Plugin Pulse
← Pulse

PHP Native Password Hash

by Ayesh Karunaratne · Uncategorized

Also makes 5 other plugins · 6.3K+ installs across the portfolio →

Makes WordPress use PHP's native password_hash() functions for portable, stronger, and time-attack safe bcrypt and Argon2 hashes.

⚠ Stale⚠ Likely abandoned⚠ Few reviews
How scoring works →
55 Health · C
Maintenance 21/100
Rating quality 82/100
Support 70/100

55 health vs 56 average across 16,376 Uncategorized plugins

Removal-risk signals

28/100

Maintenance and integrity signals that tend to precede a WordPress.org removal. Not an official status, a heads-up to act.

  • Not actively maintained. No update in about 2 years.

Directory ranking optimization

How it's scored →

How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.

64 / 100

Room to improve

Biggest win: Update recency

Update recency 30/100
WP compatibility 77/100
Rating quality 58/100
Listing tuning 100/100

To rank higher: Last updated 810 days ago — ship an update; wp.org decays a listing's search weight after ~180 days.

Get the full rank-higher report →

Daily downloads

Since 2022-10-05 · 1,425 days · wp.org + Plugin Pulse archive

+52% vs prior 30d
0Downloads · Aug 26

30-day downloads

Rolling 30-day volume · peaks are release surges

294

now · peak 1.4K

28430d downloads · Aug 26

Directory rank vs rivals

wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you

PHP Native Password · #5204 you Password bcrypt · #5214 Theme My Login · #687 PPWP · #976

Update activity

How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.

284per 1k installs · Aug 26

Release cadence

No release in a year
from wp.org release tags

How often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.

0

releases in the last 12 months

2.2y ago

latest release · v3.0

8

tagged releases on record

Recent releases

3.0 · 2.2y ago2.1 · 4.3y ago2.0 · 7.0y ago1.5 · 7.0y ago1.4 · 8.7y ago1.2 · 9.0y ago1.1 · 9.2y ago1.0 · 9.2y ago

What its installed base runs

via wordpress.org

Share of active installs on each version of this plugin · 82% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.

v3.0 82%
v2.1 17%
v1.5 0.8%

Estimated active installs

The public count shows “1K+”. Our estimate pins where the real number sits.

tracked estimate
1K–2K ≈1.4K

Refined from the date this plugin crossed into its current band.

Install history · since 2019-03-29 · 1,441 observations

1KInstalls · Aug 26

Estimated value

What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.

Est. annual revenue

N/A

Est. acquisition value

N/A

No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A small install base leaves thin data to model from.

Details

Version
3.0
Last updated
2.2y ago
Added
2017-01-04 · 9 yrs old
Requires WP
5.2
Tested up to
6.5.10
Requires PHP
7.0

Latest updates

via wp.org changelog

Recent releases and news for this plugin

  1. Version 1.0 Initial release. 1.0
  2. Version 1.1 Fixed a bug for PHP 5.5 users whose PHP core lacks the time-safe hash_equals function, resulting in a fatal error. This version introduces a polyfill to add that functionality for PHP 5.5 users. Users with newer PHP vers 1.1
  3. Version 1.2 This plugin now requires WordPress minimum version 3.9.2 the least, and uses the hash_equals() function polyfill provided by WordPress core. 1.2
  4. Version 1.4 Skipped 1.3 version because a WIP Argon2i support conflicted with the bug fix (#2). Argon2i support will be added in a future release. Fixes an error with password validation when the PasswordHash class from WordPress co 1.4
  5. Version 1.5 Fix a security issue with the password verification when updating from a password_hash()-compatible hashing algorithm to another. Thanks to Steve Thomas (Sc00bz on GitHub). 1.5
  6. Version 2.0 This is a major rewrite of the plugin. This version still requires PHP 5.5, but WordPress 5.2+ now requires PHP version 5.6 to function, and this is enforced at plugin level as well. Core functionality of the plugin is e 2.0

Behavioral tests

via WP Hive

Automated install-time checks, tested on PHP 8.1.12 · WP 6.2.2

Low memory footprint
Low page-speed impact
Runs on latest PHP + WP
No PHP errors
No JS errors
Activates cleanly
No resource errors
No external HTTP errors
Optimized database use
Frequently updated

Growth timeline

Install-tier crossings we have observed, and how long each tier took to outgrow

  1. 2026-08-01 2K+ → 1K+ down

Competes with

The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).

Compare head to head →

Embed this report card

Drop a live Pulse card for PHP Native Password Hash into a readme, a review or a deck. It updates itself.

<iframe src="https://plugins.wpmayor.com/embed/password-hash" width="480" height="300" style="border:0" loading="lazy" title="PHP Native Password Hash — Plugin Pulse"></iframe>
Preview card ↗

PHP Native Password Hash: 1K+ active installs, 5.0★ (6 reviews). Plugin Pulse (WP Mayor), as of 2026-08-29. https://plugins.wpmayor.com/plugin/password-hash