‘admin’ allowed as username
-
WooCommerce 3.91 > Settings > Accounts & Privacy
With the checkbox setting ‘Automatically generate username from customer email’ enabled, does this allow creation of a user with the username ‘admin’ if, say, their email address is [email protected]?
I’m looking to harden security on a client site and there are existing users with usernames ‘admin’, ‘admin1’, ‘admin2’ etc. that have Site Role: Customer.
They don’t have Administrator role and presume a decent password was enforced at time of creation but allowing ‘admin’ as a username just feels uncomfortable – is it best to create new usernames for these Users via the DB as a precaution (as usernames cannot be changed on the regular backend)?
- The topic ‘‘admin’ allowed as username’ is closed to new replies.