WordPress Password Hash Generator

Generate and verify WordPress ($wp$ and $P$) password hashes.

WordPress Password Hash Generator

Generate and verify WordPress password hashes in the browser. Produce a modern WordPress 6.8+ bcrypt hash ($wp$2y$…) or a legacy phpass hash ($P$B…), or check whether a password matches a hash taken from the wp_users table.

How WordPress hashes passwords

WordPress does not store your password — it stores a one-way hash of it in the user_pass column.

  • WordPress 6.8 and newer use bcrypt. Because bcrypt ignores everything past 72 bytes, WordPress first hashes the password with HMAC-SHA384 and base64-encodes it, then bcrypts the result. The stored value starts with $wp$2y$.
  • WordPress 6.7 and earlier use the phpass portable hash: an MD5-based algorithm stretched thousands of times, stored as $P$B plus salt and digest.

When a user logs in on an upgraded site, WordPress verifies against the old hash and silently rehashes the password in the new format.

Using this tool

  1. Generate – type a password, choose the 6.8+ bcrypt or legacy phpass format, and copy the hash into your database.
  2. Verify – paste an existing hash and a password to confirm whether they match. The tool auto-detects $wp$2y$, $P$/$H$, plain $2y$ bcrypt, and legacy MD5 hashes.

Security notes

Password hashing is deliberately slow to resist brute-force attacks, so generating a bcrypt hash takes a moment. Never reuse the sample password on a real site. For general-purpose hashing (not passwords) see the SHA256 Hash Generator; for keyed authentication see the HMAC Generator.

Frequently Asked Questions

Since WordPress 6.8 (2025), passwords are stored as bcrypt hashes prefixed with $wp$2y$. WordPress first computes a base64 HMAC-SHA384 of the password (to avoid bcrypt's 72-byte limit) and then bcrypts that. This tool generates and verifies that exact format.

WordPress up to 6.7 used the phpass \"portable\" hash, written as $P$B followed by a cost character, an 8-character salt, and the digest. It stretches MD5 thousands of times. This tool still generates and verifies $P$ hashes for older sites.

Generate a hash here, then run an SQL update such as UPDATE wp_users SET user_pass='<hash>' WHERE user_login='admin';. WordPress will accept it at the next login and may transparently upgrade it to the newest format.

Yes. Switch to Verify, paste the hash from the user_pass column, type the password, and the tool reports whether they match. It recognizes $wp$2y$, $P$/$H$ phpass, plain bcrypt, and legacy 32-character MD5 hashes.

The hashing runs entirely in your browser, so passwords are never uploaded. Still, only reset passwords for accounts you control, and use a strong unique password.