WordPress Password Hash Generator
Generate and verify WordPress ($wp$ and $P$) password hashes.
WordPress Password Hash Generator
Generate and verify WordPress password hashes in the browser. Produce a modern WordPress 6.8+ bcrypt hash ($wp$2y$…) or a legacy phpass hash ($P$B…), or check whether a password matches a hash taken from the wp_users table.
How WordPress hashes passwords
WordPress does not store your password — it stores a one-way hash of it in the user_pass column.
- WordPress 6.8 and newer use bcrypt. Because bcrypt ignores everything past 72 bytes, WordPress first hashes the password with HMAC-SHA384 and base64-encodes it, then bcrypts the result. The stored value starts with
$wp$2y$. - WordPress 6.7 and earlier use the phpass portable hash: an MD5-based algorithm stretched thousands of times, stored as
$P$Bplus salt and digest.
When a user logs in on an upgraded site, WordPress verifies against the old hash and silently rehashes the password in the new format.
Using this tool
- Generate – type a password, choose the 6.8+ bcrypt or legacy phpass format, and copy the hash into your database.
- Verify – paste an existing hash and a password to confirm whether they match. The tool auto-detects
$wp$2y$,$P$/$H$, plain$2y$bcrypt, and legacy MD5 hashes.
Security notes
Password hashing is deliberately slow to resist brute-force attacks, so generating a bcrypt hash takes a moment. Never reuse the sample password on a real site. For general-purpose hashing (not passwords) see the SHA256 Hash Generator; for keyed authentication see the HMAC Generator.
Frequently Asked Questions
What hash format does modern WordPress use?
Since WordPress 6.8 (2025), passwords are stored as bcrypt hashes prefixed with $wp$2y$. WordPress first computes a base64 HMAC-SHA384 of the password (to avoid bcrypt's 72-byte limit) and then bcrypts that. This tool generates and verifies that exact format.
What is the old $P$ format?
WordPress up to 6.7 used the phpass \"portable\" hash, written as $P$B followed by a cost character, an 8-character salt, and the digest. It stretches MD5 thousands of times. This tool still generates and verifies $P$ hashes for older sites.
How do I reset a WordPress password directly in the database?
Generate a hash here, then run an SQL update such as UPDATE wp_users SET user_pass='<hash>' WHERE user_login='admin';. WordPress will accept it at the next login and may transparently upgrade it to the newest format.
Can I check whether a password matches a stored hash?
Yes. Switch to Verify, paste the hash from the user_pass column, type the password, and the tool reports whether they match. It recognizes $wp$2y$, $P$/$H$ phpass, plain bcrypt, and legacy 32-character MD5 hashes.
Is this safe to use?
The hashing runs entirely in your browser, so passwords are never uploaded. Still, only reset passwords for accounts you control, and use a strong unique password.