Skip to main content
drupalreleases

Use direct release data with your AI assistant.

Learn more

Password Stats

Security covered Under active development 8 sites

This module helps you track the security of your Drupal site's password hashes. It provides information on the total number of password hashes and highlights any users still using older, less secure hashing methods. The module recommends disabling password compatibility features if no legacy hashes are found.

This module provides a drush command and a status line in the requirements table with information about stored password hashes.

Drupal uses the default PHP password_hash() and password_verify() functions in order to store and verify passwords securely since Drupal 10.1.x. User entities created with an older version might still have hashes generated with the previous password hashing algorithm.

This module displays the total number of stored password hashes along with the number of active users with password hashes generated prior to Drupal 10.1.0.

It also displays a recommendation to disable the Password Compatibility module if no active users with passwords hashed by Drupal prior to 10.1.0 were found on a site.

  • For a full description of the module, visit the project page.
  • To submit bug reports and feature suggestions, or to track changes, use the issue queue.

Table of contents

  • Requirements
  • Installation
  • Usage
  • Maintainers

Requirements

Drupal 10.1.x or better. No other modules are required.

Installation

Usage

Drush

password_stats:
  password_stats:legacy Returns the number of stored passwords hashed with legacy algorithms.
  password_stats:total  Returns the total number of hashed passwords.

Status report

Navigate to Administration › Reports › Status report and review the information under the Password Compatibility heading.

Maintainers

Current maintainers

Drupal 10–11

Ask your assistant about Password Stats

Check compatibility with your Drupal and PHP version, maintenance and security coverage, from current release data. How it works

Depends on

Dependencies of the latest stable release

No dependencies recorded for this project.

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
5
Tracked since
Jan 2023
Latest release
1 year ago
Releases (12 mo)
0 ▼ from 1
Maintenance
Dormant

Release Timeline

Releases

Version Type Core PHP Release date
2.1.0 Stable 10–11 Nov 28, 2024
2.0.0 Stable 10 Aug 17, 2023
2.x-dev Dev 10–11 Aug 17, 2023
1.0.0 Stable 10 May 3, 2023
1.0.x-dev Dev 10 Jan 27, 2023