WordPress user login

WordPress Password Generator

Create a strong login password using the same character groups defined by WordPress core. Generation happens locally and the result is never sent to this site.

Generate a WordPress login password

WordPress recommends 20 or more characters and generates 24-character suggestions in its account workflow. Standard symbols match the normal core function default.

Choose 8–128 characters. Keep 24 for the WordPress-recommended default.
Character sets
Standard adds !@#$%^&*(). Extra adds the advanced WordPress core punctuation set and may include a space.

24 characters72-character alphabet148.1 random bits
Generated locallyThe cleartext login password remains in this browser tab. Store it in a password manager before leaving.

How this matches WordPress core

WordPress's wp_generate_password() function starts with lowercase letters, uppercase letters, and digits. Its standard-symbol option adds !@#$%^&*(). The optional extra set adds additional punctuation and a space. This tool uses those documented alphabets with browser cryptography.

Why the default is 24 characters

The PHP function's historical default length is 12, but current WordPress password guidance recommends at least 20 characters and says its account workflow suggests 24-character passwords. This page therefore starts at 24 while keeping the length configurable.

Character groups are not guaranteed

Like the core function, each output character is selected independently from the enabled combined alphabet. Enabling symbols makes them available but does not force every category to occur. At 24 characters the probability of a useful mix is high; generate again if a particular external policy requires a category not present in the result.

Set the password safely

In wp-admin, open Users → Profile or edit the intended user and use the password controls. With WP-CLI, wp user update USERNAME --prompt=user_pass prompts for the value rather than placing it directly in shell history. Changing a user's password invalidates that user's existing login cookies.

Do not generate a database hash here

WordPress hashes a cleartext password when it is assigned through supported APIs or account tools. A copied database hash is not a reusable login password, and current hashing behavior can evolve. Avoid direct database edits unless recovering a site through an officially documented emergency workflow.

Login passwords versus Application Passwords

WordPress Application Passwords are revocable credentials created inside a user's profile for API clients and integrations. They are generated and registered by WordPress, shown only once, and should not be replaced by an arbitrary string from this page. Use this generator for the user's main interactive login.

Official WordPress sources

The alphabets follow the current wp_generate_password() source. Length and composition guidance follows WordPress password best practices. Safe command-line assignment follows the official WordPress login recovery guidance.

Related WordPress tools

WordPress salt generator creates the eight authentication constants for wp-config.php. Password strength checker analyzes a candidate locally. Passphrase generator creates longer word-based credentials. Use this page for a WordPress user's login password.