What are some best practices for securely storing and managing passwords in a PHP application, especially within a content management system (CMS)?

Storing passwords securely in a PHP application, especially within a CMS, is crucial for protecting user data. One best practice is to use a secure hashing algorithm like bcrypt to hash passwords before storing them in the database. Additionally, it's important to never store passwords in plain text or use weak hashing algorithms like MD5 or SHA-1.

// Hashing a password using bcrypt
$options = [
    'cost' => 12,
];

$password = 'user_password';
$hashed_password = password_hash($password, PASSWORD_BCRYPT, $options);

// Verifying a password
$entered_password = 'user_password';
if (password_verify($entered_password, $hashed_password)) {
    // Password is correct
} else {
    // Password is incorrect
}