[memb_set_password]

Description

Outputs a form allowing logged-in users to set a password without entering a current one.

When members need this

Most members meet this form right after their first login. If you onboard with magic links, the member signs in with a click and has no password at all. This form is where they create one: the member who wants password login from now on sets it here, and the member who's happy clicking links never has to think about it.

The distinction from [memb_change_password] matters: that form assumes a password exists and demands the current one as proof. This form assumes the opposite, that no password exists yet, and asks for nothing but the new one. Pair them on an account page: members with a password get the change form, members without get this one.

The form guides the member to a good password on its own:

  • A live strength meter (Too weak, Moderate, Strong) fills as they type, scored on length, character variety, and repetition.
  • The confirm field reports "Passwords match" or "Passwords do not match" while typing, so typos are caught before submission, not after.
  • The submit button stays disabled until the password is strong and both match, so a weak password never leaves the form.
  • Each field has a show/hide toggle, because typing the same password blind twice is error-prone and frustrating.

The strength check runs on the server too. The meter on the page is guidance; the rule is enforced again at submission, and the two always agree.

After a successful set, the member stays logged in and, if you set redirect_to, lands wherever you point them: the account page, a welcome video, the first lesson. On success a wpal/torii/set_password action fires, which developers can hook for logging or automation.

The HTML this shortcode renders comes from a template you can override in your theme. See Shortcode Templates.

Shortcode Examples

[memb_set_password]

Redirect to the first lesson after set:

[memb_set_password redirect_to="/courses/welcome/"]

Shortcode Parameters

redirect_to

Moves the member past the form to the next page they should view after setting their password. In an onboarding funnel that is whatever starts the membership: the welcome video, the first lesson, the member dashboard. Leave it empty and the member stays on the same page with a success notice. Default: ''.

Errors the form can show

Code Meaning
empty A field was left blank
login Session expired; log in again
match The two entries differ
nonce Security check failed; retry
strength Password scored below the strength floor

Shortcode Attributes

Attribute Value
Conditional No
Nestable No
Accepts formatting No

Hooks

For developers: a wpal/torii/set_password action fires after a successful password set, receiving the user ID.