Let PHP generate the salt automatically. PASSWORD_DEFAULT is designed to evolve, so store hashes in a column that can comfortably grow, such as VARCHAR(255).
<?php
$password = 'correct horse battery staple';
$hash = password_hash($password, PASSWORD_DEFAULT);
echo $hash;
?>Current example first; the detailed tutorial examples below are retained for additional learning and comparison.
$str="plus2net.com";
$str_hash=password_hash($str,PASSWORD_DEFAULT);
echo $str_hash;
Output is here $2y$10$/r1bsR9lXZ52gYPmeH69Bu3.k0ABji7ZJdiZTPmUWEAgaQpkBkfKq
Syntax
password_hash('$string',$alog,$options);
| Parameter | DESCRIPTION |
|---|---|
| $string | Required : Input password string variable |
| $alog | Required : algorithms to be used. |
| $options | Optional : An associative array containing options. |
salt : has to be minimum 22 char length. If not given then default salt will be used. Salt option is removed in PHP 7.0 so better not to use salt and allow PHP to use default salt. cost : bcrypt cost is configurable and depends on the PHP version and hardware. PHP 8.4+ uses 12 as the default bcrypt cost.
$str="plus2net.com";
$options = array('cost' => 12);
$str_hash=password_hash($str,PASSWORD_DEFAULT,$options);
echo $str_hash;
Output will be a bcrypt hash whose salt is generated automatically by PHP.
Author & Instructor at plus2net
I write and maintain practical tutorials on Python, PHP, SQL, JavaScript, HTML, jQuery, and web development at plus2net. The tutorials focus on clear explanations, working examples, and code that readers can test and adapt while learning.