Forces selected users to reset their password before they can continue using the site. Ideal for temporary passwords and security compliance.

Clean, audited code that installs in a click, stays out of your way, and keeps getting better — backed by the team that built it.
The capabilities that matter, built in from day one.
in days, with 0 meaning expiry is switched off (the default).
apply the policy to every non-administrator, or only to the roles you pick.
, so an unattended nightly job can never lock out the only account able to switch it off again.
Install, activate and configure in minutes — no code required.
New features and compatibility updates, included with your license.
Real help from the team that built it, whenever you need it.
Fully localizable and compatible with the latest WordPress & PHP.
Clean hooks and filters so you can extend it to fit your workflow.
Follows WordPress best practices and works with any well-coded theme.
Choose the license that fits — every plan includes updates and support.
Yes. From the Force Password Reset admin page you can force a reset for every non-administrator user with a single action, or clear the requirement just as easily.
Administrators are protected from being forced to reset by other admins to avoid lock-outs. You can still reset your own password normally. The expiry policy applies the same protection, and goes a little further: users with the administrator role, any user who can manage options, and multisite super admins are never expired by the scheduled sweep. An unattended nightly job is the wrong place to l
Go to **Settings → Password Reset → Password Expiry Policy** and set **Password Maximum Age** to the number of days you want. Leave it at 0 and nothing about the plugin's behaviour changes.
Nobody is locked out on day one. Existing accounts have no recorded password-change date, so the plugin records the moment the expiry clock started (shown on the settings screen) and treats that as their last change. Every existing user therefore gets the full maximum age of grace from that point, and the warning email still reaches them beforehand. The assumed date is written to each user the fir
No. The sweep is batched: each run examines a bounded number of users and, if there are more, records where it got to and books a follow-up run a few minutes later, until the whole user list has been covered. The batch size and the number of batches per run are filterable (fpr_expiry_batch_size, fpr_expiry_batches_per_run).
Get Force Password Reset & Expiry Policy today and set it up in minutes — backed by a 30-day money-back guarantee.
Get it now