Skip to content

Password Validation with PHP and Regular Expressions

· 2 min read · Updated

Regular-Expressions are equally complicated and elegant at the exact same time. They may be made to look like someone was only hammering randomly on their keyboard. They’re also a remarkably effective and elegant solution to describing the structure of the text and fitting those structures.

They’re very handy for defining what a string should look like and as such are very great to be used in password validation. It’s essential that the password needs to be validated With safe & strength for security. So Make it difficult for password crackers. Use long passwords with letters, CAPS, numbers, and symbols. Let’s check a password validation with PHP and regular expressions. That is a straightforward and long example for beginners.

$password = $_POST['password'] ?? '';
$error = '';

if (strlen($password) < 8) {
    $error .= "Password too short!<br>";
}
if (strlen($password) > 20) {
    $error .= "Password too long!<br>";
}
if (!preg_match("#[0-9]+#", $password)) {
    $error .= "Password must include at least one number!<br>";
}
if (!preg_match("#[a-z]+#", $password)) {
    $error .= "Password must include at least one letter!<br>";
}
if (!preg_match("#[A-Z]+#", $password)) {
    $error .= "Password must include at least one CAPS!<br>";
}
if (!preg_match("#\W+#", $password)) {
    $error .= "Password must include at least one symbol!<br>";
}

if ($error) {
    echo "Password validation failure (your choice is weak): $error";
} else {
    echo "Your password is strong.";
}

Short example with Regex

This is the short version of that password -check with regex(lookahead / lookbehind / lookaround) using PHP’s PCRE engine.

$password = $_POST['password'] ?? '';

if (preg_match("#.*^(?=.{8,20})(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*\W).*$#", $password)) {
    echo "Your password is strong.";
} else {
    echo "Your password is not safe.";
}

You may use \d instead of [0-9], and \W to match any non-word character (a symbol). You can make a manual list of most used symbols like [#.-_,$%&!].

Remember most consumers don’t enjoy passwords with symbols, you can exclude emblem checks for. Just check letters, duration, caps, and numbers.

$password = $_POST['password'] ?? '';

if (preg_match("#.*^(?=.{8,20})(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9]).*$#", $password)) {
    echo "Your password is good.";
} else {
    echo "Your password is bad.";
}

End of note

No. A770

Thanks for reading.

2 min read · Filed under PHP. Questions or corrections? Say hello. I read everything.