# How to Configure Word Length Filtering in cupp.cfg for Password Generation

> Learn to configure word length filtering in cupp.cfg using wcfrom and wcto for custom password generation. Optimize your password creation process today.

- Repository: [Mebus/cupp](https://github.com/Mebus/cupp)
- Tags: how-to-guide
- Published: 2026-07-01

---

**Set the `wcfrom` and `wcto` parameters in the `[Word length shaping]` section of [`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg) to define the minimum and maximum character limits for words used in password generation.**

The CUPP (Common User Passwords Profiler) tool, maintained in the `Mebus/cupp` repository, uses a central configuration file to control how it transforms input words into potential passwords. Configuring word length filtering in [`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg) allows you to constrain the generator to words within specific size boundaries, ensuring output passwords meet your target length policies.

## Understanding the Word Length Shaping Section

In [`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg), the `[Word length shaping]` block contains two critical parameters that control which words enter the password generation pipeline. According to the source configuration at lines 49–55, these settings establish a closed interval `[wcfrom, wcto]` that filters the input wordlist before permutation begins.

- **`wcfrom`** – Defines the **minimum word length** in characters. Words shorter than this value are excluded from the generation process.
- **`wcto`** – Defines the **maximum word length** in characters. Words exceeding this length are discarded.

When CUPP executes, it reads these values from [`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg) and applies them as a pre-filter in [`cupp.py`](https://github.com/Mebus/cupp/blob/main/cupp.py) before applying mutations and concatenations.

## Editing cupp.cfg Parameters

### Setting the Minimum Word Length (wcfrom)

Locate the `wcfrom` entry in the `[Word length shaping]` section of [`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg). This integer value represents the shortest word length the generator will accept. For security policies requiring passwords of at least 8 characters derived from base words, set this to 8.

### Setting the Maximum Word Length (wcto)

Similarly, configure `wcto` to cap the upper bound of word lengths. This prevents excessively long dictionary entries from creating unwieldy password candidates. A typical enterprise configuration might set this to 16 to balance complexity with memorability.

## Practical Configuration Examples

You can modify these parameters using any text editor or automated scripting tools. Here is a shell command that updates both values in place using `sed`:

```bash

# Update cupp.cfg to accept only words between 8 and 16 characters

sed -i \
  -e 's/^wcfrom=.*/wcfrom=8/' \
  -e 's/^wcto=.*/wcto=16/' \
  cupp.cfg

```

After updating the configuration, execute CUPP with your target wordlist:

```python

# Generate passwords respecting the new length constraints

python cupp.py -i input_wordlist.txt -o generated_passwords.txt

```

The generator will now only process words whose length falls between 8 and 16 characters, applying transformations exclusively to words within that range.

## How the Filter Works in cupp.py

The [`cupp.py`](https://github.com/Mebus/cupp/blob/main/cupp.py) script reads the [`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg) file at initialization and parses the `[Word length shaping]` section into runtime variables. As it iterates through the input wordlist, it performs a length check against the `wcfrom` and `wcto` values before adding words to the permutation buffer. This filtering occurs early in the pipeline, improving performance by excluding irrelevant words before computational transformations begin.

## Summary

- **Word length filtering** in CUPP is controlled by the `wcfrom` and `wcto` parameters in [`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg).
- The `[Word length shaping]` section defines a closed interval `[wcfrom, wcto]` that filters input words.
- Configure `wcfrom` to set the minimum word length and `wcto` to set the maximum word length.
- Changes take effect immediately when running `python cupp.py` with the updated configuration file.

## Frequently Asked Questions

### What is the default word length range in cupp.cfg?

The default values in the repository's [`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg) typically set `wcfrom` to a lower single-digit number and `wcto` to a moderate upper limit around 20 characters. Consult the specific lines 49–55 in your version of [`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg) to verify the current defaults, as these may vary by release.

### Can I disable word length filtering entirely?

While there is no explicit "disable" flag, you can effectively bypass filtering by setting `wcfrom` to 1 and `wcto` to a very high number (such as 999). This ensures virtually all words in your input list pass the length check, though this is generally not recommended for targeted password generation.

### How does word length filtering affect password complexity?

Restricting word lengths to a narrower range (e.g., 8–12 characters) typically produces more predictable passwords, while a wider range increases entropy. However, filtering out very short words (under 8 characters) is a security best practice, as excessively short base words generate weaker passwords even after permutation.

### Where is the word length configuration located in cupp.cfg?

The word length settings are located in the `[Word length shaping]` section, which appears around lines 49–55 in the standard [`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg) file from the `Mebus/cupp` repository. This section contains the `wcfrom` and `wcto` key-value pairs that control the length boundaries.