Perhaps one mitigating fix may be to add some code that checks password complexity and if the check fails the admin must either remediate the bad password, or be forced to add a configuration directive that says "I_KNOW_I_AM_DOING_SOMETHING_SILLY_AND_RECKLESS=true".
Is something like this possible in PHP?
WordPress has a built-in password strength meter which helps users choose strong passwords.
They tried something else before but the "password strength meter" said it is too short so they were left with "admin".