wp_authenticate_email_password( WP_User|WP_Error|null $user, string $email, string $password ): WP_User|WP_Error
- Since
- 4.5.0
- Source
wp-includes/user.php:242
Parameters
$userWP_User|WP_Error|null- WP_User or WP_Error object if a previous callback failed authentication.
$emailstring- Email address for authentication.
$passwordstring- Password for authentication.
Return
WP_User|WP_Error- WP_User on success, WP_Error on failure.
Cost profile
Measured from the compiled opcodes, not from a stopwatch. Every number here is identical on any machine that runs the same PHP version, and every function in core is ranked by these figures.
- Cost class
- Heavy
- Scaling
- Constant
- Instructions
- 6–67
- Plugin surface
- 1 hook
- Called by
- 0
Reaches the database via get_user_by().
No loop in the body: the same number of instructions runs whatever you pass in.
Executed per call on PHP 8.4, depending on the branch taken. The body compiles to 121.
Third-party callbacks on 'wp_authenticate_user' run inside this call, and their cost is not bounded by anything here.
Nothing in core calls this; the cost is only what you spend yourself.
What it touches
- querycontent query
get_user_by()called directly - hookthird-party callbacks
apply_filters()called directly
Further down the call graph this can also reach option, cache, serialize and transient — those are the worst case, several calls deep and usually down an error path, not what a normal call pays.
What one call costs · 10 distinct outcomes
One number would be a lie: the work depends on which branch runs. These are every distinct cost wp_authenticate_email_password() can have, taken from its control-flow graph on PHP 8.4.
| When | Instructions | Calls it makes |
|---|---|---|
$user instanceof | 6 | none |
!($user instanceof) | 12–21 | is_wp_error() |
!($user instanceof) && !empty($email) && !empty($password) && !is_email() | 14 | is_email() |
!($user instanceof) && !is_wp_error() | 26–28 | is_wp_error()__()->add() |
!($user instanceof) && !empty($email) && !empty($password) && is_email() | 27 | is_email()get_user_by()__() |
!($user instanceof) && !empty($email) && !empty($password) && is_email() && is_wp_error() | 30 | is_email()get_user_by()apply_filters()is_wp_error() |
!($user instanceof) && empty($email) && !is_wp_error() && empty($password) | 33–35 | is_wp_error()__()->add()__()->add() |
!($user instanceof) && !empty($email) && !empty($password) && is_email() && !is_wp_error() && !wp_password_needs_rehash() | 50 | is_email()get_user_by()apply_filters()is_wp_error()wp_check_password()wp_password_needs_rehash() |
!($user instanceof) && !empty($email) && !empty($password) && is_email() && !is_wp_error() && wp_password_needs_rehash() | 56 | is_email()get_user_by()apply_filters()is_wp_error()wp_check_password()wp_password_needs_rehash()wp_set_password() |
!($user instanceof) && !empty($email) && !empty($password) && is_email() && !is_wp_error() | 67 | is_email()get_user_by()apply_filters()is_wp_error()wp_check_password()__()esc_html()sprintf()wp_lostpassword_url()__() |
Across PHP versions
| PHP | Compiled | Executed | Branches | Notes |
|---|---|---|---|---|
7.4 | 121 | 6–67 | 11 | Compiles to the same instructions |
8.1 | 121 | 6–67 | 11 | Compiles to the same instructions |
8.2 | 121 | 6–67 | 11 | Compiles to the same instructions |
8.3 | 121 | 6–67 | 11 | Compiles to the same instructions |
8.4 | 121 | 6–67 | 11 | Compiles to the same instructions |
Oldest PHP that compiles this body: 7.4. An instruction is not a fixed amount of time, so a version with the same count is not necessarily the same speed; what the count rules out is a difference in the work itself.
Hooks fired · 1
One hook fires while wp_authenticate_email_password() runs, in this order:
- apply_filters( wp_authenticate_user )filterline 285 (+43 into the body)
Filters whether the given user can be authenticated with the provided password.
Uses · 11
- is_wp_error()Checks whether the given variable is a WordPress Error.
- __()Retrieves the translation of $text.
- is_email()Verifies that an email is valid.
- get_user_by()Retrieves user info by a given field.
- apply_filters()Calls the callback functions that have been added to a filter hook.
- wp_check_password()Checks a plaintext password against a hashed password.
- esc_html()Escaping for HTML blocks.
- wp_lostpassword_url()Returns the URL that allows the user to reset the lost password.
- wp_password_needs_rehash()Checks whether a password hash needs to be rehashed.
- wp_set_password()Updates the user's password with a new hashed one.
- WP_Error::__construct()Initializes the error.
Source
function wp_authenticate_email_password( $user, $email, #[\SensitiveParameter] $password) { if ( $user instanceof WP_User ) { return $user; } if ( empty( $email ) || empty( $password ) ) { if ( is_wp_error( $user ) ) { return $user; } $error = new WP_Error(); if ( empty( $email ) ) { // Uses 'empty_username' for back-compat with wp_signon(). $error->add( 'empty_username', __( '<strong>Error:</strong> The email field is empty.' ) ); } if ( empty( $password ) ) { $error->add( 'empty_password', __( '<strong>Error:</strong> The password field is empty.' ) ); } return $error; } if ( ! is_email( $email ) ) { return $user; } $user = get_user_by( 'email', $email ); if ( ! $user ) { return new WP_Error( 'invalid_email', __( 'Unknown email address. Check again or try your username.' ) ); } /** This filter is documented in wp-includes/user.php */ $user = apply_filters( 'wp_authenticate_user', $user, $password ); if ( is_wp_error( $user ) ) { return $user; } $valid = wp_check_password( $password, $user->user_pass, $user->ID ); if ( ! $valid ) { return new WP_Error( 'incorrect_password', sprintf( /* translators: %s: Email address. */ __( '<strong>Error:</strong> The password you entered for the email address %s is incorrect.' ), '<strong>' . esc_html( $email ) . '</strong>' ) . ' <a href="' . wp_lostpassword_url() . '">' . __( 'Lost your password?' ) . '</a>' ); } if ( wp_password_needs_rehash( $user->user_pass, $user->ID ) ) { wp_set_password( $password, $user->ID ); } return $user;}History
Introduced in 4.5.0. Unchanged from 6.7.7 through 7.1.0.
Signature, return type and hooks compared across 5 parsed releases.
About this page
- Parsed data
- Generated from the wordpress-develop 6.9.7 tag, from
src/wp-includes/user.php, and regenerated for each WordPress release so it tracks the code rather than a snapshot of it. - Corrections
- Something wrong on this page? Report it and it gets fixed in the next regeneration.