Walmart

walmart.com

Last update: February 2024

 

Grade

66/100

D

 

Grade Breakdown

Username and Password Limitations

Walmart users log in with their email address and password. Walmart has the following password requirements:

  • Between 8 and 100 characters
  • 1 upper-case letter
  • 1 lower-case letter
  • Either 1 number or special character

4/5

 

Multi-factor Authentication

Walmart only supports SMS for login MFA.

3/5

 

"Forgot Login" Flows

Walmart uses email address and password for its login. It first checks if the email address is associated with an account or not, and goes to an account creation screen if not.

Their forgot login flow actually uses two levels of MFA. It first asks for a verification code sent via email, then for another one sent via SMS. This leads to a change password page.

4/5

 

Account Change Notification

Walmart sends an email notification when the password or email address is changed. An email goes to the old email address if that is what changed. There is no notification for changed phone number, which seems significant because that is the only option for login MFA.

4/5

 

View Login History and Remote Logout

Walmart does not have a login history or remote logout feature.

0/5