Lyzerslab

What's new in v4.6.0

Account hygiene audit

The Account Hygiene dashboard card (Pro) reviews every unblocked account holding a privileged group — Super Users plus Administrator/Manager by Joomla's default titles — and flags three kinds of risk:

  • Missing two-factor method — the account has no MFA enrolled.
  • Default username — still called admin or administrator.
  • Dormancy — never logged in at all, or no login within the dormancy threshold (default 180 days).

Threshold

Set the dormancy window on the card itself (up to 3650 days). 0 disables the age-based check — never-logged-in accounts are still always flagged. The setting saves with the component's own hardening parameters.

Read-only by design

The audit never writes, never blocks, never reverts: blocked accounts are skipped entirely (they can't log in, so they're not live risk), and each flagged row links to Users → Manage for you to act on. It complements the protected-users snapshot watcher, which auto-reverts demotions/blocks of snapshotted Super Users — this card is the static review, that watcher is the live guard.

Joomla 3

Identical on the Joomla 3 edition (v2.3.0), same Pro gate and threshold behavior.