All skills
michtio avatar

/craft-plugins

@44a2800

Index and router for plugin-specific Craft CMS 5 guidance — configuration, Twig API, PHP API, migrations, deployment, and pitfalls for the plugins this pack documents. Triggers whenever a task names one of these plugins in ANY context (build, configure, style, render, query, import, migrate, deploy, cache, debug): Formie (forms, submissions, File Upload, form in a migration, notifications, translations), SEOmatic (meta, sitemaps, JSON-LD, SEO field), Blitz (static/page caching, purge), Feed Me (XML/JSON/CSV import), Imager-X (transforms, srcset, quick syntax, named transforms, Power Pack, pppicture, ppimg), ImageOptimize (OptimizedImages), CKEditor (rich text, nested entries), Sprig (reactive, htmx), Element API (JSON endpoints), Retour (redirects, 404s), Navigation (nav menus), Hyper (link field), Colour Swatches, Password Policy (HIBP), Typogrify, Cache Igniter, Knock Knock (staging password), Elements Panel (N+1 debug), Sherlock (security scan), Amazon SES (SES/SNS bounce), Embedded Assets (oEmbed), Timeloop (recurring dates), Vite (craft.vite.*, asset bundling), Warp (passwordless login, magic link, one-time code/OTP, passkeys, WebAuthn, craft.warp, member sessions). Also load for passwordless or magic-link auth with NO plugin named. Always load when a task names one of these plugins — read references/<plugin>.md first. Do NOT trigger for Craft core with no plugin named (craftcms), template architecture (craft-site), or content modeling (craft-content-modeling).

Use this Skill: https://skilld.dev/gh/michtio/craftcms-claude-skills/craft-plugins

This session only. Nothing lands on disk.

referencespassword-policy.md

≈1.3k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Password Policy

Password enforcement plugin by CraftPulse. Enforces minimum/maximum length, character requirements (uppercase, lowercase, numbers, symbols), "Have I Been Pwned" database checking, password strength indicator, and password retention/expiry with forced resets. CraftPulse's own plugin.

craftpulse/craft-password-policy — Free

Documentation

Common Pitfalls

  • Setting minLength below 6 — Craft's own minimum is 6 characters. The plugin enforces this as a floor and validation will reject lower values.
  • Enabling pwned check without considering network latency — the Have I Been Pwned API is called on every password save. For high-traffic registration forms, this adds a network round-trip. It's a security trade-off worth making, but be aware of the performance impact.
  • Enabling retentionUtilities without configuring expiryAmount and expiryPeriod — retention features need both values set to work correctly.
  • Forgetting that admin (user ID 1) is excluded from forced resets — the retention service intentionally skips the primary admin account to prevent lockout.
  • Not running retention checks on a schedule — password expiry only triggers when the retention console command or queue job runs. Set up a cron job.

Settings

All settings are configured in the CP under Settings → Password Policy, or via config file:

// config/password-policy.php
return [
    '*' => [
        // Minimum password length (floor: 6, Craft's minimum)
        'minLength' => 12,

        // Maximum password length (0 = no maximum)
        'maxLength' => 0,

        // Require mixed case (uppercase + lowercase)
        'cases' => true,

        // Require at least one number
        'numbers' => true,

        // Require at least one special character (!@#$%^&*)
        'symbols' => true,

        // Show password strength indicator in CP
        'showStrengthIndicator' => true,

        // Check password against Have I Been Pwned database
        'pwned' => true,

        // Enable password retention/expiry features
        'retentionUtilities' => false,

        // Password expiry period (amount + period)
        'expiryAmount' => 90,
        'expiryPeriod' => 'day',    // day, week, month, year

        // Generate CSP nonces for inline scripts
        'cspNonce' => false,
    ],
];

How It Works

Password Validation

The plugin registers custom validation rules on the User element via DefineRulesEvent. When a user sets or changes their password, the rules enforce:

  1. Length — minimum (and optional maximum) character count
  2. Character requirements — mixed case, numbers, symbols (based on settings)
  3. Pwned check — queries the Have I Been Pwned API using k-anonymity (only the first 5 chars of the SHA-1 hash are sent, never the full password)

The validation pattern is generated dynamically from the enabled settings — only active rules are included in the regex.

Password Strength Indicator

When showStrengthIndicator is enabled, the CP shows a visual strength meter on password fields. This gives editors real-time feedback while typing.

Password Retention

When retentionUtilities is enabled:

  • A CP utility page shows retention status and allows manual forced resets
  • Expired passwords trigger passwordResetRequired = true on the user
  • Users must change their password on next login
  • The primary admin (user ID 1) is always excluded from forced resets

Console Commands

# Force reset all expired passwords (queue job)
ddev craft password-policy/retention/force-reset-passwords

# Force reset with --queue flag (queue only, don't run immediately)
ddev craft password-policy/retention/force-reset-passwords --queue

Set up a cron job for automatic retention checking:

# Check daily at 2am
0 2 * * * cd /var/www/html && php craft password-policy/retention/force-reset-passwords --queue

Architecture

Service Responsibility
PasswordService Generates validation regex pattern and error messages from settings
RetentionService Handles password expiry checks, forced resets via queue jobs
SecurityService Security-related utilities
PwnedValidator Queries Have I Been Pwned API with k-anonymity

Events

The plugin hooks into Craft's user lifecycle via:

  • User::EVENT_DEFINE_RULES — adds password validation rules
  • View::EVENT_BEFORE_RENDER_PAGE_TEMPLATE — injects strength indicator JS
  • Plugins::EVENT_AFTER_INSTALL_PLUGIN — initial setup

Recommended Settings

For most projects:

'minLength' => 12,
'maxLength' => 0,          // No max — let password managers generate long passwords
'cases' => true,
'numbers' => true,
'symbols' => false,        // Controversial — NIST guidelines no longer recommend
'showStrengthIndicator' => true,
'pwned' => true,           // Always enable — negligible performance cost
'retentionUtilities' => false, // Enable only if compliance requires it

Pair With

  • Sherlock — security scanning and monitoring alongside password enforcement

Source: SKILL.md on GitHub

No alerts16d3 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The 'craft-plugins' skill is a technical reference and router for Craft CMS 5 plugins. It provides guidance on configuration, Twig and PHP APIs, and best practices for popular extensions in the Craft ecosystem. The skill consists of documentation files that describe legitimate plugin behaviors and does not contain any malicious code, obfuscation, or security vulnerabilities.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

Signed by skilld at 44a2800. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 weeks ago.

Activeupdated last month

README badge

README badge for michtio/craftcms-claude-skills/craft-plugins