
WP Expire Passwords Security & Risk Analysis
wordpress.org/plugins/wp-expire-passwordsThis plugin allows you to set passwords to expire every X amount of days (default is 90) and to expire all non-admin user passwords (requiring new uni …
Is WP Expire Passwords Safe to Use in 2026?
Generally Safe
Score 85/100WP Expire Passwords has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-expire-passwords plugin version 1.1.1 exhibits a concerning security posture despite having a minimal attack surface and no recorded vulnerabilities. The static analysis reveals a significant weakness: one AJAX handler lacks any authentication checks. This unprotected entry point is a prime target for attackers, as it could potentially be exploited to perform unauthorized actions. Furthermore, the analysis indicates a complete absence of output escaping for all identified outputs, meaning sensitive data or malicious code could be injected and rendered directly in the user's browser. While the plugin avoids dangerous functions, raw SQL, and external requests, these positive aspects are heavily overshadowed by the critical lack of security measures for its exposed AJAX endpoint and output handling.
Key Concerns
- Unprotected AJAX handler
- No output escaping
- No nonce checks
- No capability checks
WP Expire Passwords Security Vulnerabilities
WP Expire Passwords Code Analysis
Output Escaping
WP Expire Passwords Attack Surface
AJAX Handlers 1
WordPress Hooks 7
Maintenance & Trust
WP Expire Passwords Maintenance & Trust
Maintenance Signals
Community Trust
WP Expire Passwords Alternatives
Password Strength Settings for WooCommerce
wc-password-strength-settings
Help secure your WooCommerce site by enforcing stronger passwords and taking additional control of your strength requirements.
Expire Users
expire-users
Set expiry dates for user logins.
Expire User Passwords
expire-user-passwords
Require certain users to change their passwords on a regular basis.
Reset Password Removed
reset-password-removed
Enhance the security of your blogs by preventing password reset over email function.
Admin Notify
admin-notify
Short Description: Admin Notify sends email notifications when administrator accounts are added, updated, or deleted.
WP Expire Passwords Developer Profile
1 plugin · 10 total installs
How We Detect WP Expire Passwords
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-expire-passwords/js/ep-ajax.jsjs/ep-ajax.jsHTML / DOM Fingerprints
wrapbutton-primaryname="days_until_expired"id="expire_passwords_form"name="pass1"window.jQuery