Vendic Admin Password Policy
vendic/magento2-admin-password-policy
Enforces stronger admin password rules (forbidden words, upper/lowercase and special-character requirements) and automatically deactivates admin users who have not logged in for 90 days.
Supported Magento versions: 2.4.9
1,098 installs★ 0 starsLatest: v1.0.7Released 2025-12-03License: MIT
composer require vendic/magento2-admin-password-policyREADME
Reproduced from the package’s own README, under its own license, as of 2026-09-13. Links and images point back at the source repository.
This module adds additional rules for admin passwords. It ensures that the following criteria are met for admin passwords:
- Password does not contain first name, last name, username or email of the user.
- Password does not contain 'guest', 'admin', or 'password'.
- Password has at least one lowercase letter.
- Password has at least one uppercase letter.
- Password has at least one special character.
Additional rules can be added through di.xml to the rules constructor parameter of the following class: Vendic\AdminPasswordPolicy\Plugin\ValidatePassword
Additional forbidden words can be added through di.xml to the forbiddenWords constructor parameter of the following class: Vendic\AdminPasswordPolicy\Rules\DoesNotContain
Users who have not logged in the past 90 days will automatically be set on inactive by a cron job that runs every midnight. It is possible to exclude users from being marked as inactive via configuration.
composer require vendic/magento2-admin-password-policy
None at this moment. Feel free to create a pull request if you need specific settings. Check the issues for tickets that need help.
- Magento 2 or Mage-OS ^2.4.4
Links
- Packagist
- PackageMaven — quality data by PackageMaven
- Repository
- Issues