Creating password validation endpoint as a extension

Hi,

I am developing a validation endpoint as a plugin. There is only one thing I could not handle: I have a “not recently used password policy”, How can I check that the incoming password is not one of the 3 last used passwords?