Skip to main content
Drupal is a registered trademark of Dries Buytaert
Release: OpenID Connect / OAuth client 3.0.0-alpha9 New alpha version released for module openid_connect (3.0.0-alpha9). Release: Opensolr Search 4.5.0 Minor update available for module opensolr_search (4.5.0). Release: Timelinr 1.0.1 Minor update available for module timelinr (1.0.1). Usage Milestone: Simplify Module simplify crossed 10,000 active installs. Usage Milestone: Views Reference Filter Module entityreference_filter crossed 10,000 active installs. Usage Milestone: Dropdown Language Module dropdown_language crossed 10,000 active installs. Usage Milestone: Paragraphs Browser Module paragraphs_browser crossed 10,000 active installs. Usage Milestone: OpenAPI Module openapi crossed 10,000 active installs. Usage Milestone: Decoupled Router Module decoupled_router crossed 10,000 active installs. Module Revived: Entityqueue Buttons 1.1.2 Module entityqueue_buttons updated after 8 months of inactivity (1.1.2).

Flood control

30,599 sites Security covered Drupal 10–11
View on drupal.org

Flood Control provides an administrative interface to manage Drupal's built-in login attempt throttling. It allows administrators to configure the limits for failed login attempts, control the duration of blocks, and manually unblock IP addresses or usernames. The module also offers an IP allowlist for trusted addresses and can protect contact forms from excessive submissions.

Drupal's built-in flood protection blocks login attempts after repeated failures – but provides no interface to configure limits or unblock affected users. Flood Control fills that gap with an intuitive admin UI for managing brute-force protection settings and unlocking blocked IPs.

Features

  • Configurable limits – Set login attempt thresholds per IP address and per username
  • Time window control – Define how long blocks remain active
  • IP allowlist – Exempt trusted IPs or ranges from flood protection
  • Unblock interface – View, filter, and remove blocked entries with one click
  • Contact form protection – Limit email submissions when Contact module is enabled
  • Drush commands – Manage flood entries from the command line
  • No external dependencies – Works with Drupal core only

Why You Need This

When legitimate users get locked out after mistyping their password, there's no core UI to help them. Flood Control gives administrators the tools to:

  • Quickly unblock users without database access
  • Whitelist office IPs to prevent accidental lockouts
  • Fine-tune security thresholds for your specific needs

Requirements

  • Drupal 10.2+ or Drupal 11

Documentation

Documentation, covering:

  • Configuration options and recommended settings
  • IP allowlist format (single IPs and ranges)
  • Drush commands for automation
  • Permissions overview

Related Modules

  • Login Security – Additional login protection like access denial and notifications
  • CAPTCHA – Challenge-response tests to prevent automated submissions
  • Honeypot – Invisible spam prevention using hidden form fields
  • Perimeter – IP-based access control and blocking

Sponsors

Development sponsored by Finalist, a Dutch Drupal agency specializing in custom solutions for the education and healthcare sectors.

Depends on

Dependencies of the latest stable release

No dependencies recorded for this project.

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
2
Tracked since
Sep 2024
Latest release
6 months ago
Releases (12 mo)
1
Maintenance
Active

Releases

Version Type Core Release date
3.0.1 Stable 10–11 Feb 20, 2026
3.0.0 Stable 10–11 Sep 27, 2024