How this matches WordPress core
WordPress's wp_generate_password() function starts with lowercase letters, uppercase letters, and digits. Its standard-symbol option adds !@#$%^&*(). The optional extra set adds additional punctuation and a space. This tool uses those documented alphabets with browser cryptography.
Why the default is 24 characters
The PHP function's historical default length is 12, but current WordPress password guidance recommends at least 20 characters and says its account workflow suggests 24-character passwords. This page therefore starts at 24 while keeping the length configurable.
Character groups are not guaranteed
Like the core function, each output character is selected independently from the enabled combined alphabet. Enabling symbols makes them available but does not force every category to occur. At 24 characters the probability of a useful mix is high; generate again if a particular external policy requires a category not present in the result.
Set the password safely
In wp-admin, open Users → Profile or edit the intended user and use the password controls. With WP-CLI, wp user update USERNAME --prompt=user_pass prompts for the value rather than placing it directly in shell history. Changing a user's password invalidates that user's existing login cookies.
Do not generate a database hash here
WordPress hashes a cleartext password when it is assigned through supported APIs or account tools. A copied database hash is not a reusable login password, and current hashing behavior can evolve. Avoid direct database edits unless recovering a site through an officially documented emergency workflow.
Login passwords versus Application Passwords
WordPress Application Passwords are revocable credentials created inside a user's profile for API clients and integrations. They are generated and registered by WordPress, shown only once, and should not be replaced by an arbitrary string from this page. Use this generator for the user's main interactive login.
Official WordPress sources
The alphabets follow the current wp_generate_password() source. Length and composition guidance follows WordPress password best practices. Safe command-line assignment follows the official WordPress login recovery guidance.
Related WordPress tools
WordPress salt generator creates the eight authentication constants for wp-config.php. Password strength checker analyzes a candidate locally. Passphrase generator creates longer word-based credentials. Use this page for a WordPress user's login password.