BuildWithHumza Application Password Audit
Download BuildWithHumza Application Password Audit 1.0.0Description
At a glance
BuildWithHumza Application Password Audit v1.0.0 — free WordPress plugin download. Key facts: updated September 26, 2026 · requires WordPress 6.0+ & PHP 7.4+.
WordPress hides application passwords on each user’s own profile page. If your site has twenty users, checking them all means opening twenty profiles. There is no screen anywhere in WordPress that answers the obvious question:
Who, and what, can get into this site right now?
BuildWithHumza Application Password Audit adds that screen under Tools. It is read-only apart from two deliberate revoke buttons, and it never sends anything anywhere.
Why application passwords matter
An application password is a permanent key. It is created once for a script, a mobile app, a backup service or an integration, it works over the REST API, and it never expires on its own. Changing your WordPress password does not revoke it. Most site owners have no idea how many exist, who created them, or whether anything is still using them.
This plugin lists every one of them, site-wide, with the date it was created, the date it was last used, and the IP address it was last used from.
What the report shows
- Application passwords for every user, with created date, last used date and last IP
- Active login sessions per user, so you can see who is currently signed in somewhere
- Last login for every user, recorded from the moment you activate the plugin
- Roles, with accounts that can fully control the site clearly marked
- Remote management tools that hold standing access: MainWP, UpdraftCentral, ManageWP and Wordfence
- Warning flags on anything that looks abandoned
The flags are the point
A list of twenty application passwords tells you nothing. The plugin marks the ones worth acting on:
- Application passwords that have never been used at all
- Application passwords unused for over 90 days
- Administrators who have not logged in for over 90 days
- Administrators with no recorded login since tracking began
Flagged rows sort to the top, so you read the risk first instead of scrolling.
What you can do from the screen
- Sign a user out of every device at once
- Revoke a single application password without disturbing the others
- Export the whole report as CSV for a handover document or a security review
Remote access detection
A connected management dashboard is standing access just like a user account, and it survives a password change. The plugin reports whether MainWP Child, UpdraftPlus, ManageWP Worker and Wordfence are active, and where the pairing is readable it shows whether the site is connected and which WordPress user connected it.
Where a connection genuinely cannot be read, the plugin says so and explains why rather than guessing. Wordfence Central keeps its state in its own database table, so that one is reported as undetermined on purpose.
Who this is for
- Freelancers and agencies finishing a project or inheriting a site. Export the report and you have written evidence of exactly what access existed.
- Site owners checking that no former contractor, old staff account or forgotten integration still has a way in.
- Anyone who has ever created an application password and then forgotten about it.
Honest limitations
WordPress does not store login history, so no plugin can show you logins from before it was installed. This one starts recording when you activate it and displays “Not seen since [date]” rather than claiming a long-standing user has never logged in. Give it a few weeks before the login warnings mean much. Application password data is read from WordPress core and is accurate immediately.
The report loads the first 500 users by default because it is meant to be read by a person. Larger sites can raise that with the bwh_apa_user_limit filter.
Privacy
This plugin makes no external requests, loads no remote scripts and includes no tracking or analytics. It stores one timestamp per user and one option recording when tracking began. Uninstalling deletes both.
Frequently asked questions
What do I get when I download BuildWithHumza Application Password Audit?
BuildWithHumza Application Password Audit 1.0.0 is the latest version. It is a WordPress plugin you can download here free of charge under the GPL license, with the complete feature set included and no trial limitations.
Does BuildWithHumza Application Password Audit cost anything?
No. BuildWithHumza Application Password Audit 1.0.0 is 100% free — the full GPL version, not a trial or demo. There are no download limits, no accounts to create, and no upsells during the download.
How do I install BuildWithHumza Application Password Audit 1.0.0?
Download the ZIP file from this page, then in your WordPress dashboard go to Plugins → Add New → Upload Plugin, choose the file, click Install Now, then Activate. The plugin works immediately after activation — no license key or extra setup is required for the core features.
What are the requirements for BuildWithHumza Application Password Audit?
BuildWithHumza Application Password Audit 1.0.0 requires WordPress 6.0 or higher and PHP 7.4 or higher. Most modern WordPress hosts already meet these versions. Running older versions may cause features to break, so update WordPress and PHP first if your site is behind.
When was BuildWithHumza Application Password Audit last updated?
Version 1.0.0 was last updated on September 26, 2026. This page is refreshed automatically, so the download here always matches the newest version we have verified.
Is the BuildWithHumza Application Password Audit download safe?
The file is sourced directly from the official WordPress.org repository — the same file the developer published. It is served unmodified, so what you install here is byte-identical to the official release.
Technical details
| Version | 1.0.0 |
|---|---|
| Last updated | September 26, 2026 |
| Requires WordPress | 6.0 or higher |
| Requires PHP | 7.4 or higher |
| Author | Mohammad Humza |
| Tags | application-passwords, last-login, security-audit, sessions, user-management |
Download BuildWithHumza Application Password Audit
Download BuildWithHumza Application Password Audit WP PluginNote: if the download does not start, disable your ad blocker and try again.