Disabling User Accounts

If your website allows for free accounts registration, and gives your user ability to edit their account, you will be subject to massive spam registrations. Bots or spam user will register new accounts for the ability to post spam content inside the account description and post spam website URL too.

coreSecurity Pro has a Registration Control feature that will be able to handle a lot of spam or bots registrations. But, this is not a magic bullet that will stop all such registrations, a lot of spam accounts are registered by real people and they are better to avoid the automated filters will be able to use emails in good standing. And, if you only recently started using coreSecurity Pro, you may already have thousands of spam accounts that you would like to handle in some way.

Disabling accounts is usually better solution than just removing them. Once the account is removed, email and username for that deleted account are free again, and same person can register new account again. Disabling account leaves the account in the database, and the username and email for that account can’t be used again. Disabled account will not be allowed to login or reset password, and it can be even hidden from the frontend completely.

How accounts disabling works

coreSecurity Pro integrates into Users panels in WordPress. It will add a action ‘Control’ for each user account, and will also add new options into the Bulk actions dropdown.

Individual Accounts Control

If you click the ‘Control’ action for one account, you will get a new dialog opened. If the user is Enabled, the Activity radio control will be set to Enabled. When you change the radio to Disabled, you will see a long list of options related to disabling of the account.

Dialog to Disable User Account
Dialog to Disable User Account

Here is the list of options you can apply to the disabled account:

  • Reason for disabling the account: this will be saved into the database as a reminder why you wanted to disable the account.
  • Replace current account password: you can have a random password generated to replace the current account password, as a security measure. If you later enable the account, user will need to reset the password first.
  • Delete description and website URL: since the most spam account will have spam inserted into description and website URL, when you disable the account, you can remove both of these.
  • Add email to the ban list: if you later decide to remove the account, this will put email into the dictionary, and no account will be allowed with that email.
  • Add username to the ban list: if you later decide to remove the account, this will put username into the dictionary, and no account will be allowed with that username.
  • Add email domain to the ban list: if added to the ban list, no user account will be allowed from the banned domain. Be careful with this option!
  • Send user notification: if you want, you can inform the user about their account being disabled. If you want to do that, make sure to add the notice about the reason for the account disabling, and that notice will be sent to the user account email address.

If user account is already disabled, dialog shows only one option, to notify user about account activation.

Dialog to Enable User Account
Dialog to Enable User Account

Bulk Accounts Disable/Enable

Very important to this whole process is the ability to disable multiple accounts all at once, and again, enable multiple accounts at once. This can be achieved with the use of bulk options.

Bulk Disable and Enable options
Bulk Disable and Enable options

To use these options, select accounts in the list by using checkboxes, open the Bulk actions dropdown and select option to Disable or Enable accounts. Click on Apply button, and again the popup dialog will be displayed with all the same options as single account control dialog, listing all the accounts that will be affected by the Disable or Enable action.

Important Notices

  • If you use multisite network installations, disabled accounts are disabled across all the blogs in the network.
  • WordPress has no method to disable an account. Control of disabled accounts is done by coreSecurity. If you stop using coreSecurity, disabled accounts will be allowed to login again.
Rate this article
0
0
2523

You are not allowed to rate this post.

Leave a Comment

0
0
0
1
0
0
0
0
0