Application Password Alerts

Application Password Alerts

What It Does

This module watches for WordPress application passwords being created. These passwords allow access to an account through the REST API, without going through the login page.

As soon as an application password is added to an account, the user receives an email. If that account has the Administrator role, the site administration address also receives an email, unless it is already the same address.

Why It Matters

Security vulnerabilities can expose your website, user data, and business to serious risks.

By putting this security measure in place, you protect your website against threats and potential attacks. An application password created without the user's knowledge is a direct way into the account.

How to Use

Activate this module in the Users & Login section of SecuPress settings, under Password Policy. Check Yes, alert users when an Application Password is added to their account.

On SecuPress Pro, the module is activated automatically when updating to 2.6.4.

Once activated, the module works automatically. The email includes the application password name. The user can revoke it from their WordPress profile.

If you encounter any issues after activation, you can temporarily deactivate the module.