Description
The Strong Passwords addon validates the password strength at the Membership Checkout of Paid Memberships Pro using tests for length, uppercase and lowercase letters, numbers, special characters, common terms, years, and combinations with username or email. It is recommended for those who create membership areas and need to reduce registrations with weak passwords without configuring additional screens in the dashboard.
Main Features of Strong Passwords
- Checkout validation
Blocks weak passwords during member registration in Paid Memberships Pro. - Strength meter
Displays the password strength in real time on the form. - Security tests
Analyzes length, letters, numbers, special characters, and predictable patterns. - No own dashboard
Starts working after activation, with no mandatory settings. - Hooks for customization
Allows changing minimum score, messages, tooltip, and visual bar.
Benefits of Strong Passwords
- More protected accounts
Reduces registrations with easily guessed passwords. - Lower operational risk
Decreases exposure caused by predictable combinations during registration. - Immediate feedback
Helps each member correct the password before completing. - Frictionless adoption
Adds validation to the existing flow without redesigning the checkout.
Who Is Strong Passwords Intended For?
- Those who create paid communities and need to protect accounts from the initial registration.
- Course projects, clubs, and private areas that use Paid Memberships Pro.
- Those who want to apply minimum password criteria at the membership checkout.
How to Download Strong Passwords
Strong Passwords is available for download here on Ultrapack. After downloading the .zip file, install it under Plugins > Add New > Upload Plugin, select the package, and activate it in the WordPress dashboard. Keep Paid Memberships Pro installed and active for the addon to work.
Strong Passwords adds a direct layer of control to member registration, especially on sites where the password is created within the checkout itself. The extension has no settings screen and does not force password changes for existing members, nor applies the same requirement in password recovery or profile change flows, keeping the focus on initial validation.
Frequently asked questions
Is Paid Memberships Pro Strong Passwords GPL-licensed?
Yes. Paid Memberships Pro Strong Passwords is distributed under the GPL (GNU General Public License). You may legally use, modify and redistribute it on as many sites as you want.
Can I use Paid Memberships Pro Strong Passwords on multiple sites?
Yes. You can install Paid Memberships Pro Strong Passwords on as many sites as you want. Only automatic updates through Ultrapack Auto Updater have a limit: from 3 to 80 sites, depending on the plan.
How much does Paid Memberships Pro Strong Passwords cost at Ultrapack?
Paid Memberships Pro Strong Passwords costs US$2.99 as a single purchase, and it is also included in the subscription plans starting at US$12/mo (VIP I).
Does Paid Memberships Pro Strong Passwords include updates?
Yes. The current version of Paid Memberships Pro Strong Passwords is 0.5.3, published at Ultrapack on Sep 30, 2026. Subscribers update straight from the WordPress dashboard with UAU (Ultrapack Auto Updater).
Is Paid Memberships Pro Strong Passwords scanned before publication?
Yes. Every version of Paid Memberships Pro Strong Passwords goes through a malware scan (ClamAV and YARA rules, at UltraHub) before it is published.
What changed in this version
Version 0.5.3 2026-09-29
- SECURITY: Improved sanitization and escaping throughout the plugin to resolve Plugin Check security findings. #63 (@dparker1005)
Version 0.5.2 2025-10-09
- ENHANCEMENT: Update the Zxcvbn library to latest release v1.4.2. #62 (@andrewlimaza)
- ENHANCEMENT: Show a default error message if no message is returned from the Zxcvbn library. #60 (@andrewlimaza)
- BUG FIX: Fixed an issue where the password hint and meter would show up on the Signup Shortcode Add On when the password field was hidden. #61 (@andrewlimaza)
Version 0.5.1 2024-09-11
- ENHANCEMENT: Now localizing the suggestions returned from the Zxcvbn library. #56 (@kimcoleman)
- ENHANCEMENT: Update the Zxcvbn library to latest release v1.3.1. #55 (@kimcoleman)
- ENHANCEMENT: Added better support for v3.1 and use built-in CSS classes where possible. #53 (@andrewlimaza)
- ENHANCEMENT: Adjusted Javascript to work with v3.1 new CSS classes. #53 (@ipokkel)
- BUG FIX: Fixes an issue when using the block or shortcode on a page that isn't set to the checkout page options in PMPro. #51 (@andrewlimaza)
- BUG FIX: Fixed incorrect variable passed to localized text string. #48 (@ipokkel)
- SECURITY: Improved escaping on text. #53 (@andrewlimaza)
Version 0.5 2021-09-28
- ENHANCEMENT: Added new filter to allow less required characters for site's using the custom password checker `pmprosp_minimum_password_length`. #41 (@mircobabini)
- ENHANCEMENT: Update the Zxcvbn library to support PHP 8.0. #43 (@mircobabini)
- BUG FIX/ENHANCEMENT: Fixed JavaScript warning for WordPress sites on 5.5.0+, support the newer method `userInputDisallowedList`. #37 (@andrewlimaza)
- BUG FIX/ENHANCEMENT: Fixed issue for sites running PHP 7.2 or lower. New requirements for the Zxcvbn library requires PHP 7.2+, older PHP versions will run our custom checker. #35 (@andrewlimaza)
Version 0.4
- BUG FIX: Fixed an issue where site's running PHP 5.6 would fatal error. This uses a custom password checker for sites on PHP 5.6. Recommended PHP version is 7.2+
Release notes published by the developer.
How to install
Automatic updates: this item is updated by the Ultrapack Auto Updater. With it installed, the new version shows up in your dashboard like any other WordPress update (how to set it up).
This item is an add-on for the Paid Memberships Pro plugin. Installed on its own it throws no error, but it does not work either.
- Install and activate the Paid Memberships Pro plugin before this one.
- Download the file
pmpro-strong-passwords.zip. - In the WordPress dashboard, go to Plugins > Add New > Upload Plugin.
- Select the file
pmpro-strong-passwords.zip, click Install Now and then Activate.
- Both stay active at the same time. Deactivating the Paid Memberships Pro plugin turns this add-on off with it.
- An add-on settings usually show up inside the main plugin screens, not in a menu of their own. If you find nothing new in the dashboard after activating, look there before opening a ticket.
Stuck on a step? Open a ticket telling us which one you stopped at.

UAU Ready