Really? Wordpress uses md5 by default, which though it's salted and hashed several times it's still far less effective than the phpass in use on drupal.org and the derivative in use on D7. http://codex.wordpress.org/Resetting_Your_Password scared me when it suggested that you reset your admin password by just using an md5 generator and doesn't tell you to change your password AGAIN once you've reset it with a single md5. This scares me too: http://codex.wordpress.org/Updating_WordPress#Automatic_Upda... auto update requires web-write to your whole site. No wonder it's such an attractive target to build a super-botnet: http://technorati.com/technology/it/article/wordpress-under-...