• It would be nice if the “Reset All Passwords” feature would have an option to opt out of immediately emailing all users, instead have the email reset link sent after the user successfully logs in. Currently the way the plugin blasts all users with the a reset link, many would think it’s some sort of a phishing scam and just ignore it.

    Also, It would be nice if the plugin would have the optional option to have the site administrator be emailed as soon as an IP gets banned.

    https://ww.wp.xz.cn/plugins/apocalypse-meow/

Viewing 3 replies - 1 through 3 (of 3 total)
  • Plugin Author Blobfolio

    (@blobfolio)

    The current reset tool is there as an OH GOD NUKE EVERYTHING feature. Basically you’d want to use it when you can no longer trust that the existing logins haven’t been compromised. In such cases, we can’t leave passwords as-were because then a badguy could still log in.

    But I see your point about the email volume. Maybe a good middle ground is to make the email notifications optional? People could then just stand up and shout to the office at large or compose messages manually and send from a different account.

    Thread Starter Alpha01

    (@openalpha01)

    I see your point. Maybe instead of the current OH GOD NUKE EVERYTHING aproach, perhaps have the option to only reset the password after the user successfully logs in for the first time and email the information only after the “Reset All Passwords” has been triggered.

    At this point, even if the passwords were left as-were, the badguy won’t be able to login. The only way for a badguy at this point to take full control is to also have access to the email account used by the registered user.

    Plugin Author Blobfolio

    (@blobfolio)

    It’s a good idea. I’ll play around with it and see.

Viewing 3 replies - 1 through 3 (of 3 total)

The topic ‘Additional Suggested features’ is closed to new replies.