Laravel Packages

Password Strength Estimator Validation in Laravel

Published
Password Strength Estimator Validation in Laravel image

The Laravel Zxcvbn package is a validation rule that estimates password strength using a PHP port of Dropbox's dropbox/zxcvbn JS package. It considers using user inputs as well to determine a score for password guessability:

// In your validation rules
use Illuminate\Validation\Rules\Password;
use Ziming\LaravelZxcvbn\Rules\ZxcvbnRule;
 
$request->validate([
'name' => ['required']
'email' => ['required', 'email'],
'password' => [
'required',
'confirmed',
'min:8',
new ZxcvbnRule([
request('email'),
request('name'),
]),
],
]);
 
// Examples using zxcvbn-php
$weak = $zxcvbn->passwordStrength('password', $userData); // 0 - extremely guessable
$strong = $zxcvbn->passwordStrength('correct horse battery staple'); // 4 - very unguessable

You can define a ZXCVBN_MIN_SCORE configuration value to determine when validation should fail, based on this scale provided by the underlying zxcvbn-php package. The default is 3 but depending on your needs, you can configure it to match any of the following:

  • 0 means the password is extremely guessable (within 10^3 guesses), dictionary words like 'password' or 'mother' score a 0
  • 1 is still very guessable (guesses < 10^6), an extra character on a dictionary word can score a 1
  • 2 is somewhat guessable (guesses < 10^8), provides some protection from unthrottled online attacks
  • 3 is safely unguessable (guesses < 10^10), offers moderate protection from offline slow-hash scenario
  • 4 is very unguessable (guesses >= 10^10) and provides strong protection from offline slow-hash scenario

💻 You can get started with this package on GitHub: ziming/laravel-zxcvbn.

It's important to remember that Laravel has excellent password rules out of the box, including the ability to ensure a password was not present in a previous data leak. See the validation documentation for more details:

use Illuminate\Validation\Rules\Password;
 
Password::min(8)
->letters()
->mixedCase()
->numbers()
->symbols()
->uncompromised();
Paul Redmond photo

Staff writer at Laravel News. Full stack web developer and author.

Sponsored

laravelcloud logo
Laravel Cloud

Easily create and manage your servers and deploy your Laravel applications in seconds.

Visit Laravel Cloud

The latest

View all →
Securing Filament plugins with Plumb image

Securing Filament plugins with Plumb

Read article
LayaPHP: Self-Hosted Text Classification for PHP and Laravel image

LayaPHP: Self-Hosted Text Classification for PHP and Laravel

Read article
WhenMounted and BigInt Props in Inertia.js v3.8 image

WhenMounted and BigInt Props in Inertia.js v3.8

Read article
Postcodes for Laravel: GB Postcode Lookup and Geography Data image

Postcodes for Laravel: GB Postcode Lookup and Geography Data

Read article
Laravel 14 Adds a defaults() Method to Eloquent Models image

Laravel 14 Adds a defaults() Method to Eloquent Models

Read article
Laravel AI SDK and Laravel MCP Security Fixes: Update Now image

Laravel AI SDK and Laravel MCP Security Fixes: Update Now

Read article