Skip to main content
Drupal is a registered trademark of Dries Buytaert
Release: OpenID Connect / OAuth client 3.0.0-alpha9 New alpha version released for module openid_connect (3.0.0-alpha9). Usage Milestone: Google Analytics Module google_analytics crossed 1,000 active installs. Release: Timelinr 1.0.1 Minor update available for module timelinr (1.0.1). Release: GraphQL Compose Codegen 1.1.2 Minor update available for module graphql_compose_codegen (1.1.2). Release: Mapy.com 1.1.3 Minor update available for module mapycom (1.1.3). Release: Ckeditor5 entity browser 3.0.3 Minor update available for module ckeditor5_entity_browser (3.0.3). Release: Ckeditor5 entity browser 3.0.1 Minor update available for module ckeditor5_entity_browser (3.0.1). Release: Ckeditor5 entity browser 3.0.2 Minor update available for module ckeditor5_entity_browser (3.0.2). Release: Teamleader Integration 4.0.2 Minor update available for module teamleader (4.0.2). Module Revived: Entityqueue Buttons 1.1.2 Module entityqueue_buttons updated after 8 months of inactivity (1.1.2).

Secure Password Reset Log

2 sites Security covered Drupal 11 · not 10
View on drupal.org

This module enhances Drupal's password reset security by logging and monitoring reset attempts. It provides flood protection, detects suspicious activity like repeated attempts, and offers administrators an audit trail to prevent abuse.

Secure Password Reset Log enhances Drupal's password reset process by logging, monitoring, and controlling reset requests with advanced security checks and flood protection mechanisms.

Features

Secure Password Reset Log provides an additional security layer for Drupal’s password reset functionality by tracking and analyzing reset attempts in real time. It helps site administrators identify suspicious activity, prevent abuse, and maintain a clear audit trail of password reset events.

Key features include:

  • Detailed logging of all password reset requests (successful and failed).
  • Enhanced flood control to prevent brute-force and automated attacks.
  • Monitoring of repeated or suspicious reset attempts by IP or user account.
  • Configurable thresholds and time windows for blocking excessive requests.
  • Administrative visibility into password reset behavior for improved security auditing.
  • Seamless integration with Drupal core user authentication system.

This module is ideal for websites that require higher security standards, such as e-commerce platforms, membership portals, enterprise applications, or any site concerned about account abuse and unauthorized access.

Post-Installation

After installing and enabling the Secure Password Reset Log module:

  1. Navigate to the module’s configuration page under Administration > Configuration > Security > Secure Password Reset Log.
  2. OR /admin/config/security/password-reset-flood
  3. Configure settings such as:
    • Logging preferences (what data to store and how long).
    • Flood control limits (number of attempts within a specific timeframe).
    • Blocking rules and security thresholds.
  4. Review logs via the provided administrative interface or Drupal’s log report system.
  5. No new content types or text formats are created. The module operates silently in the background, enhancing the existing password reset workflow.

Ensure appropriate permissions are assigned so that only authorized roles can access sensitive log data and configuration options.

Additional Requirements

This module requires:

  • Drupal Core 11.x
  • Drupal User module (core)

No external libraries or third-party services are required for basic functionality.

For enhanced security and monitoring, the following modules are recommended but optional:

  • Flood Control – For extended rate-limiting capabilities.
  • Security Kit (Seckit) – Adds HTTP header protections and security hardening.
  • Syslog – For centralized log management and external monitoring integration.

Crowdsec integration

CrowdSec integration is supported starting from version 1.0.2.

When the CrowdSec Drupal module module is installed and configured, Secure Password Reset Log can emit CrowdSec signals for suspicious password reset activity, helping improve automated threat detection and IP remediation workflows.

Examples of events that may generate signals include:

Repeated password reset attempts
Suspicious reset activity patterns
Potential abuse or enumeration behavior

The integration is optional and does not introduce a hard dependency on CrowdSec.

For setup and configuration details, see:

CrowdSec Drupal module

Similar projects

Other modules provide logging or flood control for login attempts, but Secure Password Reset Log focuses specifically on the password reset process, offering specialized monitoring and enhanced visibility for this critical security vector. Its targeted approach ensures more precise detection and control of reset abuse compared to general authentication modules.

Supporting this Module

If you would like to support ongoing development and maintenance of this module, consider contributing through:

  • Issue reporting and feature suggestions on Drupal.org
  • Code contributions and testing feedback
  • Sponsorship or financial backing (details to be added by maintainer)

Community Documentation

Future documentation, tutorials, and walkthroughs will be provided via:

  • Drupal.org project page
  • Example configuration guides
  • Demo implementations

Community contributions and guides are welcome and encouraged.

Additional Notes

Secure Password Reset Log is designed with performance and security best practices in mind. It introduces minimal overhead while significantly improving visibility and protection around password reset operations. Regular updates will continue to improve detection mechanisms and system compatibility.

Depends on

Dependencies of the latest stable release

  • user Drupal core

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
4
Tracked since
Nov 2025
Latest release
3 months ago
Releases (12 mo)
4 ▲ from 0
Maintenance
Active

Release Timeline

Releases

Version Type Core Release date
1.0.2 Stable 11 May 8, 2026
1.0.1 Stable 11 Dec 24, 2025
1.0.0 Stable 11 Nov 26, 2025
1.0.x-dev Dev 11 Nov 26, 2025