Skip to content
  • About WordPress
    • About WordPress
    • WordPress.org
    • Documentation
    • Support
    • Feedback
  • Log In
  • Register
WordPress.org
WordPress.org

بلوچی

  • Themes
  • Plugins
  • News
  • Support
  • About
  • Contact
  • Get WordPress
Get WordPress

Plugins

  • My Favorites
  • Beta Testing
  • Developers

This plugin hasn’t been tested with the latest 3 major releases of WordPress. It may no longer be maintained or supported and may have compatibility issues when used with more recent versions of WordPress.

Download

Signup Breach Checker

By Dan Dulaney
  • Details
  • Reviews
  • Installation
  • Support
  • Development

Description

**Note: This plugin sends e-mail address (and optionally SHA1 hashed passwords) to an external API, at https://haveibeenpwned.com **

This plugin is meant to provide a service to your site members by doing the following:

  • On user registration, check the haveibeenpwned API to see if their e-mail has been in any known breaches
  • Stores (in user_meta) any breaches found, and if the user has been notified (by your site)
  • If welcome e-mails are enabled, adds a section sharing information about the breaches, and the suggestion to use a strong password with a link to help. If not, it also lets them know they are clean.
  • Optional (Disabled by default): Enable password checking against the API’s list of known passwords on password reset / new user password set. This only triggers if the user also has had their e-mail leaked in a known breach, and e-mails the user with additional information.

Planned for future updates:

  • (Toggleable) Method of checking existing users and notifying them.
  • (Toggleable) Method to periodically check all users that haven’t had a breach, and notify them if that changes.
  • (Toggleable) Method to add admin notifications of new breaches discovered by HaveIBeenPwned.com

Dependencies and Liscencing

This plugin relies on the the HaveIBeenPwned APIv2, and has been designed to comply with rate limiting and usage policy.

Screenshots

  • Sample modified Welcome E-mail (if registrating person's e-mail was found in a breach).
  • Sample e-mail if Password Checking is enabled and the password is found on a pw dump list.
  • Signup Breach Checker settings page / control panel.

Installation

  1. Upload the plugin files to the /wp-content/plugins/signup-breach-checker directory, or install the plugin through the WordPress plugins screen directly.
  2. Activate the plugin through the ‘Plugins’ screen in WordPress
  3. Head over to the Signup Breach Checker settings page, found on the Dashboard sidebar on the Tools submenu.

FAQ

What do I need for this plugin to run?

You must have at LEAST WordPress 4.9.0 or higher, as it uses the wp_new_user_notification_email filter.

Is checking passwords secure?

Passwords are first hashed on-site using sha1, and then sent over https. This is as secure as using the haveibeenpwned password service yourself. This is turned OFF by default, but may be turned on on the settings page.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“Signup Breach Checker” is open source software. The following people have contributed to this plugin.

Contributors
  • Dan Dulaney

“Signup Breach Checker” has been translated into 1 locale. Thank you to the translators for their contributions.

Translate “Signup Breach Checker” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

1.1

  • Check with latest version of WP

1.0

  • Initial Plugin Release

Meta

  • Version: 1.1
  • Last updated: 3 years ago
  • Active installations: 10+
  • WordPress Version: 4.9.0 or higher
  • Tested up to: 5.2.15
  • Languages:

    English (US) and German.

    Translate into your language

  • Tags:
    HaveIBeenPwnednotificationuser signup
  • Advanced View

Ratings

This plugin has not been rated yet.

Log in to submit a review.

Contributors

  • Dan Dulaney

Support

Got something to say? Need help?

View support forum

Donate

Would you like to support the advancement of this plugin?

Donate to this plugin

  • About
  • News
  • Hosting
  • Donate
  • Support
  • Developers
  • Get Involved
  • Learn
  • Showcase
  • Plugins
  • Themes
  • Patterns
  • WordCamp
  • WordPress.TV
  • BuddyPress
  • bbPress
  • WordPress.com
  • Matt
  • Privacy
  • Public Code
WordPress.org
WordPress.org

بلوچی

  • Visit our Facebook page
  • Visit our Twitter account
Code is Poetry.