The Extension:Passwordstr purposely weakens user password
strengths by excluding many possible passwords from the
choices, users can make. By its regexp rules, many of which
can easily be determined automatically, brute force password
cracking automats can spare some tests and thus find passwords
faster.
We should recommend not using this kind of pseudo-wannabe-security.
Better delete the extension altogether.
Version: unspecified
Severity: major