[wp-trac] [WordPress Trac] #21022: Use bcrypt for password hashing; updating old hashes

WordPress Trac noreply at wordpress.org
Fri Feb 21 21:20:17 UTC 2025


#21022: Use bcrypt for password hashing; updating old hashes
-------------------------------------------------+-------------------------
 Reporter:  th23                                 |       Owner:
                                                 |  johnbillion
     Type:  enhancement                          |      Status:  reopened
 Priority:  normal                               |   Milestone:  6.8
Component:  Security                             |     Version:  3.4
 Severity:  normal                               |  Resolution:
 Keywords:  has-patch needs-testing has-unit-    |     Focuses:
  tests has-dev-note                             |
-------------------------------------------------+-------------------------

Comment (by stgoos):

 Replying to [comment:234 yani.iliev]:
 > It is quite common to transfer a website between different versions of
 WordPress.

 Isn't that just bad practise?
 Ideally - you always bring both sides to the same version to avoid issues
 in that area!

 > Right now, this will break all transfer/migration plugins.

 It would be for one transfer/migration round only. Then it get's fixed
 anyway by updating the source website first... (I know that sounds way
 easier than reality sometimes will be.)

 When transfering/migrating a website between different versions one should
 already be extra aware of what's going on, just by mapping the
 risks/challenges by reading through changelogs and testing upfront, and
 act accordingly to mitigate those risks/challenges.

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/21022#comment:235>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list