Stale accounts are a classic attack surface, so this script disables logins that have gone unused for too long. It targets only real people by selecting UIDs of 1000 or higher with genuine login shells from /etc/passwd, while a whitelist protects critical names like root. For each candidate it reads lastlog to find the most recent login, treating "Never logged in" as inactive and otherwise converting the timestamp to epoch seconds to compare against the threshold. Accounts already locked (shown by passwd -S as status L) are reported and skipped. By default the script runs in dry-run mode, printing what it would do so you can review before committing. Passing apply makes it act: usermod -L locks the password and the shell is switched to nologin for defence in depth. The aligned table of user, last login, and action gives a clear, auditable result every run.