What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

WordPress has two different password-reset controls: one removes the visible “Lost your password?” link, while the other blocks reset processing. Hiding the link alone does not stop someone from opening wp-login.php?action=lostpassword directly. Use the documented filters below according to whether you need a cosmetic change or an enforced policy.

Choose between hiding the link and blocking resets

Goal Core control What it changes
Hide the login-page link lost_password_html_link Removes or changes the rendered “Lost your password?” navigation link.
Prevent reset processing allow_password_reset Determines whether WordPress permits a password-reset request for a user.

The login screen is handled by wp-login.php, whose lost-password and retrieve-password actions remain available unless reset processing is also restricted.

Hide the visible “Lost your password?” link

Add this code in a small custom plugin or a site-specific snippets plugin:

add_filter( 'lost_password_html_link', '__return_empty_string' );

WordPress documents lost_password_html_link as the filter for “the link that allows the user to reset the lost password.” Returning an empty string removes the generated link from the login form.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When this approach is appropriate

  • You are changing the interface for a controlled environment.
  • An external identity provider or help desk handles account recovery.
  • You still want WordPress’s reset mechanism available to users who know the direct endpoint.

This is not an access-control measure. CSS that hides the anchor, editing a login template, or filtering the HTML does not prevent direct requests.

Disable password-reset processing

To block reset requests, add the allow_password_reset filter:

add_filter( 'allow_password_reset', '__return_false' );

This broad example returns false for every user handled by the filter. WordPress’s password-reset checks use this hook through wp_is_password_reset_allowed_for_user(); the callback receives the current allowance and the user ID.

Keep an administrator or recovery account exempt

Most sites should not disable every recovery path. Scope the callback to the users or context that must be restricted, and allow a documented emergency account or administrator route to continue working.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
function freedom251_allow_selected_password_resets( $allow, $user_id ) {
    // Replace this condition with your site's policy.
    $recovery_user_id = 123;

    if ( (int) $user_id === $recovery_user_id ) {
        return true;
    }

    return false;
}
add_filter( 'allow_password_reset', 'freedom251_allow_selected_password_resets', 10, 2 );

The user ID and exemption in this example are placeholders for your own policy, not values to copy unchanged. If your rule depends on role, domain, membership status, or another attribute, implement and test that condition in the callback.

Use both filters when the policy requires both

If users must neither see nor use password recovery, apply both controls:

add_filter( 'lost_password_html_link', '__return_empty_string' );
add_filter( 'allow_password_reset', '__return_false' );

For a production site, replace the second line with a scoped callback if any administrator or recovery account must retain access.

Why direct URLs still matter

WordPress’s login controller recognizes the lostpassword and retrievepassword actions. A visitor can therefore request the lost-password screen by entering the endpoint directly, even when the normal link is absent. Enforcement belongs in allow_password_reset, not in the presentation layer.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Install the code safely

  1. Create a small site-specific plugin or use a maintained snippets plugin. A custom plugin keeps the rule independent of the active theme.
  2. Place the filter code in the plugin’s main PHP file, with the opening PHP tag if the file requires one.
  3. Test on staging before activating it on production.
  4. Record how to deactivate the plugin or remove the filter if administrators are locked out.
  5. Deploy during a maintenance window and verify the recovery route immediately.

Test the change before rollout

  • Confirm ordinary login still works for an existing account.
  • Open the login page and verify whether the visible link is present, as your policy requires.
  • Visit wp-login.php?action=lostpassword directly.
  • Submit a known account and confirm whether WordPress accepts or rejects the reset request.
  • Check that no reset email is sent when processing is blocked.
  • Test the administrator or emergency account that is meant to remain recoverable.
  • Document and rehearse the rollback method.

Multisite and login-plugin considerations

Networked WordPress installations and login plugins can add their own screens or policies. Verify the behavior on the relevant site and network login flows rather than assuming a single-site test covers every path. A plugin that changes the login URL may alter where users enter credentials without disabling password recovery.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What common alternatives actually do

WordPress.org password-reset plugins

The WordPress.org directory includes plugins named for disabling “Lost Your Password” and other reset tools. Before installing one, check its latest update, tested WordPress versions, support activity, multisite behavior, and whether it hides the link, blocks processing, or does both. Directory availability alone does not establish current maintenance or the exact scope of enforcement.

WPS Hide Login

WPS Hide Login changes the login URL and blocks access to the default login path. Its listing states that registration and lost-password forms continue to work, so it is a login-URL change, not proof that password reset has been disabled.

Password-policy and notification plugins

Tools such as Fuerte-WP document password-policy or reset-notification features. Those controls may strengthen account security, but they are not necessarily a way to remove the reset option.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Operational risks and recovery planning

Password reset is a built-in recovery route. Removing it can turn a forgotten password, an expired credential, or an administrator lockout into a manual incident. Before enabling enforcement, keep at least one tested recovery method, restrict access to it, and store the rollback instructions somewhere administrators can reach without logging in.

Recommended decision

  • Choose lost_password_html_link when the requirement is only to clean up the login interface.
  • Choose a scoped allow_password_reset callback when the requirement is to enforce who may reset a password.
  • Use both when the interface and the underlying capability must be removed, while preserving a tested administrator fallback.

Frequently Asked Questions

Does hiding “Lost your password?” stop direct reset requests?

No. The link filter changes the rendered login page only. A direct wp-login.php?action=lostpassword request can still reach WordPress unless reset processing is restricted with allow_password_reset.

Can I disable resets for only some users?

Yes. Use a callback for allow_password_reset and make the decision from its $user_id argument, leaving an administrator or recovery account allowed when required.

Should I edit my theme’s login files?

Usually no. A small site-specific plugin or maintained snippets plugin uses WordPress’s documented hooks and is less likely to be lost during a theme change.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.