该插件尚未通过WordPress的最新3个主要版本进行测试。 当与较新版本的WordPress一起使用时,可能不再受到维护或支持,并且可能会存在兼容性问题。

Emergency password reset

描述

This plugin does 3 things
1) It will check you don’t have a username called “admin” which is asking to be hacked
2) It will allow you to reset all passwords, with an password reset link sent to all users to warn them.
Following a couple of reviews from v7.0 the plugin will allow you to set the email from address, name, subject and message
3) You can also change the SALTS which forces a logout of all users.

屏幕截图

安装

  1. 将emergency-password-reset目录上传至/wp-content/plugins/目录。
  2. 通过 WordPress 的“插件”菜单以激活本插件。
  3. 点击用户菜单中的紧急密码重置。
  4. Adjust the settings as required
  5. 点击“重置密码”按钮。

常见问题

它是如何工作的?

当您点击重置密码时,插件会为每个用户重新创建随机密码,并通过重置密码链接发送给他们。

Will I be secure now from a hack?

Not necessarily. We advise you change your SALTS in the wp-config.php file which will force logouts for all users. WordPress provide a tool to generate new ones.
You can now reset them automatically from the plugin Dashboard>Settings>Reset SALTs
Check out our blog post on hacked WordPress sites

评价

2022 年 3 月 6 日
Does it work? Yes. Those subscribed to my Wordpress blog got emails asking them to reset their passwords. But… 1) I was not able to set the text or add to it. The outgoing message looked like spam. The subject was okay: Password reset for [website] The body was not. It only said: We have had to reset your password on [website]. Your username is still [username], please reset your password Thanks. Had I been able to add a personal message, my legit users (a tiny percentage of the total; the rest being bot accounts) would have known it came from me. 2) I was not able to set the From address. It didn't even go from my address at that website. Rather, it went from my primary email address. 3) Gmail looked at the large volume of emails that went out and blocked me. (And/or people who received the emails marked them as spam.) It's been a week and I can not send any mail to gmail users (all gmail users, not just ones the email went to). I am deleting this plugin and never ever using it again.
2022 年 2 月 18 日
This plugin does what it says it does. I used it after we found malware in one of the sites I migrated into my Multsite WP install. All passwords where reset and the "Password reset" email was sent to the users. Definetly helped fixing this emergency. Thanks!
2021 年 4 月 15 日
Or, if it crashes, some. I'd rate it higher if you could reset passwords for only a group at a time, instead of literally every single account that has ever been made on your website. That's sending over 2000 (useless) emails for companies using things like woocommerce!
2019 年 1 月 24 日
As we all know our members may get lazy with maintaining (updating) their passwords. This really is a nice simple way of resetting everyone's password. I have about 100 user accounts and all of my members were able to quickly and easily change their password. The Password Reset Link they receive in their email is really great! One of the other benefits of this plugin is it quickly helps you identify user accounts with defunct email addresses. I simply deleted these accounts thereby forcing users with outdated email accounts to re-register. A couple of suggestions: #1. Reset All Passwords in the morning. This gives users enough time to reset their passwords before the link expires. #2. When installing the plugin, add the following css code to your Customizer's Custom CSS. This will nudge your users to choose strong passwords. Note – install this css code before resetting all passwords. .pw-weak { display: none !important; } I will use this plugin to force all of my members to change their passwords on an annual basis. Great job Andy!
阅读所有12条评价

贡献者及开发者

「Emergency password reset」是开源软件。 以下人员对此插件做出了贡献。

贡献者

更新日志

9.4

  • Extra step added for resetting SALTS

9.3

  • Adjusted menu to manage_option role only (was administrator before)

9.2

  • Fix not all users password changed

9.1

  • Security audit and update

9.0

  • Check nonce for settings change to prevent CSRF

8.0

  • Emails sent in batches of 10 as BCC, to avoid crashes and email errors

7.0

  • Setttings to change email name, from and message

6.2

  • Translation ready

6.1

  • New username when changing from “admin” properly sanitized.

6.0

  • Don’t allow a user to reset admin username to empty field!

5.0

  • Added WordPress reset “salt keys” to secure your site – Dashboard>Settings>Reset SALTs

4.0

  • Updated deprecated functions

3.0

  • 更新重置链接

2.0

  • 密码重置链接已发送。

1.0

  • Sends link to reset password page rather than new password

0.5

  • Form to change username from “admin”

0.4

  • Shows WP 4.0 compatability

0.3

  • 增加了截图。

0.2

  • 正确标题在readme.txt!

0.1

  • 首次发布