Skip to main content
Capell home
Live demo
Password Policy marketplace hero artwork.
Beta

Password Policy

Password Policy adds configurable strength, expiry, reuse-history, and compromised-password rules for Capell admin accounts.

Beta

Check compatibility before using this Beta extension

Beta does not mean production-ready. Review compatibility, support, site impact, and likely upgrade work before enabling it.

Maintenance

Release activity stays visible

These dates come from approved package releases, so you can see the release trail before installing.

Latest approved release
v1.1.0-beta.38 Sep 23, 2026
Recent activity
1 approved release in the last 12 months
Overview

What Password Policy helps you do

Licence Unavailable
Unavailable
Review site impact

Marketplace listings can describe install impact and data access.

This installs as a Composer package. Check its removal guidance and retained-data policy before uninstalling it.

This private package is outside the Released and Beta channels, so no public install path is available.

Open the live demo

Explore the available extensions on the demo site.

Standard support is included with a paid licence.

Install with Composer composer require capell-app/password-policy
Version
1.1.0-beta.38
Runs on
Capell 1.x, Laravel 12.41.1+ in the 12.x line or Laravel 13.x, PHP 8.4.
Last release
Sep 23, 2026
Support
Standard support
Data access
Uses package-local configuration and Capell metadata needed to enable the feature.
Documentation
Documentation

6 captures

Password Policy adds configurable strength, expiry, reuse-history, and compromised-password rules for Capell admin accounts.

Administrators set the policy and require selected users to change their password before continuing in the admin.

The package covers its Capell user forms and forced-change flow; custom password-writing flows need explicit integration.

Use it when an installation needs a shared password standard and a controlled way to require credential changes.

What changes on your site

Review the admin, public, data, scheduled, and command surfaces Password Policy adds when enabled.

  • Password Rules
  • Password Expiry
  • Forced Password Change
Installation impact

Before you install

Confirm version compatibility, support, data access, migrations, retained data, and removal steps first. Then install the Composer package from the account that owns access.

Support
Standard support
Data access
Uses package-local configuration and Capell metadata needed to enable the feature.
  1. 01

    Require the package

    composer require capell-app/password-policy
  2. 02

    Register the extension

    php artisan capell:extension:enable password-policy
  3. 03

    Clear schema cache

    php artisan capell:admin:clear-schemas-cache
Changelog

Release notes and maintenance evidence

Total downloads
0
Last downloaded
No downloads yet

Version history

1 release
  1. v1.1.0-beta.38
    Sep 23, 2026
Capell reviewed

Review evidence for this release

Password policy package reviewed with no defects found; complexity, reuse and expiry rules are enforced through the framework's own validation and hash comparison, with no bypass path found.

Review reduces risk, but it is not a permanent security guarantee.

Automated checks passed
AI-assisted analysis completed
Human sign-off completed
Reviewed version
1.1.0-beta.38
Approval date
Sep 22, 2026

Areas reviewed

  • Strict, maintainable PHP
  • Presentation-only public views
  • Actions and typed boundaries
  • Clean anonymous public output
  • Authorisation and input safety
  • Declared package boundaries
  • Manifest and migration integrity
  • Compatibility and interoperability
  • Meaningful behavioural tests
  • Security and supply-chain checks
  • Performance and operational behaviour
  • Theme delivery quality where applicable
  • Marketplace claims matched to behaviour
  • AI-assisted analysis with human accountability

Accepted limitations

  • Reuse history compares against a configurable number of previous hashes, so an older password beyond that window can be reused.

Before checkout

Know who owns access and what happens next

Payment, customer account ownership, site activation, and package access are separate steps. The checkout reference lets support trace a problem without moving the licence to another account.

Who processes the payment and taxes?

Lemon Squeezy is the seller and hosts paid marketplace checkout. Any VAT due is calculated and added by Lemon Squeezy at checkout, and Lemon Squeezy issues the tax receipt. Capell does not collect card details; it activates the matching marketplace licence after payment is confirmed.

Which account owns the licence?

The signed-in customer account that completes checkout owns the Capell licence, support history, and future install access. Capell surfaces a link to the tax receipt issued by Lemon Squeezy. Use the intended organisation account before paying.

How does the site receive package access?

The install flow connects the licence to the requesting site. Paid and private packages then use authenticated Composer access from the customer account that owns the licence.

What happens if checkout is cancelled or expires?

No licence is created until Lemon Squeezy confirms payment. After a cancellation or expired quote, return to the same marketplace listing and start a fresh checkout so price and package details are recalculated.

How do I request a refund?

Use the order link on the Lemon Squeezy receipt and request the refund through the Lemon Squeezy order receipt. If the receipt or order link is unavailable, contact Capell support so the payment and access record can be traced.

What should I do if access does not appear?

Keep the checkout reference from the page or receipt and contact support before trying another account. Support can trace the payment, customer account, licence, and connected site from that reference.

Review from an eligible customer

Share what happened while installing or using this extension. Sign in with an account that has bought, downloaded, or installed it before submitting.

Sign in first. Review eligibility is checked against marketplace purchase, download, or install access.

No approved reviews yet. Reviews from eligible customers appear here after moderation.

Password Policy screenshot gallery

Password Policy settings page with expiry, forced-change, complexity, compromised-password, and reuse controls