s built-in functions
 will use bcrypt too, when intially
creating an account, changing your password, or adding a password to a post.

  What happens if I deactivate the plugin?

As long as you have bcrypt support (PHP 5.3.0 or newer) WordPress will happily continue
checking passwords that are hashed using
 bcrypt. Everything should work fine. But
any new passwords you hash (for a new account, or changing an existing account) 
will be made using MD5.

## Reviews

![](https://secure.gravatar.com/avatar/1a0fd27bc4b3c3ee44286d05e3abc7a721b051cca8f1a4d43571e67ab1622319?
s=60&d=retro&r=g)

### 󠀁[Is it work with wordpress 4.9?](https://wordpress.org/support/topic/is-it-work-with-wordpress-4-9/)󠁿

 [momosampaii](https://profiles.wordpress.org/momosampaii/) dekabr 2, 2017

Is it work with wordpress 4.9? Thanks

 [ Read all 4 reviews ](https://wordpress.org/support/plugin/wp-bcrypt/reviews/)

## Contributors & Developers

“wp-bcrypt” is open source software. The following people have contributed to this
plugin.

Contributors

 *   [ harrym ](https://profiles.wordpress.org/harrym/)

[Translate “wp-bcrypt” into your language.](https://translate.wordpress.org/projects/wp-plugins/wp-bcrypt)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/wp-bcrypt/), check 
out the [SVN repository](https://plugins.svn.wordpress.org/wp-bcrypt/), or subscribe
to the [development log](https://plugins.trac.wordpress.org/log/wp-bcrypt/) by [RSS](https://plugins.trac.wordpress.org/log/wp-bcrypt/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.0.1

 * Readme improvements

#### 1.0.0

 * Initial release

## Meta

 *  Version **1.0.1**
 *  Last updated **12 years ago**
 *  Active installations **300+**
 *  WordPress version ** 3.4 or higher **
 *  Tested up to **3.9.40**
 *  Language
 * [English (US)](https://wordpress.org/plugins/wp-bcrypt/)
 * Tags
 * [passwords](https://tuk.wordpress.org/plugins/tags/passwords/)[security](https://tuk.wordpress.org/plugins/tags/security/)
 *  [Advanced View](https://tuk.wordpress.org/plugins/wp-bcrypt/advanced/)

## Ratings

 5 out of 5 stars.

 *  [  4 5-star reviews     ](https://wordpress.org/support/plugin/wp-bcrypt/reviews/?filter=5)
 *  [  0 4-star reviews     ](https://wordpress.org/support/plugin/wp-bcrypt/reviews/?filter=4)
 *  [  0 3-star reviews     ](https://wordpress.org/support/plugin/wp-bcrypt/reviews/?filter=3)
 *  [  0 2-star reviews     ](https://wordpress.org/support/plugin/wp-bcrypt/reviews/?filter=2)
 *  [  0 1-star reviews     ](https://wordpress.org/support/plugin/wp-bcrypt/reviews/?filter=1)

[Add my review](https://wordpress.org/support/plugin/wp-bcrypt/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/wp-bcrypt/reviews/)

## Contributors

 *   [ harrym ](https://profiles.wordpress.org/harrym/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/wp-bcrypt/)