Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →WordPress already includes a secure password generator: wp_generate_password(). For a tool that only creates and displays a password, you can wrap this function in a small plugin or theme feature. Changing a user’s stored password is a separate operation that requires an authorized, nonce-protected workflow.
Choose what your generator should do
First decide whether the feature should merely produce a candidate password or also save that password to a WordPress account.
| Feature | What it does | Security requirements | Best existing option |
|---|---|---|---|
| Generate and display | Creates a value for the visitor or administrator to copy. | Use wp_generate_password() and escape the value when rendering it. |
A small shortcode, block, admin tool, or custom plugin. |
| Generate and change | Creates a value and stores it as a user’s account password. | All of the display requirements, plus capability checks, nonce verification, validation, and a controlled password-update workflow. | The built-in profile/edit screens, registration flow, or a carefully authorized custom feature. |
WordPress user profiles already provide password management, and core registration uses wp_generate_password() to create a random password. If those screens meet your requirement, adding another password-changing form increases risk without adding much value.
How WordPress generates the password
wp_generate_password() accepts three arguments:
$length: the requested length; the documented default is 12.$special_chars: whether to include the standard special-character set; the default istrue.$extra_special_chars: whether to include additional special characters; the default isfalse.
The documented character groups are letters and digits, standard symbols !@#$%^&*(), and extra symbols -_ []{}<>~`+=,.;:/?|. WordPress uses wp_rand() and applies the random_password filter to the result. See the complete reference at WordPress Developer Resources.
#1 Best Overall
- Stylish and Secure: Our password book features a premium blue leatherette hardcover, adding a touch of elegance while keeping your passwords safe from prying eyes.
- Effortless Organization: With its outstanding and thoughtful layout, our password keeper book provides alphabetical tabs, making it easy to find specific passwords quickly. No more fumbling through scattered notes or forgetting important login information!
- Comprehensive Record-Keeping: Designed to cater to all your digital needs, our password notebook allows you to store up to 576 passwords, along with 48 records of licenses, and essential network, email, and wireless settings. It comes with extra lined pages for taking notes, using them for keeping track of security questions, hints, or any other relevant details. Stay organized and never miss an important detail again!
- Peace of Mind: Your online security is our top priority. The lock included with our password book provides an extra layer of protection, ensuring that only you have access to your confidential information. Store your passwords with confidence and take control of your digital life!
- Durable and Portable: Sized at 7.5in x 5.5in, our small password book is compact yet spacious enough to hold all your vital information, making it convenient to carry with you wherever you go.
There is no universally correct length or symbol policy. Longer values generally create a larger search space, while unusual symbols can cause compatibility problems in systems that impose password rules. Select a policy that matches the accounts or service receiving the value.
Add a display-only generator with a shortcode
The following plugin adds a [simple_password_generator] shortcode. It generates a fresh 16-character value when the shortcode is rendered, includes standard special characters, leaves extra symbols disabled, and escapes the result before placing it in the page.
Rank #2
- Organized Password Management: Juvale's password book with alphabetical tabs offers a streamlined way to manage login credentials. This internet password book is designed to fit seamlessly into your lifestyle, enhancing both efficiency and security
- Versatile Note-Taking: Each password keeper book includes extra lined pages for additional notes, perfect for professionals and students. The compact design ensures portability, while the alphabetical notebook layout keeps information neatly organized
- Durable Construction: Crafted with a sturdy plastic cover and high-quality paper, this address book resists wear and tear over time. The spiral binding allows the password logbook to lie flat for easy writing, offering a reliable tool for everyday use
- Compact and Portable: Sized at 6 x 7 inches, this mini address book fits effortlessly into bags and briefcases. Its solid color design appeals to those seeking a stylish yet practical personal organizer for efficient password management
- Convenient Backup Set: This set includes two spiral-bound address books, ensuring an additional copy for safeguarding vital information. The inclusion of the address book and password book combo enhances accessibility and productivity
- Create a file named
simple-password-generator.phpin a new folder underwp-content/plugins/, such aswp-content/plugins/simple-password-generator/. - Paste the code below into that file.
- In WordPress, open Plugins → Installed Plugins and activate Simple Password Generator.
- Add
[simple_password_generator]to a page or post.
<?php
/**
* Plugin Name: Simple Password Generator
* Description: Displays a password generated by WordPress core.
* Version: 1.0.0
*/
if ( ! defined( 'ABSPATH' ) ) {
exit;
}
function itg_simple_password_generator_shortcode() {
$password = wp_generate_password( 16, true, false );
return '<label>Generated password</label> '
. '<input type="text" readonly value="'
. esc_attr( $password )
. '" />';
}
add_shortcode( 'simple_password_generator', 'itg_simple_password_generator_shortcode' );
The readonly field lets a visitor select and copy the value but does not save it to a user account. For a more polished interface, add a button with JavaScript that requests a new value from an endpoint; keep generation on the server and apply the same output-escaping rule.
Let an administrator choose length safely
If you expose a length field in an admin screen, treat it as untrusted input. Validate it as an integer, enforce a sensible minimum and maximum for your feature, and reject invalid values rather than silently accepting them. The WordPress security handbook’s rule is: “Always make sure to validate and sanitize user input before using it, and to escape on output.” Read the guidance at Security – Common APIs Handbook.
For example, after receiving a submitted length, convert it to an integer, verify that it falls inside the range your interface documents, and only then pass it to wp_generate_password(). Escape the generated value with the context-appropriate function: esc_html() for text content, esc_attr() for an HTML attribute, or another WordPress escaping function suited to the output context.
If the tool must change a user password
Generation and credential modification should be separate steps in your design. A form that changes an account password must identify which user may be changed, require an authenticated request, and perform the update only after authorization succeeds.
Protect the request against CSRF
For a normal form, add a WordPress nonce and verify it when processing the submission. For AJAX, send and verify a nonce in the request. WordPress documents nonces as protection against cross-site request forgery, not as authentication or authorization. Follow the details in Nonces – Common APIs Handbook.
Check capabilities separately
After nonce verification, check the current user’s capability with current_user_can() before changing any account credential. A valid nonce does not grant permission. Restrict the operation to the precise capability and user scope your feature requires.
Best Value
- Time- and headache-saving little volume is organized with tabbed A to Z pages, with space on each page to write down websites, usernames, passwords, and notes.
Use WordPress’s user APIs
Do not write a password directly into the database or invent a hashing routine. Use WordPress’s supported user-management APIs and follow the behavior documented for edit_user() and the broader Working with Users guide. Test the complete success and failure paths, including what the administrator sees after the password is changed and how the new value is delivered securely.
When the built-in tools are enough
User profile and edit screens
For an administrator changing an existing account, the dashboard’s user profile/edit screens already include password management. This avoids maintaining a second credential workflow.
Registration
Core registration creates a random password through wp_generate_password(). If your requirement is simply to give new users generated credentials, extend or configure the registration experience instead of duplicating the generator.
WP-CLI
For command-line administration, wp user create supports user creation and its password option defaults to a random password. Use it only from a secured shell or deployment process, and handle any displayed credential as sensitive data.
Do not confuse this with Application Passwords
Application Passwords are revocable, per-application credentials for programmatic access. They are intended to let an integration connect without sharing the account’s main password. They are not a replacement name for an ordinary user-password generator and should not be presented as one.
Quick Recap
Testing checklist
- Confirm the plugin activates without PHP errors and the shortcode renders only where expected.
- Verify the generated value has the requested length and character policy.
- Inspect the page source and confirm the value is escaped for its output context.
- Test invalid length values if your interface accepts a setting.
- For password changes, test a logged-out request, a user without the required capability, an invalid nonce, and an invalid user ID; each must be rejected.
- Do not log generated or newly assigned passwords in debug output, analytics, or ordinary application logs.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

