Skip to main content
Drupal is a registered trademark of Dries Buytaert
Release: Views Bootstrap 5.5.4 — Minor update available for module views_bootstrap (5.5.4). Release: Download Tracker 1.0.7 — Minor update available for module download_tracker (1.0.7). Release: Directory2Block Slideshow 1.0.8 — Minor update available for module directory2block_slideshow (1.0.8). Release: Mautic Audiences 1.1.5 — Minor update available for module mautic_audiences (1.1.5). Release: Rightup theme 1.0.3 — Minor update available for theme vartheme_bs5_rightup (1.0.3). Release: CommentOn 1.0.6 — Minor update available for module commenton (1.0.6). Release: ChatGPT Ads 1.0.3 — Minor update available for module chatgpt_ads (1.0.3). Release: Opensolr Search 5.1.3 — Minor update available for module opensolr_search (5.1.3). Module Revived: Swagger-PHP OpenAPI 3 documentation generator 1.0.0 — Module swagger_php updated after 10 months of inactivity (1.0.0). Security Coverage: Microsoft Azure AI — Module ai_provider_azure now has official Drupal security advisory coverage.

Password Strength module provides realistic password strength measurement and server-side enforcement for Drupal sites using pattern-matching and entropy calculation. Almost any type of password can be allowed so long as the password proves to be of high enough entropy. For inspiration see the XKCD comic on password strength.

How it's different

Other password enforcement tools are simplistic: they work by checking passwords on explicit rules like character count and amount of varying character types (symbols, numbers, uppercase letters, etc). A string like “Password1” will prove acceptable to such systems but are obviously weak and easily brute-forced.

How it works

Instead of checking on strict rules, Password Strength classifies the expected brute-force time for the summed entropy of common underlying patterns in the password. Patterns that can be detected in passwords include:

  • Words that are found in a dictionary of common words, common first and last names, or common passwords.
  • Words that are found in the dictionary, but with common "1337" or "leet" substitutions, such as 4 or @ for a, and 5 for s.
  • Common sequences of letters (abcde), numbers (12345), or characters spatially near each other on common keyboards (qwerty).
  • Three or more of the same characters, such as "aaa" or "8888".
  • Dates or years, such as "1921" or "19-11-1978."

Dependencies

Password Strength relies on the PHP library Zxcvbn-PHP for password complexity measurement. For Drupal 7, use Composer Manager or XAutoload to include the library with Password Strength. See the README.txt for more information.

Comparison to other modules and previous versions

Password Strength was a Drupal 5 and 6 module by jrbeeman that was decommissioned and replaced by Password Policy. Password Policy provides a system for defining explicit requirements on passwords. Password Strength differs by allowing nearly any password so long as the patterns that comprise it sum to a high entropy.

Drupal 8

We just released the Drupal 8 version, which is a plugin to Password Policy.

Depends on

Dependencies of the latest stable release

No dependencies recorded for this project.

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
2
Tracked since
Oct 2023
Latest release
2 years ago
Releases (12 mo)
0
Maintenance
Slowing

Releases

Version Type Core Release date
8.x-2.0-beta4 Pre-release Jul 31, 2024
8.x-2.0-beta3 Pre-release Oct 9, 2023