The Disable Client Edit plugin allows administrators to prevent clients from modifying their account information, ensuring data consistency and compliance.
From £9.99 - View Pricing
What Disable Client Edit gives you
Configure it independently for each brand on a multi-company install, so every company runs with its own settings.
Every staff and client label ships in editable language files, ready to translate into any language or reword to match your brand.
The locks apply to real client sessions only, so your staff, your API integrations and automated jobs keep updating contact details normally.
Decide whether the locks cover every contact on the account or only the primary contact, so clients can still manage their own additional contacts if you want them to.
An optional message is shown as a notice above the locked fields in the client portal, so clients know to open a ticket instead of wondering why the form will not save.
Choose per field whether clients see it greyed out and unchangeable or do not see it at all, so you can either show the value you hold on file or keep the form short and clean.
Pull a client group's existing read-only contact field list straight into the form with one click, review what it selected, then save. No re-entering settings you already configured.
Set a default lock set that applies everywhere, then give individual client groups their own, so verified, reseller or corporate clients can be treated differently from everyone else.
First name, last name, company, title, address 1 and 2, city, country, state, zip, email and phone numbers can each be locked, so the details that matter to your invoices and verification stay exactly as you set them.
Locked fields are restored to their stored values on save, so a hand-crafted form submission that bypasses the page cannot change them. Locking the email address also keeps the client's login username from being moved.
Every reverted change is recorded with the date, client, field, the value that was attempted, the value it was restored to and the source IP address, on its own paginated tab, so you can see who is trying to edit locked details.

Stop clients changing the contact details you rely on for billing and compliance, with locks that hold even against a crafted form submission.
Once a client's identity is verified, the last thing you want is for them to quietly change the name, company or email address your invoices and compliance checks depend on. Blesta lets clients edit their own contact details freely, and its built-in "read-only contact fields" setting only goes so far. Disable Client Edit lets you lock any of twelve contact fields per client group, choose whether a locked field is shown greyed out or hidden entirely, and enforces the lock on the server, not just in the browser, so a hand-crafted form submission that bypasses the page cannot change a locked value either.
Blesta already offers a per-group "read-only contact fields" setting, and Disable Client Edit is built to sit alongside it rather than replace it. It adds per-group lock sets with a company-wide default, a hidden mode on top of read-only, a phone-numbers lock, a primary-or-all contact scope, a client-facing explanation message, and a tamper log recording every submission that was reverted server-side. Use the Import from Blesta's read-only fields button to seed the plugin's toggles from Blesta's own setting for the selected group.
Installing and updating extensions can now be done automatically through the Blesta Club Subscription Manager - this is the recommended way going forward.

Upload the extension folder into your Blesta installation so it lands under your Blesta directory at:
plugins/disable_client_edit/
For example, on a typical install: /var/www/html/blesta/plugins/disable_client_edit/
Disable Client Edit needs no API credentials, no cron task and no package or service to work against - it locks fields on Blesta's own client contact forms.
You're ready to go - see the usage guide for a walkthrough of day-to-day use.
Installing and updating extensions can now be done automatically through the Blesta Club Subscription Manager - this is the recommended way going forward.

Upgrading works just like installing: upload the new files over the old ones, then run the upgrade from the same page you installed it on.

Go to Settings > Company > Plugins, find Disable Client Edit in the installed list and click Manage. The Settings tab opens first.
When a specific (non-default) client group is selected, an Import from Blesta's read-only fields button also appears. It pre-ticks the Read-only fields that match whatever Blesta's own per-group "read-only contact fields" setting already has for that group, so you don't have to re-enter them by hand - review the pre-ticked selections, then click Submit to apply them.
Click the Tamper Log tab to see every locked-field change that a client attempted and that was reverted server-side: the date, the client, the field, the value they attempted, the value it was restored to, and their IP address. This table lists every reverted attempt across all client groups and grows over time - it is not pruned automatically.
Locked fields appear on the client's own Manage Account page (their name, company and contact details) and on their Contacts page (any additional contacts on the account, when locks are set to apply to all contacts rather than the primary contact only):
Staff edits, API calls and cron jobs are never affected by any of this - the locks only apply when a client is editing their own details.
v2.0.0 - 2026-09-11
PHP 7.2 - 7.4, 8.1 - 8.4 · Blesta 5.x
Per-client-group lock sets with a company-wide default. Optional "why is this locked" client hint. Tamper audit log of reverted client edits, viewable on the manage screen. Primary-vs-all contact scope toggle. Per-field Editable / Read-only / Hidden mode. One-click import of Blesta's own read-only contact fields. A locked phone-numbers field is now also enforced when a client creates a new contact, not only when they edit an existing one.
v1.0.0 - 2024-09-22
PHP 7.2 - 7.3, 8.1 - 8.4 · Blesta 5.x
Blesta Club release
Get exactly what you need and want.
Requires PHP 7.2 - 7.4, 8.1 - 8.4 · Blesta 5.x
Value: £42.3
Not sure whether to lease or own? Our FAQ explains how the licence types differ.
What our customers say
(0 customer reviews)
It is possible to leave a review only if you have purchased this extension or a Club tier which contains it.
We reserve the right to alter wording or formatting for presentation.
We will discuss any changes made and offer the option to withdraw review text if the changes can't be agreed on.
It may take up to 1 hour for a review to appear or update due to caching.
More extensions to explore
Plugin
Integrate the Announcements plugin to provide updates and news to your clients.
PHP 8.2 - 8.4 · Blesta 6.x
Plugin
Give your clients rewards based upon service purchases.
PHP 8.2 - 8.4 · Blesta 6.x