Skip to main content
drupalreleases
Release: Cms 2.2.3 — Update released for Drupal core (2.2.3)! Release: Easy Breadcrumb 2.0.11 — Minor update available for module easy_breadcrumb (2.0.11). Release: Bootstrap 8.x-3.42 — Minor update available for theme bootstrap (8.x-3.42). Release: Editoria11y Accessibility Checker 3.0.10 — Minor update available for module editoria11y (3.0.10). Release: Editoria11y Accessibility Checker 2.2.24 — Minor update available for module editoria11y (2.2.24). Release: Leaflet 10.4.13 — Minor update available for module leaflet (10.4.13). Release: Flag 5.1.1 — Minor update available for module flag (5.1.1). Release: Layout Paragraphs 3.0.0-beta5 — New beta version released for module layout_paragraphs (3.0.0-beta5). Module Revived: Bootstrap 8.x-3.41 — Theme bootstrap updated after 6 months of inactivity (8.x-3.41). Usage Milestone: Mime Mail — Module mimemail crossed 50,000 active installs.

Simple password policy

135 sites Security covered Drupal 10–11
View on drupal.org

This module enforces a simple password policy with configurable rules for length, character types, and preventing reuse of old passwords. It also allows for password expiration notifications and can be bypassed under certain conditions.

INTRODUCTION

This module implements a simple account policy with the following configurable set of fixed rules:

  • minimum password length
  • minimum amount of lowercase chars (a-z)
  • minimum amount of uppercase chars (A-Z)
  • minimum amount of numeric chars (0-9)
  • minimum amount of special chars not(a-z A-Z 0-9)
  • minimum amount of old password allowed
  • period in which old passwords are not allowed
  • check paswword is not similar to username

The module will also notify the user his password is expired and will send a warning mail ahead of time.

  • expire the password after period
  • send email password is about to expire

Password policy can be ignored using:

  • ignore password policy expiration check on configured routes:
  • don't apply policy for users matching a pattern
  • applying the permission 'bypass password policy'

SIMILAR MODULES

If you want more control over the rules and how a password policy should apply, the password_policy module is more
enhanced. If you want more strict rules, password_strength might be an option too. This module was build to keep it
simple.

* password_policy
* password_strength

REQUIREMENTS

This does not require any other module.

RECOMMENDED MODULES

None

INSTALLATION

Install as you would normally install a contributed Drupal module. Visit
https://www.drupal.org/node/1897420 for further information.

CONFIGURATION

General usage

After installing the module is configured with these default rules:

  • min_length: 12
  • min_lowercase: 1
  • min_uppercase: 1
  • min_numeric: 1
  • min_special: 1
  • min_old: ''
  • min_old_age: ''
  • similar_username: ''
  • ignore_routes:
    • 'entity.user.edit_form'
    • 'system.ajax'
    • 'user.logout'
    • 'admin_toolbar_tools.flush'
    • 'user.pass'
    • 'image.style_public'
  • ignore_users: { }
  • expire_period: '1 year'
  • expire_warning: '3 weeks'

Configuration is found under the "People" configuration item.
/admin/config/people/password_policy

Depends on

Dependencies of the latest stable release

  • user Drupal core

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
13
Tracked since
Jan 2023
Latest release
1 month ago
Releases (12 mo)
6 ▲ from 1
Maintenance
Active

Release Timeline

Releases

Version Type Core Release date
1.1.4 Stable 10–11 Aug 25, 2026
1.1.3 Stable 10–11 Aug 21, 2026
1.1.2 Stable 10–11 Aug 14, 2026
1.1.1 Stable 10–11 Aug 14, 2026
1.1.0 Stable 10–11 Aug 13, 2026
1.1.x-dev Dev 10–11 Aug 13, 2026
1.0.5 Stable 10–11 Oct 15, 2024
1.0.4 Stable 8–10 Sep 15, 2023
1.0.3 Stable May 31, 2023
1.0.2 Stable Feb 14, 2023
1.0.1 Stable Feb 14, 2023
1.0.x-dev Dev Feb 14, 2023
1.0.0 Stable Jan 30, 2023