App Password Audit
List WordPress application passwords and revoke the ones that should be dead.
App Password Audit is a proposed WordPress plugin — List WordPress application passwords and revoke the ones that should be dead. It is not available for download yet — 0 of the 40 votes needed have been cast. Vote to move it forward, or join the waitlist to be emailed on release.
Updated
At a glance
- Platform
- WordPress
- Status
- Collecting votes
- Votes
- 0 of 40 (40 to go)
- Requirements
- WordPress 6.4+, PHP 8.1+
- Integrations
- Application passwords, users
- Pricing
- Free core + Pro · Pro from $19/year
- Build time
- ~4 weeks after threshold
The problem
Application passwords are created for a CI job and never revoked, and wp-admin does not show a site-wide list.
Who this WordPress plugin is for
Admins with REST or CLI integrations on production.
App Password Audit is a proposed WordPress plugin for Admins with REST or CLI integrations on production..
A single screen lists application passwords by user, last used, and name. You can revoke one. It does not replace REST authentication.
Proposed plugin features
What this WordPress plugin would include in an initial release.
-
Site-wide list
Every application password, not only the current user.
-
Last used
See which tokens still touch the site.
-
Revoke
Destroy a token without deleting the user.
Not in the first release
Kept out of scope on purpose, so the first version ships small and focused.
- OAuth servers
- Disabling the REST API
- A security scanner
Concept screens
What happens after you vote
Every draft follows the same path from proposal to release.
-
1
Collecting votes You are here
The community decides whether this plugin gets built.
-
2
Threshold reached
Enough votes — the draft enters the build queue.
-
3
In development
Scope stays close to the published feature list.
-
4
Ready to download
Waitlisted voters are emailed first, with download details.
Application passwords, users
WordPress 6.4+, PHP 8.1+
Free core + Pro · Pro from $19/year
Per-user profile screens, User Enum Gate, a security suite
Frequently asked questions
Common questions about this WordPress plugin draft.
Does this turn off application passwords?
No. It lists and revokes. A global off switch is a different hardening choice.
Are the secrets shown?
No. Names, users, and last used only.
Is App Password Audit available to download yet?
No. App Password Audit is a proposed WordPress plugin, not a finished download. It has 0 of the 40 votes needed before development starts.
What does App Password Audit do?
List WordPress application passwords and revoke the ones that should be dead. It is a WordPress plugin proposal published on DraftPlugins, where the community votes on which drafts get built.
When will App Password Audit be released?
Estimated build time is ~4 weeks after threshold. Everyone on the waitlist is emailed as soon as it ships.
How much will App Password Audit cost?
Expected pricing: Free core + Pro · Pro from $19/year. Pricing for a draft is indicative and can change before release.
How do I get notified when App Password Audit is ready?
Vote on this page and join the waitlist with your email. We only email you about App Password Audit — release notes and access details.
What does App Password Audit require?
Planned requirements: WordPress 6.4+, PHP 8.1+.