Title: Yard | Warden
Author: Yard | Digital Agency
Published: <strong>21 de Agosto, 2026</strong>
Last modified: 21 de Agosto, 2026

---

Buscar plugins

![](https://ps.w.org/yard-warden/assets/banner-772x250.png?rev=3658261)

![](https://ps.w.org/yard-warden/assets/icon-256x256.png?rev=3658261)

# Yard | Warden

 Por [Yard | Digital Agency](https://profiles.wordpress.org/yarddigitalagency/)

[Descargar](https://downloads.wordpress.org/plugin/yard-warden.1.0.5.zip)

 * [Detalles](https://gl.wordpress.org/plugins/yard-warden/#description)
 * [Valoracións](https://gl.wordpress.org/plugins/yard-warden/#reviews)
 *  [Instalación](https://gl.wordpress.org/plugins/yard-warden/#installation)
 * [Desenvolvemento](https://gl.wordpress.org/plugins/yard-warden/#developers)

 [Soporte](https://wordpress.org/support/plugin/yard-warden/)

## Descrición

Yard Warden hardens core WordPress password and login flows:

 * **Password strength** via [zxcvbn-php](https://github.com/bjeavons/zxcvbn-php).
   Scores passwords 0-4 (default 4) based on real guessability, not arbitrary character-
   class rules. User inputs (login, email, display name) are fed to zxcvbn so passwords
   containing them score lower.
 * **Minimum length** enforcement (default 16) on top of the zxcvbn score.
 * **Generic login errors** to prevent username enumeration on the wp-login form.
   Always on, no toggle. Only applies to authentication failures; password-reset
   and profile-update validation errors remain verbose so users can correct their
   input.
 * **Safer multisite onboarding.** Auto-activates new signups server-side so no 
   activation link is emailed and the wp-activate.php landing page (which would 
   print username + plaintext password) is never reached. The welcome email is rewritten
   to contain a one-time password-reset link instead of a generated password.
 * **Login limiting** via transient-based counters across three dimensions (IP+Username,
   IP, Username). Locks out brute-force attempts. Admin can clear all counters via
   Settings > Yard Warden.

#### Filters

 * `yard::warden/password/min-length` (default `16`) – Minimum character count.
 * `yard::warden/password/min-score` (default `4`) – Minimum zxcvbn score (0-4).
 * `yard::warden/login/generic-error` (default `Invalid credentials.`) – Replacement
   login error message.
 * `yard::warden/login/leaky-error-codes` (default `['invalid_username', 'invalid_email','
   incorrect_password']`) – WP_Error codes to rewrite.
 * `yard::warden/onboarding/welcome-subject` (default `Welcome to <site>!`) – Multisite
   welcome email subject.
 * `yard::warden/onboarding/welcome-body` (default reset-link body) – Full welcome
   email body. Receives `$user`, `$resetUrl`, original body.
 * `yard::warden/limit-login/enabled` (default `true`) – Set to `false` to disable
   login limiting entirely.
 * `yard::warden/limit-login/client-ip` (default `REMOTE_ADDR`) – Override IP detection(
   e.g. for reverse proxies).
 * `yard::warden/limit-login/error-message` (default `Too many failed login attempts...`)–
   Lockout error shown to the user.
 * `yard::warden/limit-login/skip-error-codes` (default `['expired_session']`) –
   WP_Error codes that do not count as failed attempts.
 * `yard::warden/limit-login/threshold/{dimension}` (default `5` / `50` / `3`) –
   Attempts before lockout per dimension (`ip_user` / `ip` / `username`).
 * `yard::warden/limit-login/window/{dimension}` (default `300` / `3600` / `1500`)–
   Counting window in seconds per dimension.
 * `yard::warden/limit-login/lockout/{dimension}` (default `300` / `3600` / `1500`)–
   Lockout duration in seconds per dimension.

#### Policy override example

    ```
    add_filter('yard::warden/password/min-score', function (int $score) {
        return max($score, 4);
    });
    ```

## Instalación

 1. Upload the plugin files to `/wp-content/plugins/yard-warden`, or install through
    the Plugins screen directly.
 2. Activate the plugin through the “Plugins” screen in WordPress.
 3. Configure login-limit thresholds via Settings > Yard Warden, or override any default
    via the filters above.

## Preguntas frecuentes

### Does this add password expiry or forced rotation?

No. Forced password rotation is not implemented; it pushes users toward weaker, 
predictable passwords rather than improving security.

### Can I disable login limiting?

Yes, via the `yard::warden/limit-login/enabled` filter.

## Comentarios

Non hai recensións para este plugin.

## Colaboradores e desenvolvedores

“Yard | Warden” é un software de código aberto. As seguintes persoas colaboraron
con este plugin.

Colaboradores

 *   [ Yard | Digital Agency ](https://profiles.wordpress.org/yarddigitalagency/)

[Traduce “Yard | Warden” ao teu idioma.](https://translate.wordpress.org/projects/wp-plugins/yard-warden)

### Interesado no desenvolvemento?

[Revisa o código](https://plugins.trac.wordpress.org/browser/yard-warden/), bota
unha ollada ao[repositorio SVN](https://plugins.svn.wordpress.org/yard-warden/),
ou subscríbete ao [log de desenvolvemento](https://plugins.trac.wordpress.org/log/yard-warden/)
por [RSS](https://plugins.trac.wordpress.org/log/yard-warden/?limit=100&mode=stop_on_copy&format=rss).

## Rexistro de cambios

#### 1.0.5

 * Source code published on GitHub and the package registered on Packagist.
 * Added the EUPL-1.2 licence text and declared it in composer.json.

#### 1.0.4

 * Fixed a fatal error when the plugin is installed via Composer, where dependencies
   are autoloaded by the project instead of the plugin.

#### 1.0.3

 * Minimum WordPress version raised to 6.3.
 * Bundled Dutch translations removed; translations are now served through translate.
   wordpress.org.
 * WP_Error codes prefixed with yard_warden_ to avoid collisions with other plugins.
 * Login-limit transient keys prefixed with yard_warden_ll_.
 * Welcome-email opt-out query flag renamed to yard_warden_disable_welcome_email.

#### 1.0.2

 * Text domain adjusted to yard-warden.

#### 1.0.0

 * Initial release.

## Meta

 *  Versión **1.0.5**
 *  Última actualización **Fai 1 mes**
 *  Instalacións activas **30+**
 *  Versión de WordPress ** 6.3 ou superior **
 *  Probado ata **7.0.6**
 *  Versión de PHP ** 7.4 ou superior **
 *  Idioma
 * [English (US)](https://wordpress.org/plugins/yard-warden/)
 * Etiquetas
 * [Brute Force](https://gl.wordpress.org/plugins/tags/brute-force/)[login](https://gl.wordpress.org/plugins/tags/login/)
   [multisite](https://gl.wordpress.org/plugins/tags/multisite/)[password](https://gl.wordpress.org/plugins/tags/password/)
   [security](https://gl.wordpress.org/plugins/tags/security/)
 *  [Vista avanzada](https://gl.wordpress.org/plugins/yard-warden/advanced/)

## Valoracións

Aínda non se enviaron valoracións.

[A túa valoración](https://wordpress.org/support/plugin/yard-warden/reviews/#new-post)

[Ver todas as valoracións](https://wordpress.org/support/plugin/yard-warden/reviews/)

## Colaboradores

 *   [ Yard | Digital Agency ](https://profiles.wordpress.org/yarddigitalagency/)

## Soporte

Tes algo que dicir? Necesitas axuda?

 [Ver o foro de soporte](https://wordpress.org/support/plugin/yard-warden/)