UniLogin
Flexible authentication: Login with email or username, securely configurable.
J4 J5 J6 Plugin P1.2
Current Version0.11K
Active UsersSee our product features
One Field, Two Ways In
Login with email or username
The same Joomla login field accepts either — UniLogin maps the email to the account and verifies the password with native hashing.
Username Fallback you control
Leave it on for email-or-username, or turn it off for email-only authentication.
Brute-Force Resistance
Configurable attempt limits
Set max failed logins and lockout minutes — slow down credential stuffing without locking the whole site.
Clear lockout messaging
Visitors see a timed “try again later” message instead of endless retries.
Login Audit Trail
Every attempt, logged
Optional logging stores identifier, IP, status, and timestamp so you can review suspicious patterns.
Retention that cleans itself
Old rows drop automatically after your retention days — no manual purge.
Email Domain Rules
Allow only company domains
Whitelist mode keeps login to domains you list (e.g. company.com).
Or block the noise
Blacklist mode stops known throwaway or competitor domains at the auth step.
Group-Based Access
Limit by user group
Restrict UniLogin to Registered, Authors, or any groups you select — others fall through or are denied.
Fits membership sites
Useful when only certain roles should sign in with email.
Custom Error Messages
Brand the failure copy
Override no-user, bad-password, locked, and domain-blocked messages with your own wording.
Clearer support burden
Helpful text reduces “I can’t log in” tickets without exposing whether an account exists.
Smart Post-Login Redirects
Send people where they belong
Set a default return URL, or different destinations per user group (dashboard vs member area).
Safe relative paths
Internal paths and index.php routes work; external open redirects are blocked.
Login Form That Matches
Rename the username field
Show “Email or Username” (or any label) so visitors know the field accepts both.
Hint text included
Set a placeholder that guides first-time users without changing your template.
Built for Modern Joomla
Native auth, no nested hacks
Uses Joomla’s AuthenticationEvent and UserHelper::verifyPassword — no embedding the core Joomla auth plugin.
Hardened lookups
Bound SQL, timing-safe misses, and stopPropagation on success for a cleaner auth chain.
Login with email or username
The same Joomla login field accepts either — UniLogin maps the email to the account and verifies the password with native hashing.
Username Fallback you control
Leave it on for email-or-username, or turn it off for email-only authentication.
Configurable attempt limits
Set max failed logins and lockout minutes — slow down credential stuffing without locking the whole site.
Clear lockout messaging
Visitors see a timed “try again later” message instead of endless retries.
Every attempt, logged
Optional logging stores identifier, IP, status, and timestamp so you can review suspicious patterns.
Retention that cleans itself
Old rows drop automatically after your retention days — no manual purge.
Allow only company domains
Whitelist mode keeps login to domains you list (e.g. company.com).
Or block the noise
Blacklist mode stops known throwaway or competitor domains at the auth step.
Limit by user group
Restrict UniLogin to Registered, Authors, or any groups you select — others fall through or are denied.
Fits membership sites
Useful when only certain roles should sign in with email.
Brand the failure copy
Override no-user, bad-password, locked, and domain-blocked messages with your own wording.
Clearer support burden
Helpful text reduces “I can’t log in” tickets without exposing whether an account exists.
Send people where they belong
Set a default return URL, or different destinations per user group (dashboard vs member area).
Safe relative paths
Internal paths and index.php routes work; external open redirects are blocked.
Rename the username field
Show “Email or Username” (or any label) so visitors know the field accepts both.
Hint text included
Set a placeholder that guides first-time users without changing your template.
Native auth, no nested hacks
Uses Joomla’s AuthenticationEvent and UserHelper::verifyPassword — no embedding the core Joomla auth plugin.
Hardened lookups
Bound SQL, timing-safe misses, and stopPropagation on success for a cleaner auth chain.
Need help getting started?
Our comprehensive documentation provides step-by-step instructions for setting up and installing UniLogin.
We have a pricing plan that's perfect for you!
Choose the subscription plan that suits you.
$9
$19
$29
$49
Frequently Asked Questions
UniLogin lets users sign in with their email address (and optionally username) in the standard Joomla login field.
UniLogin 1.2 supports Joomla 4, Joomla 5, and Joomla 6. PHP 8.1+ is recommended.
Yes. Keep the core Authentication - Joomla plugin enabled. UniLogin handles email mapping and can verify passwords itself; core auth remains part of a healthy login stack.
Enable Username Fallback in the plugin settings (default ON in 1.2).
When enabled, UniLogin counts recent failed attempts for the login value and IP. After the maximum, login is blocked for the lockout duration.
In the #__unilogin_attempts table created on install/update. Retention cleanup removes older rows automatically.
Yes. Enable Domain Restrictions, choose Whitelist, and list domains such as company.com (one per line).
Visit support.joomlax.com.
Still have questions?
Create Your Own Joomla Module for Free!
Use our Free Joomla Module Generator to quickly create custom modules for your website.




