Security & Logging
Use the Security & Logging tab.
Rate limiting
- Enable Rate Limiting — turn brute-force protection on or off (default On)
- Maximum Failed Attempts — failures before lockout (default 5; range 1–20)
- Lockout Duration — minutes locked after the limit (default 15; range 1–1440)
Failed attempts are counted by identifier (email/username) and IP. A successful login clears prior failed rows for that identifier/IP.
Logging
- Enable Login Logging — store attempts in
#__unilogin_attempts(default On) - Log Retention Period — days to keep rows (default 30; range 1–365); older rows are deleted automatically
Each row stores: identifier, IP address, timestamp, status (success, failed, locked), and user ID when known.
View logs with phpMyAdmin or any SQL tool. There is no admin list view in the plugin itself.