WPThumbs
Themes Plugins By purpose By industry Best-of lists Fix it guides
Free Plugin by Teydea Studio v3.8.0

Teydea Login Security

Define and enforce password policies for your WordPress site with length, complexity, and expiration rules.

Teydea Login Security

The facts

Rating
5★ from 1
Active installs
200+
Price
Free
Last updated
27 Aug 2026
Added
Apr 2024
Requires WP
6.6
Tested up to
WP 7.1
Requires PHP
7.4
Downloads
7,409

Our analysis

AI-assisted

Teydea Login Security is a WordPress plugin that allows you to define and enforce password policies for all users on your site. It provides settings for password length, complexity, expiration, and more, helping to maintain consistent security standards across user accounts. The plugin is suitable for personal blogs, membership sites, or multisite networks, ensuring compliance with various security protocols.

The plugin validates passwords during login, registration, and password changes, redirecting users to reset non-compliant passwords. It integrates with WordPress multisite networks and offers features such as restricting certain characters and requiring users to confirm their current password before making changes.

Best for: This plugin suits site administrators looking to enhance password security for their WordPress users.

What it does well

  • Enforces minimum and maximum password length
  • Supports password complexity rules
  • Allows password expiration settings
  • Compatible with WordPress multisite networks
  • Integrates with Site Health for configuration checks

Where it falls short

  • No information on premium features or pricing
  • Limited details on user experience or interface

Verdict

Teydea Login Security provides essential tools for enforcing password policies, making it a practical choice for those prioritising site security.

From the developer

Teydea Studio's own description of Teydea Login Security, lightly tidied.

Teydea Login Security lets you define and enforce password policies for all users on your WordPress site.

Set rules for password length, complexity (uppercase, lowercase, digits, special characters), restricted characters, password expiration, and more. The plugin validates passwords on login, registration, password changes, and during active sessions — automatically redirecting users to reset non-compliant passwords.

Key benefits:

  • Enforce password length and complexity rules from a single settings page.
  • Set password expiration to ensure users update their passwords regularly.
  • Require users to confirm their current password before making changes.
  • Compatible with WordPress multisite networks.

Whether you manage a personal blog, a membership site, or a multisite network, Teydea Login Security helps you maintain consistent password standards across all user accounts.

Learn more at teydeastudio.com/plugins/login-security.

Why password policies matter

Weak passwords remain one of the most common entry points for unauthorized access to WordPress sites. Teydea Login Security lets you enforce the password-policy controls that many security and compliance programs call for — minimum length, character composition, expiration, restricted characters, and more — across every user account. It helps you apply these controls, but does not by itself make your site compliant with any particular standard.

Features

Free Features

  • Minimum password length — Set and enforce the minimum number of characters for user passwords.
  • Maximum password length — Cap the number of characters a password may contain, keeping passwords within a length your site and any systems you integrate with accept.
  • Password complexity rules — Require a mix of uppercase letters, lowercase letters, digits, special characters, and a minimum number of unique characters.
  • Consecutive username symbols — Restrict how many consecutive characters from the user’s username or display name can appear in the password. Matching ignores letter case.
  • Restricted characters — Block specific characters from being used in passwords.
  • Restricted words and phrases — Maintain a site-wide list of words and phrases (one per line) that passwords cannot contain. Case-insensitive substring matching catches site-specific tokens such as your brand name, product names, your city, or a year token (for example: acme, summer, 2026).
  • Maximum password age — Force users to update their passwords periodically (e.g., every 30 days).
  • Minimum password age — Prevent users from changing their password too frequently, discouraging rapid cycling back to an old password.
  • Require current password — Add a “Current Password” field to the user profile screen and validate it before allowing password changes.
  • Custom password hints — Replace the default WordPress password hint with a policy-specific hint based on active rules.
  • Site Health integration — A Site Health test reports whether your plugin settings are properly configured.
  • Multisite/network support — Works with both standard and multisite WordPress installations.
  • AI integration — On WordPress 6.9+ with the MCP Adapter plugin, list, configure, and delete password policies through natural language commands from any connected AI provider.
  • Translation-ready — Localize the plugin into any language.

PRO Features

  • Prevent password reuse — Block users from reusing their previous passwords, encouraging new, unique passwords every time.
  • Custom password policies per role or user — Assign different password rules for administrators, editors, WooCommerce customers, or specific users.
  • Block common, weak passwords — Over 100,000 common passwords are blocked, preventing users from choosing easy-to-guess passwords.
  • Breached password screening (HaveIBeenPwned) — Screen passwords against the HaveIBeenPwned “Pwned Passwords” breach corpus using k-anonymity, so users cannot pick a password already exposed in a data breach. The full password never leaves your server.
  • Password expiry warning emails — Warn users by email on a schedule you configure before their password expires, so they can change it before being locked out.
  • Vendor-default account detection — Scan user accounts for risky patterns — default or predictable usernames, logins matching your domain, and unchanged display names — and review or dismiss each finding from a dedicated settings tab, a dashboard widget, and admin notices.
  • Integrations:
    • WooCommerce integration — Enforce password policies on WooCommerce login, registration, checkout account creation (including Store API), account details, password change, and password reset forms. Replaces WooCommerce’s built-in password strength meter with your policy rules.
    • Ultimate Member integration — Enforce password policies within Ultimate Member registration, login, password reset, and password change forms. Disables Ultimate Member’s built-in password strength option to avoid conflicts.
    • Tutor LMS integration — Enforce password policies on Tutor LMS student and instructor registration, login, password change, and password reset forms.
    • LifterLMS integration — Enforce password policies on LifterLMS registration (including checkout), account password change, and password reset forms. Replaces LifterLMS’s built-in password strength meter with your policy rules.
    • LearnPress integration — Enforce password policies on LearnPress registration, login, and password change forms.
    • Sensei LMS integration — Enforce password policies on Sensei LMS registration and login forms.
    • BuddyPress integration — Enforce password policies on BuddyPress registration, login, and password change forms.
    • bbPress integration — Enforce password policies on bbPress login and profile password change forms. Replaces bbPress’s built-in password strength meter with your policy rules.

    Learn more about the PRO version at teydeastudio.com/plugins/login-security/pricing.

    Video Tutorial

    See the plugin in action:

    Read the full description on the official page →

Tagged as

Alternatives

Other plugins for securing a site.

Really Simple Security

Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vuln...

Free 3M+ installs 4.9★ (8,862)
Wordfence Security

Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team....

Free 5M+ installs 4.7★ (4,983)
Akismet Anti-spam: Spam Protection

The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam sol...

Free 5M+ installs 4.7★ (1,186)
Loginizer

Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.

Free 1M+ installs 4.8★ (1,030)
Safe SVG

Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website.

Free 1M+ installs 4.9★ (79)
All-In-One Security

Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plu...

Free 1M+ installs 4.7★ (1,715)