21 Responses

  1. The Frosty
    The Frosty January 19, 2012 at 7:28 pm | | Reply

    That’s an interesting plugin, what circumstances would you need this in?

  2. Beth
    Beth January 20, 2012 at 2:52 am | | Reply

    Whoa, now this is interesting. I, too, am wondering what circumstance one could find themselves in where they wouldn’t want to be able to reset their PW to their WP, but I’m gonna go ahead and bet that there’s a very specific one in mind here. Really interesting add-on idea, looking forward to your answer! Thanks in advance!

  3. Stefan
    Stefan January 20, 2012 at 8:27 am | | Reply

    Is this restriction related to security?

  4. Review: CutePress | Open Knowledge January 20, 2012 at 1:56 pm |
  5. Bovespa
    Bovespa January 20, 2012 at 2:32 pm | | Reply

    can you explain. why?

    Why i need this?

  6. Geert Verschaeve
    Geert Verschaeve January 23, 2012 at 10:35 am | | Reply

    Thx Justin, I was looking for something similar!

    Bovespa, it is used to prevent fraud and bad behavior. Like Justin said it can become rather annoying when someone else keeps trying to reset your admin password, when you are the admin…

  7. Alex Capul
    Alex Capul January 25, 2012 at 4:33 pm | | Reply

    Great job Justin! Works like a charm. Cheers!

  8. Ashlife
    Ashlife January 30, 2012 at 9:08 am | | Reply

    great plugin, can there be like a option where the admin can choose which members should not be allowed to change password this way. ?

  9. Azman
    Azman February 5, 2012 at 10:41 pm | | Reply

    Interesting plugin.
    few days ago i experience a strange wp error. the reset email cannot be sent out. interestingly enough, I managed to reset the pw through the database. not that difficult though.

  10. Tuan
    Tuan February 6, 2012 at 9:56 am | | Reply

    This is a nice plugin but I don’t get its idea. What other users will do when they forget password and why do we need to prevent password reset?

  11. Cx Rana
    Cx Rana March 2, 2012 at 7:02 am | | Reply

    Hhahaha.. It’s really cool plugin for new and expencive webmaster…..

  12. Curtis
    Curtis March 5, 2012 at 10:21 pm | | Reply

    I agree. Can the Option be an admin only checkbox. But still a great plugin

  13. Chris
    Chris March 7, 2012 at 9:53 pm | | Reply

    I can see the usefulness of this when you’d like to prevent people with bad intentions from trying to reset your password – but then what do you do when you or a legitimate admin forgets their password?

    I guess you better hope another admin can help you out, eh?

  14. Luke
    Luke March 13, 2012 at 3:16 pm | | Reply

    Depending on whether or not your Wordpress site would be subject to internal control audits (like a SAS70), this is a security issue that could trip a negative report. The idea is that you should not be able to compromise an administrative account of one system (in this case Wordpress) by hacking what might be a non-administrator account of a potentially less secure system like email.

    If I can see/control your email, I can steal your password simply by forcing the password reset email to be sent. Then I view/intercept your email depending on how badly I’ve compromised your system, use the link to reset the password and gain control of your administrative account. By failing to adequately address this security issue, it can put you in a state of non-compliance with several different US regulations depending upon the industry you serve and the information you store about your non-admin users.

  15. vinu
    vinu March 31, 2012 at 6:40 pm | | Reply

    Thank you very much for this tip. I guess this feature would be good for admins due to the majority of word press hacking that is prevalent these days.

  16. Bharat Chowdary
    Bharat Chowdary April 2, 2012 at 3:24 pm | | Reply

    This plugin helps to provide an extra bit of security. Thanks Justin.

  17. Neunoteam
    Neunoteam April 10, 2012 at 8:53 am | | Reply

    Dear, Justin. Great plugin!!

    TIP: Add an option in user profile to disable password change. Very usefull!!

Leave a Reply

By submitting a comment here you grant this site a perpetual license to reproduce your words and name/Web site in attribution.

Please use your real name or a pseudonym (i.e., pen name, alias, nom de plume) when commenting. If you add your site name, company name, or something completely random, I'll likely change it to whatever I want.