Admin Password Reminder Expiry Backend Security | Renew passwords on schedule
Description
Highlights
About the Extension
Quick question. When did each person with access to your Shopware administration last change their password? In most shops nobody can answer that. The password someone chose on their first day is often still the one they use today.
The problem
Shopware has no expiry date for admin passwords. Once set, a password stays valid until someone remembers to change it. If your own security policy, a trade customer or a partner expects regular password changes, all you have is a calendar reminder, a team email and the hope that everyone plays along. You cannot check whether they did.
The solution
Admin Password Reminder gives every admin password a validity period, 90 days by default. As the expiry date gets closer, the user sees a notice after logging in and receives one email a day until the password is changed. With Premium, the reminder becomes a rule: anyone who does not renew an expired password is locked out of the administration until they do.
What's in it for you
You stop chasing people. The plugin reminds every user on its own, in the administration and by email. You set the rule once and that is the end of your involvement.
Nobody gets caught off guard. Reminders start 7 days before expiry by default. Your team changes the password when it suits them, not halfway through packing an order.
You can see who is lagging behind. Each user's detail page shows when the password was last changed. One look, no spreadsheet, no asking around.
Your policy becomes binding (Premium). With enforcement switched on, nobody keeps working on an expired password. The profile page and logging out stay available, everything else waits for the new password.
A change is a real change (Premium). The password history blocks a user's most recent passwords, the last 5 by default. Swapping back and forth between two familiar passwords no longer works.
Technical accounts keep running (Premium). You can exempt an emergency login or a service account from the lock on the user detail page. The notice and the email still reach that user.
How the plugin works
In the plugin configuration you decide how many days a password stays valid and how many days before expiry the reminders begin. Two switches control whether the notice appears after login and whether emails go out.
The notice reads "Password expires soon" or "Password expired". The "Change password" button takes the user straight to the "Your profile" page. "Remind me later" closes the notice until the next browser session.
Once a day the plugin checks all active users and sends each one inside the reminder window at most one email. The "Admin password reminder" template comes ready in German, English and Dutch under Settings > Email templates, where you edit the subject, sender and text like any other Shopware email.
Every password change counts, whether the user changes it in their profile, an administrator resets it under Settings > Users & permissions, or someone uses "forgot password". The validity period then starts again.
For users who already exist when you activate the plugin, the validity period starts at activation. So nobody has to change their password on installation day. With the default values the first reminder arrives after 83 days.
Typical use cases
A small team running the daily business. A handful of people maintain products, process orders and answer customer emails. You want a 90-day rhythm without sending a reminder email every quarter and following up by hand.
A security questionnaire lands on your desk. A trade customer, your insurer or a payment partner asks how you handle admin passwords. The plugin supports your password policy, and with Premium the administration no longer accepts expired passwords.
Outside access. Your agency or a freelance developer has their own admin user. Instead of staying unchanged for years, that password expires and gets renewed like everyone else's.
Technical facts for your IT team
- Shopware 6.7, PHP 8.2 or later.
- Works in the administration only. No storefront components, no impact on shop page load times.
- Two dedicated tables (change timestamp and exemption per user, password history). Shopware's original tables stay untouched.
- Stored data: timestamps, an exemption flag and, with Premium, the password hashes of recent passwords. Never plain text.
- The plugin does not send any data to external servers. Everything stays in your Shopware database and concerns your admin users only.
- Emails are sent by a daily scheduled task through the mailer configured in Shopware. Scheduled tasks and the message queue need to be running.
- Lock (Premium): the Admin API answers requests from affected users with 403. Login, password recovery and the profile page remain reachable. Integrations with their own access key are not affected.
- Uninstalling: if you keep the data when uninstalling, everything stays. Otherwise the plugin removes both tables plus the email template and its type.
To be honest
The settings apply to the whole shop, not per sales channel, because admin users do not belong to a sales channel. The password history only knows passwords set after Premium was unlocked. And the plugin neither checks password strength nor replaces two-factor login. If regular password changes matter to you, try it in your shop.
Legal notice
We accept no liability for legal requirements. Please check the use of this plugin with a qualified legal advisor.
Details
- Available: English, German
- Latest update: 7 October 2026
- Publication date: 8 October 2026
- Version: 6.7.0
- Category: Administration
Resources
Reviews (0)
About the Extension Partner
BuI Hinsche GmbH
Partner Status
-
Shopware
Bronze Partner -
Shopware
Premium Extension Partner
Details
- Ø-Rating: 4.3
- Partner since: 2014
- Extensions: 99
- Certifications: 2
Support
- Based in: Germany
- Speaks: German, English
- Response time: Very quickly