Opens in a new tab
Turquoise abstract wavy W logo on a black background
Turquoise abstract wavy W logo on a black background
White WP PowerSuite logo on a black background
White WP PowerSuite logo on a black background
[wpps_ai_summarize]
On This Page
Last updated: 02/09/2026

Disable Password Reset

Turn off public "forgot password" self-service for everyone. Use only when you reset passwords another way (manual admin password, WP-CLI, or admin-sent reset links when enabled in settings). Existing email reset links stop working while this module is on.

Overview

Turn off public password recovery in WordPress when account passwords should be managed by administrators rather than through self-service reset forms.

Disable Password Reset blocks the standard WordPress and WooCommerce lost-password flows, removes public password-reset links, and prevents visitors from requesting new recovery emails. Administrators can optionally retain the ability to send password reset links directly from the WordPress Users screen, giving you centralized control without preventing legitimate account recovery.

Normal login, registration, logout, logged-in password changes, and administrator-managed password changes remain available.

Disable Password Reset is a Free security module in WP PowerSuite.

Solid black square
Solid black square
Who is this for?
  • Private WordPress sites where administrators manage user access
  • Membership and internal websites with controlled account recovery
  • Agencies managing client or staff accounts from WordPress
  • Sites that want to remove public self-service password recovery
  • WooCommerce sites with administrator-managed customer access

Features

Disable Public Password Recovery
Prevent visitors from requesting new password reset emails through WordPress's standard lost-password system.
WordPress & WooCommerce Support
Block password recovery through wp-login.php as well as WooCommerce My Account lost-password flows.
Custom Disabled Message
Display your own instructions when someone attempts to use disabled password recovery, such as directing them to contact an administrator.
No Impact on Normal Login
The module does not change how users authenticate and does not act as a login lockout system.

Take Control of WordPress Password Recovery

WordPress normally allows anyone who knows a valid username or email address to open the Lost Password form and request a password-reset email. For public websites and large membership systems, that self-service workflow is often exactly what users need.
Other websites operate differently.
An internal company website may require employees to contact an administrator for account recovery. A private portal may have tightly controlled accounts that should not initiate recovery independently. An agency-managed website may have only a handful of client accounts, making administrator-controlled recovery preferable to maintaining a public lost-password workflow.
Disable Password Reset lets you remove that public recovery path without disabling WordPress authentication itself.
Users can still sign in normally. Existing sessions remain valid. Registration is not disabled, and logged-in users can still change their own passwords where WordPress normally allows it. The module focuses specifically on preventing unauthenticated visitors from starting a new password-recovery process.

Block the Actual Recovery Flow, Not Just the Link

Simply hiding Lost your password? from the login page would not genuinely disable password recovery. Anyone who knew the standard WordPress URL could still access the underlying recovery action directly.
WP PowerSuite handles the recovery process itself.
Public password-reset permission is disabled through WordPress's password-reset controls, and direct requests to lost-password and recovery actions are redirected back to the login screen with a notice explaining that password recovery is unavailable.
Generated lost-password URLs are also changed so themes and plugins using WordPress's normal lostpassword_url mechanism do not continue directing users to a recovery form that has been disabled.
The login-screen link is removed as part of the user experience, but the actual protection comes from blocking the underlying self-service reset functionality.

Keep Administrator-Controlled Password Recovery

Disabling self-service recovery does not necessarily mean administrators should lose the ability to help legitimate users regain access.
By default, WP PowerSuite allows authorized users with appropriate user-management permissions to continue using WordPress's Send password reset action from the Users screen.
This creates a useful controlled workflow. A user who cannot access their account contacts an administrator, the administrator verifies the request according to the organization's process, and then sends the normal WordPress reset email.
The user still receives a standard secure WordPress reset link, but they cannot initiate that email themselves through a public form.
If your security policy requires password resets to be handled differently, administrator-sent reset links can also be disabled through the module settings.

When Should You Disable WordPress Password Reset?

Public password recovery is useful and should not be disabled simply because it exists.
On a public membership website with thousands of users, forcing every forgotten-password request through an administrator could create a poor user experience and significant support workload. WooCommerce stores with ordinary customer accounts may face the same issue.
Disable Password Reset makes more sense when accounts are controlled, the user population is relatively manageable, or your organization has another established recovery process.
Examples include internal company sites, private portals, controlled membership systems, staging or restricted environments, and websites where administrators deliberately manage user credentials.
The right configuration depends on how users are expected to regain access. The module gives you the control to remove self-service recovery when that matches your security and account-management model.

Use Cases

  • Internal Company Websites
    Require employees to contact an administrator instead of initiating password recovery through a public WordPress form.
  • Agency-Managed Client Websites
    Allow the agency to send verified password-reset links while removing public self-service recovery.
  • Controlled WooCommerce Accounts
    Disable customer-initiated lost-password requests when store accounts are provisioned and managed through a controlled process.
  • Restricted WordPress Environments
    Remove public password recovery while keeping normal login, administrator password management, and authenticated password changes available.

Frequently Asked Questions

Related Modules

Slow down password-guessing bots by locking out repeated failed logins for increasing cool-off periods—simple protection for your sign-in form.
Disabled
Remove the dashboard screens that let anyone edit theme or plugin code from the browser—one less disaster if an account is compromised.
Disabled
Blocks risky default usernames during registration so bots have fewer easy targets.
Disabled
Always open your dashboard and login screen over a secure https:// link. Anyone using the old http:// address is sent to the...
Disabled
Removes WordPress version from public HTML generator tags, feed generator output, and the admin footer. Does not change ver= on script and...
Disabled
Closes the old XML-RPC channel many password-guessing tools still target. Fine for most sites; skip if you rely on legacy apps or...
Disabled
Google reCAPTCHA on logins, forms, comments, and WooCommerce to block bots and spam signups.
Disabled
Two-factor login for selected roles—extra proof beyond the password.
Disabled
Ask a quick math question, custom prompt, or image check before someone can submit a form or log in. Everything runs on...
Disabled
Bot protection with Cloudflare Turnstile on logins, forms, comments, and WooCommerce—low hassle for real people.
Disabled