Disable Password Reset Extended Security & Risk Analysis

wordpress.org/plugins/disable-password-reset-extended

This plugin is used to completely disable the built-in password reset feature in WordPress. Used for high-security purpose ONLY.

20 active installs v1.0 PHP + WP 2.7+ Updated Aug 29, 2011
disablepasswordreset
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Disable Password Reset Extended Safe to Use in 2026?

Generally Safe

Score 85/100

Disable Password Reset Extended has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 14yr ago
Risk Assessment

The "disable-password-reset-extended" v1.0 plugin exhibits a seemingly strong security posture based on the provided static analysis. The absence of any identified dangerous functions, SQL queries not using prepared statements, file operations, external HTTP requests, or outputting unescaped data are all positive indicators. The plugin also correctly avoids critical issues such as unsanitized taint flows and has no known vulnerabilities in its history. The limited attack surface is also a good sign, with no AJAX handlers, REST API routes, or shortcodes exposed without authentication checks.

However, the complete lack of any logged security-relevant events (AJAX, REST API, shortcodes, cron, nonces, capability checks) raises a significant concern. While it suggests the plugin might be very narrowly focused or operate entirely passively, it also means that critical security checks like nonce and capability checks are entirely absent from its design. This could indicate a superficial implementation where these vital security layers were simply not deemed necessary, or worse, were omitted due to oversight. This absence of standard security mechanisms, even with a zero attack surface, introduces an unknown risk if the plugin's functionality were to ever expand or interact with user input in a more complex manner in future versions.

In conclusion, the plugin is currently secure due to its limited functionality and the absence of known vulnerabilities and obvious code flaws. However, the complete lack of standard security implementations like nonce and capability checks is a significant weakness that could become a problem if the plugin's scope changes. The plugin is best described as passively secure, rather than actively robust.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Disable Password Reset Extended Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Disable Password Reset Extended Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Disable Password Reset Extended Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
filterallow_password_resetdisable-password-reset-extended.php:13
filtershow_password_fieldsdisable-password-reset-extended.php:14
filtergettextdisable-password-reset-extended.php:23
actionlogin_headdisable-password-reset-extended.php:25
filterlogin_errorsdisable-password-reset-extended.php:32
Maintenance & Trust

Disable Password Reset Extended Maintenance & Trust

Maintenance Signals

WordPress version tested3.2.1
Last updatedAug 29, 2011
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings1
Active installs20
Developer Profile

Disable Password Reset Extended Developer Profile

Pascal Meunier

1 plugin · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Disable Password Reset Extended

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Disable Password Reset Extended