A password is the secret combination of characters that proves your identity when logging into your WordPress dashboard. It’s one of the most basic, and most important, layers of protection for your site.
What Makes a Password Strong
- At least 12–16 characters long.
- A mix of uppercase, lowercase, numbers, and symbols.
- No real words, names, or predictable patterns.
- Unique to this account — never reused elsewhere.
Why Weak Passwords Are Risky
Automated bots constantly attempt to guess common passwords on WordPress login pages. A weak password — something short, common, or reused from another account — is one of the easiest ways for a site to get compromised.
Making Strong Passwords Manageable
WordPress can generate a strong password automatically when creating a new user, and a password manager can store it securely so you don’t need to memorize it. Pairing a strong password with two-factor authentication adds another solid layer of protection.