password is hashed not encrypted

you need to use password function to enforce password simplicity check