Home›Java›Mods›AntiSimpleLogin
AntiSimpleLogin
ModsJava

AntiSimpleLogin

Java mod listed for Minecraft 1.21. Downloads from the MC Java Mods app on Android.

⬇ Download on Spigot
AntiSimpleLogin
The missing security layer for SimpleLogin​

⚙ What does it do?

SimpleLogin stores passwords obfuscated in the database, but it never hides the plaintext password from the server console. Anyone with console access can see every /login cesarrt command in real time.

AntiSimpleLogin fixes this by intercepting /login, /register, and /changepassword before they reach the console, replacing the password with ***** while still allowing SimpleLogin to work normally.

✅ Features

Password Interception

Password Logging

Threat Detection

Password Security Warnings

Statistics & Monitoring

Plugin Integrations

Commands

Command Description Permission
/asl reload Reload the configuration antisimplelogin.admin
/asl logs [N] View last N log entries (default: 10) antisimplelogin.admin
/asl stats View plugin statistics antisimplelogin.admin
/asl player <name> View a player's last IP and failed attempts antisimplelogin.admin
/asl ips List all tracked IPs antisimplelogin.admin
/asl purge <days> Delete log files older than X days antisimplelogin.admin
/asl version Show plugin version antisimplelogin.admin


⚙ Configuration

Code (Text):

# Whether to log captured passwords to daily rotating files
log-passwords: true

# Whether to hide the password in console/server logs
mask-console: true

# The string shown in console instead of the real password
console-mask: "*****"

# Brute-force protection
brute-force:
  max-attempts: 5        # Kick after this many failed /login attempts
  window-seconds: 30     # Time window to count attempts
  stuffing-threshold: 5  # Accounts from same IP to trigger stuffing alert

# Threat detection
detection:
  fast-login-ms: 1000    # Fast-login threshold in milliseconds
  anti-vpn: true         # Warn admins if player uses VPN/proxy

# Password policy (warnings only)
password-policy:
  min-length: 6
  blacklist:
    - "minecraft"
    - "admin123"

# LuckPerms integration
luckperms:
  enabled: false
  register-group: "default"
 
Installation

  1. Download AntiSimpleLogin-1.0.0.jar
  2. Place it in your server's plugins/ folder
  3. Make sure SimpleLogin is already installed
  4. Start/restart your server
  5. Configure plugins/AntiSimpleLogin/config.yml to your liking
  6. Run /asl reload after any config changes

Requirements


❓ FAQ

Does this break SimpleLogin?
No. The command interception happens at LOWEST priority, so SimpleLogin still receives and processes the command normally. Only the console output is masked.

Does it block weak passwords?
No — all password policy checks are warnings only. Players are informed but never blocked from registering.

Is the VPN check accurate?
It uses the free tier of ip-api.com (no API key needed). It's a best-effort check — false positives are possible.

Where are the logs stored?
In plugins/AntiSimpleLogin/logs/passwords-YYYY-MM-DD.log. A new file is created each day automatically.

Commands

Plugin details

Read from the plugin's own plugin.yml.

Quick facts

Install steps are the general flow for this file type — How to install Minecraft Java mods & modpacks walks through it step by step.

AntiSimpleLogin is a free Minecraft Java mod. Compatible with Minecraft 1.21. Downloaded 27 times (via Spigot). Download it and open it directly in the game.

Explore more