Expire User Passwords
Require certain users to change their passwords on a regular basis.
The facts
- Rating
- 4.2★ from 5
- Active installs
- 3k+
- Price
- Free
- Last updated
- 17 Feb 2026
- Added
- Dec 2019
- Requires WP
- 4.0
- Tested up to
- WP 6.9.7
- Requires PHP
- 8.1
- Downloads
- 60,881
Our analysis
AI-assistedExpire User Passwords is a WordPress plugin designed to enhance site security by enforcing regular password changes for users. It allows administrators to set a maximum duration for password validity, with a default of 90 days, and specify which user roles must comply with this requirement. This plugin is particularly useful for sites that need to adhere to strict security standards, such as those in government, banking, or healthcare sectors.
The plugin is a fork of the unsupported Expire Passwords plugin and is actively developed on GitHub. It supports multiple languages, making it accessible to a diverse user base. The plugin is suitable for site administrators looking to bolster security measures against unauthorized access from inactive user accounts.
Best for: This plugin is best for sites that require strict password management policies, particularly in sensitive industries.
What it does well
- ✓Enhances site security by enforcing password expiration
- ✓Customizable settings for password duration and user roles
- ✓Supports multiple languages
Where it falls short
- •Limited feature information available
- •No recent updates beyond February 2026
Verdict
Expire User Passwords is a straightforward solution for improving user account security. Its focus on compliance makes it a suitable choice for specific sectors, although the lack of detailed feature information may limit its appeal to some users.
From the developer
Matt Miller's own description of Expire User Passwords, lightly tidied.
Note: This is a forked version of the now unsupported Expire Passwords plugin. The notes below are copied over from the original plugin and will be updated as relevant updates become available. Please help by contributing to the GitHub repository Expire Passwords on GitHub
Did you find this plugin helpful? Please consider leaving a 5-star review.
Harden the security of your site by preventing unauthorized access to stale user accounts.
This plugin is also ideal for sites needing to meet certain industry security compliances – such as government, banking or healthcare.
In the plugin settings you can set the maximum number of days users are allowed to use the same password (90 days by default), as well as which user roles will be required to reset their passwords regularly (non-Administrators by default).
Languages supported:
- Albanian (Shqip)
- Arabic (العربية)
- Armenian (Հայերեն)
- Basque (Euskara)
- Bengali (বাংলা)
- Bulgarian (Български)
- Catalan (Català)
- Chinese Simplified (简体中文)
- Croatian (Hrvatski)
- Czech (Čeština)
- Danish (Dansk)
- Dutch (Nederlands)
- Estonian (Eesti)
- Finnish (Suomi)
- French (Français)
- Galician (Galego)
- Georgian (ქართული)
- German (Deutsch)
- Greek (Ελληνικά)
- Hebrew (עברית)
- Hindi (हिन्दी)
- Hungarian (Magyar)
- Indonesian (Bahasa Indonesia)
- Irish (Gaeilge)
- Italian (Italiano)
- Japanese (日本語)
- Korean (한국어)
- Latvian (Latviešu)
- Lithuanian (Lietuvių)
- Macedonian (Македонски)
- Norwegian (Norsk)
- Persian (فارسی)
- Persian – Afghanistan (دری)
- Polish (Polski)
- Portuguese – Brazil (Português do Brasil)
- Portuguese – Portugal (Português)
- Romanian (Română)
- Russian (Русский)
- Serbian (Српски)
- Slovak (Slovenčina)
- Slovenian (Slovenščina)
- Spanish (Español)
- Swedish (Svenska)
- Tamil (தமிழ்)
- Thai (ไทย)
- Turkish (Türkçe)
- Ukrainian (Українська)
- Urdu (اردو)
- Vietnamese (Tiếng Việt)
- Welsh (Cymraeg)
Development of this plugin is done on GitHub. Pull requests welcome. Please see issues reported there before going to the plugin forum.