PHPackages                             mutms/moodle-tool\_mupwned - PHPackages - PHPackages  [Skip to content](#main-content)[PHPackages](/)[Directory](/)[Categories](/categories)[Trending](/trending)[Leaderboard](/leaderboard)[Changelog](/changelog)[Analyze](/analyze)[Collections](/collections)[Log in](/login)[Sign up](/register)

1. [Directory](/)
2. /
3. [Security](/categories/security)
4. /
5. mutms/moodle-tool\_mupwned

ActiveMoodle-tool[Security](/categories/security)

mutms/moodle-tool\_mupwned
==========================

Compromised passwords blocking plugin for Moodle LMS

v5.0.9.01(2d ago)015GPL-3.0-or-laterPHPCI passing

Since Mar 27Pushed yesterday1 watchersCompare

[ Source](https://github.com/mutms/moodle-tool_mupwned)[ Packagist](https://packagist.org/packages/mutms/moodle-tool_mupwned)[ Docs](https://github.com/mutms/moodle-tool_mupwned)[ RSS](/packages/mutms-moodle-tool-mupwned/feed)WikiDiscussions MOODLE\_405\_STABLE Synced yesterday

READMEChangelogDependencies (7)Versions (14)Used By (0)

Compromised passwords blocking plugin for Moodle™ LMS
=====================================================

[](#compromised-passwords-blocking-plugin-for-moodle-lms)

[![MDL Shield](https://camo.githubusercontent.com/abfbcd816eb2cd0a34b65a3a746ac71e2a9320bd02414aa789ef6ef1e6f1f229/68747470733a2f2f696d672e736869656c64732e696f2f656e64706f696e743f75726c3d68747470732533412532462532466d646c736869656c642e636f6d2532466170692532466261646765253246746f6f6c5f6d7570776e6564)](https://mdlshield.com/plugins/tool_mupwned) [![Moodle Plugin CI](https://github.com/mutms/moodle-tool_mupwned/actions/workflows/moodle-ci.yml/badge.svg)](https://github.com/mutms/moodle-tool_mupwned/actions/workflows/moodle-ci.yml/badge.svg)

Blocks compromised passwords in standard Moodle™ LMS installations — fully open source under GPL 3.0, with no restrictions on commercial use. Part of the [MuTMS suite](https://github.com/mutms).

Checks passwords against the [Have I Been Pwned](https://haveibeenpwned.com) database of known breaches when passwords are created, updated, or optionally on every login. Uses the k-Anonymity API — the full password is never sent outside Moodle. Users with a compromised password are blocked until they reset it.

Features
--------

[](#features)

- Checks passwords on creation and update
- Optional check on every login
- k-Anonymity API — no full password ever leaves Moodle
- Blocks access until a compromised password is replaced

Configuration
-------------

[](#configuration)

1. Install the plugin
2. Log in as admin — ensure you can reset your administrator password via email if needed
3. Enable the Password policy setting and review password requirements
4. Enable the Check password on login setting
5. Go to Site administration / Plugins / Authentication / Compromised password blocking
6. Enable Detect compromised passwords

If anything goes wrong, passwords can be reset from the CLI via `/admin/cli/reset_password.php`.

Requirements
------------

[](#requirements)

> This plugin is included in the [MuTMS distribution](https://github.com/mutms/mutms) — no manual installation needed if you use the distribution.

No other plugins are required.

Documentation
-------------

[](#documentation)

See [online documentation](https://docs.mutms.org/mupwned/) for more information.

---

> MuTMS is an independent open-source project, not affiliated with Moodle HQ.

###  Health Score

40

—

FairBetter than 86% of packages

Maintenance100

Actively maintained with recent releases

Popularity6

Limited adoption so far

Community7

Small or concentrated contributor base

Maturity42

Maturing project, gaining track record

 Bus Factor1

Top contributor holds 100% of commits — single point of failure

How is this calculated?**Maintenance (25%)** — Last commit recency, latest release date, and issue-to-star ratio. Uses a 2-year decay window.

**Popularity (30%)** — Total and monthly downloads, GitHub stars, and forks. Logarithmic scaling prevents top-heavy scores.

**Community (15%)** — Contributors, dependents, forks, watchers, and maintainers. Measures real ecosystem engagement.

**Maturity (30%)** — Project age, version count, PHP version support, and release stability.

###  Release Activity

Cadence

Every ~12 days

Recently: every ~28 days

Total

12

Last Release

2d ago

Major Versions

v4.5.10.05 → v5.0.6.052026-03-28

v4.5.10.06 → v5.0.6.062026-03-29

v4.5.11.01 → v5.0.7.012026-04-18

v4.5.12.01 → v5.0.8.012026-06-05

v4.5.13.01 → v5.0.9.012026-08-08

### Community

Maintainers

![](https://avatars.githubusercontent.com/u/203032388?v=4)[MuTMS](/maintainers/mutms)[@mutms](https://github.com/mutms)

---

Top Contributors

[![skodak](https://avatars.githubusercontent.com/u/241453?v=4)](https://github.com/skodak "skodak (64 commits)")

---

Tags

moodlemoodle-pluginmutms

### Embed Badge

![Health badge](/badges/mutms-moodle-tool-mupwned/health.svg)

```
[![Health](https://phpackages.com/badges/mutms-moodle-tool-mupwned/health.svg)](https://phpackages.com/packages/mutms-moodle-tool-mupwned)
```

###  Alternatives

[helsingborg-stad/municipio

A bootstrap theme for creating municipality sites.

4028.6k10](/packages/helsingborg-stad-municipio)[october/rain

October Rain Library

1601.7M102](/packages/october-rain)[johnbillion/user-switching

Instant switching between user accounts in WordPress and WooCommerce.

20177.0k2](/packages/johnbillion-user-switching)[pressbooks/pressbooks

Pressbooks is an open source book publishing tool built on a WordPress multisite platform. Pressbooks outputs books in multiple formats, including PDF, EPUB, web, and a variety of XML flavours, using a theming/templating system, driven by CSS.

45844.8k1](/packages/pressbooks-pressbooks)[mediawiki/maps

Adds various mapping features to MediaWiki

85155.1k3](/packages/mediawiki-maps)[civicrm/civicrm-drupal-8

Open source constituent relationship management for non-profits, NGOs and advocacy organizations.

19256.6k4](/packages/civicrm-civicrm-drupal-8)

PHPackages © 2026

[Directory](/)[Categories](/categories)[Trending](/trending)[Changelog](/changelog)[Analyze](/analyze)
