Introduction
Discover a unique security tool for Joomla with "User - Log Bad Passwords," a reimagined plugin designed to help administrators track and manage weak or previously failed password attempts. Originally released as a package of two plugins for earlier Joomla versions, this re-release consolidates that functionality into a single, streamlined plugin—simplifying installation while retaining the same powerful features.
How It Works
Inspired by a personal revelation about password tracking, I created this plugin to empower Joomla administrators with insights by creating an extension to log bad passwords, mirroring capabilities like those Google might use. When users enter incorrect passwords, "User - Log Bad Passwords" logs them—storing only failed attempts in clear text (not a security risk since they’re known bad passwords) when that user makes a successful login attempt. If a user later adopts a logged bad password, it’s automatically cleared from the list, ensuring continuous protection.
The log appears exclusively on the user edit screen in the Joomla administrator backend, nowhere else, giving admins full control. You can configure the plugin to track bad passwords for frontend logins, backend logins, or exclude specific user groups, tailoring its scope to your needs. Installation and setup are straightforward: install the single plugin, then configure where it runs and which groups to exclude.
Ethical Considerations and Use Cases
Is this plugin unethical? That depends on its application. For a support representative on a private intranet site, it’s a valuable tool for identifying weak passwords and improving security. However, using it on public-facing sites raises ethical questions, as it could expose passwords users might reuse elsewhere. I released it as a warning, not an invitation to compromise accounts—please keep ethical opinions out of reviews, as I’m simply highlighting a possibility. If you’re concerned a site uses this plugin, check for /plugins/user/logbadpasswords/logbadpasswords.xml; if you see XML, it’s installed.
Why Choose User - Log Bad Passwords?
This plugin isn’t for every site, but for controlled environments like private intranets, it’s a game-changer. It’s an experiment in secure password monitoring, built with care, and now simpler than ever with its single-plugin re-release. Use it responsibly to enhance security, but weigh the risks carefully for public sites.
Features
- Streamlined Single Plugin: Combines previous dual-plugin functionality into one installer for easier use.
- Bad Password Logging: Tracks failed password attempts, clearing them if reused, visible only in the admin user edit screen.
- Flexible Configuration: Set to monitor frontend, backend, or exclude specific user groups.
- Ethical Awareness: Designed for controlled, private use—exercise caution on public sites.
Log Bad Passwords
- Version:
- 5.0.0
- Developer:
- Michael Richey
- Last updated:
-
Mar 04 2025
1 month ago - Date added:
- Nov 19 2014
- License:
- GPLv2 or later
- Type:
- Free download
- Includes:
- p
- Compatibility:
- J3 J5
Share