The Joomla! Extensions Directory ™


Block Password Reset Plugin

This is a system plugin for Joomla 1.5x that makes it possible to block password resetting from the front-end of your site for selected users or user groups.

This plugin is designed to make your Joomla site more secure by preventing hackers from resetting your administrator password.

Upload and install using the Joomla installer. Remember to enable the plugin in the plugin manager. Set the individuals that you wish to block password resetting for in the plugin parameters. You can block password resetting for selected individuals listed by id, or for specific groups.

You should only use this plugin if you are confident that you will not forget your admin password, or if you have access to your site database so that you can reset your password directly in an emergency.

Please note that this does not require registration to download, there is a direct download link on the download page referenced here. You can register if you want but it is not obligatory.

Also, several people have asked for a version for Joomla 2.5. Actually this is not necessary, it is not possible to use the front-end password reset function with Joomla 2.5.

Report

2011-07-15
Reviews: 2
I learned the hard way, when a client's Joomla site was hacked using a password reset. I use this plugin on every Joomla website a create now.
2010-07-13
Reviews: 2
Should i block myself (Admin) or just registered users?
Thanks.
Owner's reply

The purpose of the plugin is to prevent your administrator password from being reset from the front-end - so you should block password resets for yourself. There is no reason why you cannot block password resets for registered users too - that would prevent them from being able to reset their own passwords, I don't see why you would want to do this, but you can.

Please note that when you block a user password reset that means that you are blocking the password from being reset for that user BY ANYONE, I think you are misunderstanding that point.