WordPress Password Hash Generator
Generates a phpass hash WordPress still accepts, in your browser, with the SQL to use it and a straight account of why a reset email or WP-CLI is better.
8,192 rounds, saltedphpass →The files nobody edits often enough to remember: wp-config constants, fresh salts, .htaccess rules, robots.txt and security headers.
Generates a phpass hash WordPress still accepts, in your browser, with the SQL to use it and a straight account of why a reset email or WP-CLI is better.
8,192 rounds, saltedphpass →Generate the eight WordPress authentication keys and salts in your browser, as define() lines, an array, or environment variables.
define( 'AUTH_KEY', '…' );wp-config.php →The six security headers, what each one does, whether http redirects to https, and what the server publishes about itself. Passive: nothing is probed.
Six headers, one requestPassive →Generate the WordPress hardening snippets worth having: file editing off, XML-RPC and REST user enumeration closed, login errors quietened, version hidden.
add_filter( 'xmlrpc_enabled', '__return_false' );WordPress →Write a $wpdb query with prepare() used correctly: placeholders for values, an allowlist for table and column names, and the right get_ method.
$wpdb->get_results( $wpdb->prepare( $sql, $value ) );wpdb →Build a complete wp-config.php with database settings, fresh security salts, debugging, hardening and memory limits.
define( 'DISALLOW_FILE_EDIT', true );define() →Generate HTTP security headers for Apache, nginx or WordPress PHP, with a content security policy you can start in report-only mode.
Header always set X-Frame-Options "SAMEORIGIN"HTTP →An RFC 9116 security.txt with the Expires field it requires, which is the field most of the files on the web are missing or have let lapse.
Contact + Expires, the two required fieldsArithmetic →Put a site into maintenance mode with a real 503 and Retry-After header, while letting logged-in users, an IP allowlist and the login page through.
wp_die( $message, $title, array( 'response' => 503 ) );template_redirect →htaccess rewrite rules for redirects, HTTPS and www, with the proxy case that makes the usual HTTPS rule loop and a reminder to test with 302.
Test with 302, ship 301mod_rewrite →Generate valid, ready-to-paste WordPress code in seconds without configuring a local runtime.
Your input is never uploaded
No submit button, no waiting
Copy, download or share a link
Built by Pixarlabs for WordPress
Clean output that follows WordPress conventions, no bloat, and everything computed in your browser.
Tools run in your browser. Database names, prefixes and secret salts you type are never sent to a server.
$ uploaded: 0 bytesGenerated code uses translatable labels, safely quoted values and the core hooks WordPress expects.
$ add_action( 'init', 'register_book' );Copy the result, download a ready file, or share a link that restores your settings.
$ download wp-config.php