ModsJava
AntiSimpleLogin
Java mod listed for Minecraft 1.21. Downloads from the MC Java Mods app on Android.
⬇ Download on Spigot
AntiSimpleLogin
The missing security layer for SimpleLogin
The missing security layer for SimpleLogin
⚙ What does it do?
SimpleLogin stores passwords obfuscated in the database, but it never hides the plaintext password from the server console. Anyone with console access can see every /login cesarrt command in real time.
AntiSimpleLogin fixes this by intercepting /login, /register, and /changepassword before they reach the console, replacing the password with ***** while still allowing SimpleLogin to work normally.
✅ Features
Password Interception
- Intercepts /login, /register, /changepassword and their aliases
- Replaces passwords with ***** in console — SimpleLogin still works normally
- Also intercepts commands issued from the server console itself
- Detects and blocks chat messages that accidentally contain a password
Password Logging
- Saves captured plaintext passwords to daily rotating log files (passwords-YYYY-MM-DD.log)
- Each entry includes: timestamp, player name, UUID, IP address, and password
- /asl purge <days> — delete log files older than X days
Threat Detection
- Brute-force protection — kicks players after X failed /login attempts in Y seconds (configurable)
- IP change alert — warns admins in-game when a player logs in from a different IP than last time
- Fast-login detection — logs a warning if a player authenticates suspiciously fast after joining
- Credential stuffing detection — alerts when the same IP tries many different accounts
- VPN/Proxy detection — warns admins if a player is connecting through a VPN or proxy (uses ip-api.com)
Password Security Warnings
- Shows a password strength indicator to players on /register: Débil / Media / Fuerte
- Warns if the password is in the top-100 most common passwords list
- Warns if the password equals the player's username
- Warns if the password is numbers only
- Warns if the password is too short
- Configurable custom blacklist of forbidden passwords in config.yml
- All checks are warnings only — registration is never blocked
Statistics & Monitoring
- /asl stats — view total logins, registers, failed attempts, VPN alerts, IP changes, and more
- /asl player <name> — view a player's last known IP and failed attempt count
- /asl ips — list all tracked IPs and which accounts used them
- /asl logs [N] — view the last N entries from today's log file
Plugin Integrations
- PlaceholderAPI — %asl_last_ip%, %asl_failed_count%, %asl_logins%, %asl_registers%
- LuckPerms — automatically assigns a configurable group when a player registers
Commands
| Command | Description | Permission |
| /asl reload | Reload the configuration | antisimplelogin.admin |
| /asl logs [N] | View last N log entries (default: 10) | antisimplelogin.admin |
| /asl stats | View plugin statistics | antisimplelogin.admin |
| /asl player <name> | View a player's last IP and failed attempts | antisimplelogin.admin |
| /asl ips | List all tracked IPs | antisimplelogin.admin |
| /asl purge <days> | Delete log files older than X days | antisimplelogin.admin |
| /asl version | Show plugin version | antisimplelogin.admin |
⚙ Configuration
Code (Text):
# Whether to log captured passwords to daily rotating files
log-passwords: true
# Whether to hide the password in console/server logs
mask-console: true
# The string shown in console instead of the real password
console-mask: "*****"
# Brute-force protection
brute-force:
max-attempts: 5 # Kick after this many failed /login attempts
window-seconds: 30 # Time window to count attempts
stuffing-threshold: 5 # Accounts from same IP to trigger stuffing alert
# Threat detection
detection:
fast-login-ms: 1000 # Fast-login threshold in milliseconds
anti-vpn: true # Warn admins if player uses VPN/proxy
# Password policy (warnings only)
password-policy:
min-length: 6
blacklist:
- "minecraft"
- "admin123"
# LuckPerms integration
luckperms:
enabled: false
register-group: "default"
- Download AntiSimpleLogin-1.0.0.jar
- Place it in your server's plugins/ folder
- Make sure SimpleLogin is already installed
- Start/restart your server
- Configure plugins/AntiSimpleLogin/config.yml to your liking
- Run /asl reload after any config changes
Requirements
- Spigot / Paper / Purpur 1.17+ (Java 17+)
- SimpleLogin (required — this plugin patches it)
- PlaceholderAPI (optional)
- LuckPerms (optional)
❓ FAQ
Does this break SimpleLogin?
No. The command interception happens at LOWEST priority, so SimpleLogin still receives and processes the command normally. Only the console output is masked.
Does it block weak passwords?
No — all password policy checks are warnings only. Players are informed but never blocked from registering.
Is the VPN check accurate?
It uses the free tier of ip-api.com (no API key needed). It's a best-effort check — false positives are possible.
Where are the logs stored?
In plugins/AntiSimpleLogin/logs/passwords-YYYY-MM-DD.log. A new file is created each day automatically.
Quick facts
- Edition: Minecraft Java
- File type: .jar
- Minecraft version listed: 1.21
- How to install: Install the matching mod loader (Forge, Fabric or NeoForge) for your Minecraft version. → Download the .jar. → Put it in the .minecraft/mods folder and launch that loader profile.
- Where to get it: Opens on Spigot — not every file is mirrored on our own servers.
Install steps are the general flow for this file type — How to install Minecraft Java mods & modpacks walks through it step by step.
AntiSimpleLogin is a free Minecraft Java mod. Compatible with Minecraft 1.21. Downloaded 27 times (via Spigot). Download it and open it directly in the game.