Creating a Strong Password and Using a Password Manager
Your WordPress login is a common target, so a strong, unique password matters more than it might seem.
What makes a password strong
- At least 12–16 characters – length matters more than complexity tricks.
- A mix of unrelated words, or a random string, rather than a predictable phrase.
- Unique to this site – never reused from another account.
- Not based on personal information (names, dates, addresses) that could be guessed or found online.
Using WordPress’s built-in generator
When setting or changing a password in your profile, WordPress can generate a strong random one for you automatically – look for a “Generate Password” button on the password field.
Password managers
A password manager (such as Bitwarden, 1Password, or the one built into your browser) generates and stores strong unique passwords for every site you use, so you don’t need to remember them yourself.
Tip: If you’re reusing the same password across multiple sites, that’s the single biggest risk to fix first – a breach on an unrelated site can expose your WordPress login too.
Conversation
Leave a Reply
You must be logged in to post a comment.
Thanks for the feedback. Let us know what was missing and we will improve this page.
Thank you for your feedback.