edit: To further make the case, I just ran your password requirements against the input file. The most popular password that meets your requirements is some variation of "p@ssw0rd" -- usually "P@ssw0rd", but "P@ssw0rd123", "P@ssw0rd$", and so on are all popular too. Direct variations of "p@ssw0rd" (where the user only changed the capitalization of one letter) occur 47 times in the input file. For comparison, the index file contains every password that occurs at least 5 times...
Other popular combinations that meet your requirements are l58jkdjp!(46 times), !qaz2wsx (39), 1qaz!qaz (37), 1qaz@wsx (18), !qazxsw2 (16), zaq!2wsx (15), nick1234-rem936 (12), xxpa33bq.adna (11), !qaz1qaz (11), g00dpa$$w0rd (11), jhon@ta2011 (10), nloq_010101 (9), 1qazzaq! (9), pa$$w0rd (8)...
Meanwhile a nice long passphrase, which doesn't occur at all in the input file, is not allowed according to your requirements unless the user also throws in a special character and a number and an uppercase letter and a lowercase letter.