Protects your Flarum community by checking passwords against Have I Been Pwned β a database of passwords exposed in known data breaches. Passwords are checked securely using the k-anonymity model: only the first 5 characters of the SHA-1 hash are ever sent to the API, so no plaintext password data leaves your server.
- Registration check β blocks sign-up with a known-compromised password
- Password reset check β prevents users from resetting to a known-compromised password
- Login check (optional) β detects accounts already using a compromised password at login time and sends a password reset email automatically
- Admin revocation (optional) β strips admin permissions from any account using a compromised password until it is changed
- Persistent notice banner β shows analert to the affected user on every page until they change their password, with a "Resend Reset Email" button and a configurable "Learn More" link
- Configurable learn-more URL β defaults to
haveibeenpwned.com/Passwords; can be overridden in the admin panel with a forum-hosted explanation page
Password checks use the HIBP Pwned Passwords range API with k-anonymity:
- The password is hashed with SHA-1 locally
- Only the first 5 hex characters of the hash are sent to
api.pwnedpasswords.com - The API returns all matching hash suffixes (padded to a consistent size)
- The extension checks whether the full hash appears in the results β entirely client-side (server-side in PHP)
No password or full hash is ever transmitted.
composer require fof/pwned-passwordscomposer update fof/pwned-passwords
php flarum migrate
php flarum cache:clearNavigate to Admin β Extensions β FoF Pwned Passwords:
| Setting | Description |
|---|---|
| Enable password check on login | Check passwords at login and send a reset email if compromised |
| Revoke permissions from pwned admins | Remove admin access until the user changes their password |
| "Learn More" link URL | URL shown in the notice banner (defaults to haveibeenpwned.com/Passwords) |
An extension by FriendsOfFlarum.