From that list, the first one mentioned is the worst of the bunch. "8) A password cannot be too similar to a previous password.”
How can you possibly know this without storing the password in plain text or without storing something in the database that reveals critical information about the pattern?