Actually, security wise, this would be a solid option for developers to include. Usually if someone is not back to a site within a 6 months to a year, they probably are not coming back. So locking "stale" accounts (and requiring a password reset using their old email) would not be a bad deal...