WordPress Password Hash Generator

Enter a password and get a 34-character $P$B phpass hash you can paste into the user_pass column of wp_users.

The WordPress Password Hash Generator turns a plain password into the same kind of hash WordPress writes to the user_pass column of the wp_users table: a 34-character string starting with $P$B, produced by the "portable PHP password hashing" scheme (phpass) that wp_hash_password() has used since WordPress 2.5. Paste the result into the database and you can log in with the password you typed. It exists for the moment when you are locked out of a site and phpMyAdmin is the only door you have.

How the hash is built

There is one input, the password, and one button. When you press it the tool does exactly what WordPress's bundled phpass class does:

  1. Draws 8 random salt characters from the phpass alphabet (./0-9A-Za-z).
  2. Computes MD5 of salt + password, then feeds MD5 of (previous digest + password) back into itself 8,192 times. That iteration count is what the B in $P$B encodes (2 to the power 13).
  3. Encodes the final 16-byte digest with phpass's own base64 variant into 22 characters.

The output is $P$B + 8 salt characters + 22 hash characters. Because the salt is random, hashing the same password twice gives two different strings, and both are valid. WordPress reads the salt back out of the stored hash when it checks a login, so any one of them will work.

Resetting a WordPress password through the database

This is the main reason people need a phpass hash by hand. The steps, whether you use phpMyAdmin, Adminer or the MySQL command line:

  1. Generate a hash for the new password here and copy it.
  2. Open the wp_users table (the prefix may differ if it was changed at install time) and find the row for your user by user_login or user_email.
  3. Replace the value in user_pass with the hash. In SQL: UPDATE wp_users SET user_pass = '$P$B...' WHERE user_login = 'admin';
  4. Log in with the new password. WordPress may re-hash it on first login if the site is on a newer scheme, which is fine.

Some panels offer an "MD5" dropdown next to the field. That also works, because WordPress still accepts a bare 32-character MD5 and upgrades it on login, but a plain MD5 sits unsalted in your database until then. The MD5 Hash Generator will give you one if you prefer that route; the phpass hash is the better default.

Sample output

PasswordSalt partFull hash (34 characters)
passwordabcdefgH$P$BabcdefgH1cmw/0aaKqIh599GO/xQ91
test123459IQRaTwmf (count 9)$P$9IQRaTwmfeRo7ud9Fh4E2PdI0S3r.L0

The second row is the test vector shipped with the original phpass library, which we used to check this implementation; it uses a lower iteration count (9) than WordPress does. The tool itself always emits $P$B hashes with a fresh salt, so your results will differ from the first row even for the same password.

What about the newer WordPress hashes

WordPress 6.8 started hashing new passwords with bcrypt, prefixed $wp$2y$10$, after running the password through SHA-384. Sites that upgraded keep verifying old $P$B hashes and quietly convert them the next time the user logs in, so a phpass hash from this page still gets you in on a current install. If you need a bcrypt string for some other system, the SHA256 Hash Generator and SHA512 Hash Generator won't help either; those are fast digests, not password hashes, and are only useful for checksums.

If what you actually need is a new strong password to hash, the Random Password Generator or the easier-to-type Memorable Password Generator will make one. Other utilities of this kind are grouped under all developer & test data tools.

Frequently asked questions

Is the password sent anywhere?

No. The hash is computed in your browser using the crypto module bundled with the page. Nothing is posted to a server, so it is safe to type the real password you plan to use.

Why is the hash different each time I press the button?

Each run picks a new random 8-character salt, and the salt is part of the hash. WordPress reads the salt from the stored string when it verifies a login, so every hash the tool produces for a password is valid.

Will this work on WordPress 6.8 and later?

Yes. Newer versions store fresh passwords as bcrypt, but they still verify $P$B phpass hashes and upgrade them on the next successful login.

Can I use this for a Drupal or phpBB site?

Both used phpass at one time. phpBB 3.0 hashes start with $H$ and Drupal 7 uses a SHA-512 variant with $S$, so this tool's $P$B output only matches WordPress and other software that uses the portable MD5 phpass mode.

Can I get the password back from the hash?

No. The hash is one way; the only way to know the password is to have it. If you have lost it, generate a hash for a new password and write that into the database.