Lyzerslab

Changelog & Roadmap

Every release we ship and what we're working on next -- one hub for all our Joomla and WordPress products.

MuRu Guard

Joomla48 items
  1. Live now22 items
    1. CurrentHIGH priority

      Protection Mode

      Companion plugin inspects every site request, with manual IP allow/block lists (CIDR), cached fail-open country blocking, and scanner, bot, and brute-force login blocking.

    2. CurrentHIGH priority

      Active Web Application Firewall (Pro)

      Blocks SQL injection, XSS, file inclusion, and command-injection patterns in real time, including a signature for Joomla's CVE-2023-23752 webservices probe; broad matches log only.

    3. CurrentHIGH priority

      Filesystem Scan

      Scans media, images, templates, tmp, cache, and webroot; cross-references Joomla's extension registry to catch spoofed extensions; flags suspicious PHP, phtml, phar, and shtml files.

    4. CurrentMEDIUM priority

      Core Integrity

      Checks Joomla entry points for prepended payloads, verifies supported core files with SHA-256 hashes, and scans MuRu Guard's own extension files too.

    5. CurrentMEDIUM priority

      File Integrity Monitoring (Pro)

      Baseline-hash every file once, then flag silent changes; drift alerts use the same email, Slack, Discord, and Telegram pipeline as scheduled scans.

    6. CurrentMEDIUM priority

      Database Scan

      Finds Helix Ultimate mega-menu XSS payloads, checks SP Page Builder asset rows for injected code, and reports template defacement strings.

    7. CurrentHIGH priority

      Smart AI Assistant (Pro)

      Chat assistant that lists, searches, reads, and edits project files with guarded paths, explicit confirmation for destructive actions, and a full audit log.

    8. CurrentHIGH priority

      TimeMachine Backup & Restore (Pro)

      Every AI repair saves a verified snapshot first; one-click undo for a single file or a whole request, covering files and database rows.

    9. CurrentMEDIUM priority

      Autopilot Mode (Pro)

      Scheduled scans auto-remove near-zero-false-positive threats after an independent AI-verification pass; opt-in, everything restorable via TimeMachine.

    10. CurrentMEDIUM priority

      Automations & Alerts (Pro)

      Cron-token scheduled scans with email, Slack, Discord, and Telegram alerts, Fleet Dashboard reporting, and bulk re-scan and hardening pushes.

    11. CurrentMEDIUM priority

      Smart False-Positive Handling

      One-click safe marking tied to exact reviewed content, with automatic re-alerts if the same file is compromised later.

    12. CurrentLOW priority

      .htaccess Hardening Advisor

      Read-only checks for PHP execution blocking and sensitive-file protection, with copy-paste rules that never edit the file.

    13. CurrentMEDIUM priority

      Pro Analysis Toolkit (Pro)

      Snippet and IOC code search, reversible quarantine, custom PCRE signatures, and a read-only PHP, Joomla, and extension update audit.

    14. CurrentMEDIUM priority

      Live VEL cross-check (Pro)

      Installed extensions matched against the official Joomla Vulnerable Extensions List, flagged VULNERABLE or Verify.

    15. CurrentHIGH priority

      Virtual patching (Pro)

      Per-CVE firewall rules blocking exploit requests between disclosure and update, with Test-a-Request preview.

    16. CurrentMEDIUM priority

      Global Configuration audit (Pro)

      17 read-only hardening checks over Global Configuration with deep links to each Joomla screen.

    17. CurrentHIGH priority

      Secret administrator URL (Pro)

      /administrator hidden behind a secret address with brand-free 404 and self-lockout-proof recovery.

    18. CurrentHIGH priority

      Privileged 2FA enforcement (Pro)

      Nag banner then hard refuse for privileged logins without MFA, with 7-day grace and bypass file.

    19. CurrentMEDIUM priority

      Sensitive-file exposure probes (Pro)

      Live HTTP exposure probes plus a managed, self-tested .htaccess deny block with rollback.

    20. CurrentMEDIUM priority

      Honeypot canaries (Pro)

      Self-tripping decoy file plus blocked decoy Super User with scheduled trip alerts.

    21. CurrentMEDIUM priority

      Reputation & blocklist watch (Pro)

      Google Safe Browsing + Spamhaus ZEN self-checks with transition-only email alerts.

    22. CurrentLOW priority

      Weekly all-clear digest (Pro)

      One plain-text email per 6-day cadence: ALL-CLEAR or NEEDS-REVIEW with 8 signals.

  2. Recently shipped20 items
    1. CompletedAddedShipped in v4.0.0MEDIUM priority

      Joomla 3.10+ support in the same package (PHP 7.4+).

      The component, Shield plugin and bundle now install and run on Joomla 3.10 alongside 4, 5 and 6. A small compatibility layer (`admin/helpers/compat.php`) maps the namespaced Joomla API onto Joomla 3's legacy classes, with version branches for the few calls that genuinely differ (`getIdentity()`, `getSession()`, Extension-table params saves, the stylesheet loader, and the com_ajax webcron URL, which points at the site frontend on Joomla 3). New static-check sections (10-11) plus a PHP 7.4 CI lint job guard both version floors. Core-file checksum verification stays heuristic-only on Joomla 3 for now, since the bundled manifest covers 4.4/5.x/6.x; everything else works identically.

    2. CompletedAddedShipped in v4.0.0MEDIUM priority

      Single-install bundle (pkg_muruguard).

      One package zip installs the scanner component and the Shield plugin together. It is the easiest install path and the package submitted to the Joomla Extensions Directory. The individual component and plugin zips are still built.

    3. CompletedAddedShipped in v4.0.0MEDIUM priority

      Joomla update support for the Shield plugin

      (1.3.3). The plugin manifest now declares its own update server (`free-shield` feed), so Shield updates appear in the admin just like component updates.

    4. CompletedAddedShipped in v4.0.0MEDIUM priority

      Install preflight checks.

      Installing on PHP older than 7.4 or Joomla older than 3.10 now aborts cleanly with a plain-language message instead of leaving a half-installed component.

    5. CompletedAddedShipped in v4.0.0MEDIUM priority

      Clean uninstall.

      Uninstalling the component now removes the Dashboard and MuRu Settings submenu items the installer created, instead of leaving orphaned menu rows.

    6. CompletedAddedShipped in v4.0.0MEDIUM priority

      scripts/build.sh.

      One command rebuilds the vendored admin stylesheet (when Tailwind CSS is available) and all three `dist/` zips from the current manifests, with zip-layout verification. Changed

    7. CompletedAddedShipped in v4.0.0MEDIUM priority

      No more CDN dependency.

      The admin styling is now a precompiled stylesheet shipped inside the package (`media/css/muruguard.css`) instead of the Tailwind Play CDN script, so the page renders identically offline and makes zero third-party calls on its own. An automated check verifies that every utility class used in the sources has a rule in the shipped CSS.

    8. CompletedAddedShipped in v4.0.0MEDIUM priority

      Joomla 6 compatibility hardening.

      The installer script and scheduled-alert mailer now prefer the container (`DatabaseInterface` / `MailerFactory`) over the legacy `Factory::getDbo()` / `Factory::getMailer()` shortcuts, and the admin sidebar submenu degrades gracefully where the legacy sidebar helper no longer exists. Supported range is now Joomla 3.10+ (PHP 7.4+) through 6.x (PHP 8.1+ on Joomla 4 and later).

    9. CompletedAddedShipped in v4.0.0MEDIUM priority

      Global Configuration radio fields no longer use the Joomla 4 radio.switcher layout, which does not exist on Joomla 3.

      They render as standard Yes/No radios there. The component's own Settings panel is custom HTML and unaffected.

    10. CompletedAddedShipped in v4.0.0MEDIUM priority

      Privacy statement corrected.

      The README's privacy section now lists every outbound connection (update checks, advisory feed, newsletter opt-in, Ask AI, country lookup, hardening self-tests) instead of only the first two.

    11. CompletedAddedShipped in v4.0.0MEDIUM priority

      Component manifest description is now the COM_MURUGUARD_XML_DESCRIPTION language string, and the remaining hardcoded English strings in the vulnerabilities table moved into language files.

    12. CompletedAddedShipped in v4.0.0MEDIUM priority

      Component display name shortened to MuRu Guard, matching the admin menu label.

      The Manage list, menu and install name now all agree.

    13. CompletedAddedShipped in v4.0.0MEDIUM priority

      The admin header's "Report an issue" link now opens a support ticket on the store dashboard (store.lyzerslab.com/dashboard/support/new) instead of a GitHub issue.

      Fixed

    14. CompletedAddedShipped in v4.0.0MEDIUM priority

      Bundle package (pkg_muruguard) uninstall.

      The first bundle draft installed fine but uninstall always failed with "Package Uninstall: Missing manifest file." Joomla derives a package's `#__extensions.element` as `pkg_` + the filtered `<packagename>`, but looks up the installed manifest by the manifest file's basename. The draft `<packagename>` ("MuRu Guard Security Suite (Free)") produced the element `pkg_MuRuGuardSecuritySuiteFree` while the file on disk is `pkg_muruguard.xml`, so uninstall could never find it. `<packagename>` is now `muruguard`, making element and filename agree. A static check (`tests/static-checks.php`, also run by `scripts/build.sh` and CI) asserts this invariant so the mismatch can never ship. The component and plugin zips were never affected.

    15. CompletedAddedShipped in v4.0.0MEDIUM priority

      JED Checker findings on the bundle package.

    16. CompletedAddedShipped in v4.0.0MEDIUM priority

      The bundle now ships en-GB.pkg_muruguard.sys.ini, translating its install name to MuRu Guard instead of the raw pkg_muruguard key, which tripped the type-prefix error.

    17. CompletedAddedShipped in v4.0.0MEDIUM priority

      The bundle now declares an update server (required by JED), pointing at the same live free feed as the component.

    18. CompletedAddedShipped in v4.0.0MEDIUM priority

      The translated bundle name stays within all of JED Checker's top-level name rules (no type prefix, no reserved words, ASCII, under 40 characters).

    19. CompletedAddedShipped in v4.0.0MEDIUM priority

      Joomla 3 "Cannot declare class" warnings breaking scans.

      Joomla 3.10's own loader creates its core-registered aliases (`Joomla\CMS\Router\Route`, `HTMLHelper`, `BaseController`, `HtmlView`, `ToolbarHelper`) as a side effect of loading the legacy class, so the compatibility layer's check-then-declare raced it and re-declared the name. The resulting warnings corrupted the chunked scan's JSON responses ("The scan couldn't continue"). Every alias loop (component, Shield plugin, installer script) now re-checks after loading the original and uses Joomla's identical alias instead. Covered by a static check plus a harness mode that mimics Joomla's loader behaviour.

    20. CompletedAddedShipped in v4.0.0MEDIUM priority

      Joomla 3 core false positives removed.

      Seven genuine Joomla 3.10 core files no longer flag as High on Joomla 3 sites: `cli/` legacy scripts (`finder_indexer.php`, `sessionGc.php`, `sessionMetadataGc.php`), `bin/keychain.php`, com_finder's `controllers/index.php` and `models/index.php`, and com_privacy's `controllers/request.xml.php`. Each platform is checked against its own core-file list, so the Joomla 4+ lists stay tight and the same paths still flag there. **Note for local testers of the interim 3.6.4-dated bundle:** if you installed a `pkg_muruguard-3.6.4.zip` test build, its package row carries the wrong element (`pkg_MuRuGuardSecuritySuiteFree`). Back up first, then fix it with one SQL statement (replace `xyz_` with your real table prefix): `UPDATE xyz_extensions SET element = 'pkg_muruguard' WHERE type = 'package' AND element = 'pkg_MuRuGuardSecuritySuiteFree';`. Then install the current bundle normally (it takes the update path) or uninstall cleanly.

  3. Planned6 items
    1. PlannedTarget: v5.1.0HIGH priority

      No-execute protection for upload directories

      One-click managed rules that stop PHP executing inside media/, images/, tmp/ and cache/ — uploaded webshells become harmless junk files, even on zero-day CVEs no signature knows yet. Self-tested on apply, one-click rollback, nginx snippet included.

    2. PlannedTarget: v5.1.0HIGH priority

      Database privilege audit

      Read-only review of the site DB grants (FILE, SUPER, GRANT OPTION, …) showing how far a SQL injection could go — with the exact REVOKE statements to fix it. Report-only, never auto-changes anything.

    3. PlannedTarget: v5.1.0MEDIUM priority

      Admin action digest — who changed what

      Surfaces the security-relevant slice of Joomla's User Actions Log: extension installs, privilege grants, config and template changes — plus email alerts on new Super Users and installs.

    4. PlannedTarget: v5.1.0MEDIUM priority

      Update-server hijack watch

      Watches every Joomla update-server URL for hijacks: plain-HTTP locations, disabled core sources, and any new/changed/removed row since the recorded baseline — with change alerts.

    5. PlannedTarget: v5.1.0MEDIUM priority

      Email authentication audit (SPF / DKIM / DMARC)

      Checks the domain's SPF, DKIM and DMARC records via DNS and cross-checks the site's sender address — stopping brand spoofing and spam-foldering. Zero mail sent, read-only.

    6. PlannedTarget: v5.1.0LOW priority

      Live security-header verification

      Probes what the browser actually receives — HSTS, frame protection, content-type options, referrer and permissions policies — plus version-disclosure banners. Closes the gap between what .htaccess claims and what arrives on the wire.

MuRu Migration - J3

Joomla8 items
  1. Live now8 items
    1. CurrentHIGH priority

      Full Migration

      One export and one import moves users, groups, articles, categories, images, menus, and modules in a single ZIP, in dependency order.

    2. CurrentHIGH priority

      Dry Run Preview Mode

      Every import previews items to add, update, or skip, flags missing targets, and reports remappable references with zero database writes.

    3. CurrentMEDIUM priority

      Cross-Version ID Remapping

      Old-to-new ID maps per source site remap module assignments, alias targets, and article links to target IDs.

    4. CurrentMEDIUM priority

      Menu & Category Tree Safety

      Imported trees never reuse source lft/rgt values; menu and category trees rebuild after import without corrupting existing content.

    5. CurrentMEDIUM priority

      ZIP-Based Media Export

      Article exports ship data.json plus a media folder covering intro, full, inline, and CSS background images up to 10 MB each.

    6. CurrentMEDIUM priority

      Users, Groups & Profiles

      Password hashes preserved with no forced reset; groups matched by title and created under correct parents; profile data restored.

    7. CurrentMEDIUM priority

      Modules & SP Page Builder

      Full module config, positions, and assignments preserved; SP Page Builder content exported and restored automatically.

    8. CurrentHIGH priority

      Cross-Version Compatibility

      Export from Joomla 3, 4, 5, or 6 into any other, with schema differences and version-specific columns handled automatically.

MuRu AI-SPPB

Joomla33 items
  1. Live now6 items
    1. CurrentHIGH priority

      Prompt-to-Page in the Editor

      Generate AI Page button with a prompt modal; the editor reloads onto the finished layout for the open page.

    2. CurrentMEDIUM priority

      Uses SP Page Builder's Own AI Settings

      No separate API key; works with OpenAI gpt-* and Gemini gemini-* models and warns on weak configurations.

    3. CurrentMEDIUM priority

      Output Repaired Before Saving

      Column widths forced to valid breakpoints, settings coerced, nameless addons dropped, duplicated headings removed.

    4. CurrentHIGH priority

      Reversible by Design

      Page snapshotted to Version History first with a "Before AI generation" restore point; nothing outside the page is touched.

    5. CurrentMEDIUM priority

      Bundled SP Page Builder Knowledge

      Section, column, and addon data model with a 69-addon catalog, verified style fields, and known-good skeletons.

    6. CurrentLOW priority

      Back End Only

      Administrator editor only, behind Joomla authentication, ACL, and CSRF tokens; nothing rendered on the public site.

  2. Recently shipped27 items
    1. CompletedAddedShipped in v1.6.0MEDIUM priority

      Review before anything is written.

      Generating on a page now produces a staged preview first — section titles, per-section block lists, counts and advisory quality notes (missing headings, duplicate headings, empty sections, very large pages) — with **Apply to page** / **Discard**. Nothing touches the page until you apply; applying still snapshots to Version History first.

    2. CompletedAddedShipped in v1.6.0MEDIUM priority

      Tone dropdown

      in the Generate window (Professional, Friendly, Bold, Playful, Formal, plus a Default tone plugin setting that preselects it). The chosen tone is appended to the generation request so all copy is written in that voice.

    3. CompletedAddedShipped in v1.6.0MEDIUM priority

      Current-page outline hint

      in the Generate window (sections/blocks on the open page, via a shared read-only outline call) and a **size estimate** next to the model name (rough prompt tokens vs the configured max output tokens).

    4. CompletedAddedShipped in v1.6.0MEDIUM priority

      Regenerate one section.

      The Generate window now lists the open page's sections — pick one, describe the change, and only that section is rebuilt and swapped back into its exact position (snapshot to Version History first, as always; the new section is re-id'd against the rest of the page so styling can't collide).

    5. CompletedAddedShipped in v1.6.0MEDIUM priority

      "Improve this page" button.

      One click to lift a hand-built page: fixes responsive gaps, scales typography for mobile, fills single-item carousels, swaps `raw_html` for native addons — the layout rules applied as a linter-with-fixer. The prompt box is an optional focus hint.

    6. CompletedAddedShipped in v1.6.0MEDIUM priority

      Brand kit.

      New plugin settings for primary/secondary/accent colors, heading/body fonts and button radius. Set values go to the model as hard constraints on every generation ("buttons MUST use #…"); empty slots are auto-detected from the site template when possible, and manual values always win. The Generate window notes when a kit is active.

    7. CompletedAddedShipped in v1.6.0MEDIUM priority

      EasyStore-aware generation.

      On EasyStore Single, Collection and storefront layouts the model is now told which layout it is building, with the addon naming constraints for that context only — so Single/Collection addons land on the layouts where they render instead of pages where they'd show empty. Normal pages are untouched.

    8. CompletedAddedShipped in v1.6.0MEDIUM priority

      Privacy note:

      Regenerate-section, Improve and Translate send the current section/page JSON to your configured AI provider along with the prompt — the only features that transmit page content rather than just the prompt plus the layout rules. Nothing else leaves the site, and nothing is sent for training or telemetry.

    9. CompletedAddedShipped in v1.6.0MEDIUM priority

      Custom prompt templates.

      Save the current prompt as a named template from the Generate window; your templates appear as a "My templates" group inside the preset dropdown. Stored per-site in the plugin's own settings (no new tables).

    10. CompletedAddedShipped in v1.6.0MEDIUM priority

      Prompt history.

      Your last 10 prompts are kept per user — pick one from the new Recent prompts dropdown to re-run it.

    11. CompletedAddedShipped in v1.6.0MEDIUM priority

      Prompt-pack import/export.

      Export the template library as a `{name, prompts[]}` JSON file to share between sites; importing validates and merges it (same name updates, unknown keys are skipped and reported). Packs carry templates only — never keys or credentials.

    12. CompletedAddedShipped in v1.6.0MEDIUM priority

      Page images, picked from the Media Manager.

      The Generate window now lists the page's image settings — each row has a text field plus a Choose button opening Joomla's Media Manager; Apply writes the chosen paths back (snapshot to Version History first, as always).

    13. CompletedAddedShipped in v1.6.0MEDIUM priority

      SEO text from the same generation.

      The model may now return an optional `meta` block (title, description, Open Graph) next to the layout; when present it is written to the page's settings and Open Graph fields on apply. Older responses without it behave exactly as before.

    14. CompletedAddedShipped in v1.6.0MEDIUM priority

      Translate this page.

      The Generate window can now duplicate the open page into a new page in another language: same sections, columns and blocks in the same order with the same ids, only the text translated. A server-side structural check rejects the translation when the layout drifted (saving nothing); the new page starts as a copy — title, styling and SEO text travel with it — with its language set to the target tag. Multilingual associations wiring follows in a later release.

    15. CompletedAddedShipped in v1.6.0MEDIUM priority

      Generation activity log.

      Every successful write now records who, which page, which mode, which model, how many sections and when — prompt text is never logged. The plugin settings show the recent entries read-only, and page editors can read the same list back.

    16. CompletedAddedShipped in v1.6.0MEDIUM priority

      Bulk / CLI generation.

      `php cli/joomla.php muruai:generate --prompt="..." --page-id=N` reuses the same license check, model settings and write path as the editor (Version History snapshot first, activity logged). Without `--confirm` it only previews; add `--confirm` to write. Optional `--mode=append`, `--tone` and `--user-id`.

    17. CompletedAddedShipped in v1.6.0MEDIUM priority

      Frontend-editor support (opt-in, off by default).

      A new plugin setting also injects the Generate button into SP Page Builder's frontend editor. The same login, security token, page-edit rights and license checks apply there as in the backend, and nothing is injected for guests or users without edit rights.

    18. CompletedAddedShipped in v1.6.0MEDIUM priority

      Fill a collection item with AI.

      Opening an item (`Dynamic Content → collection → items → an item`) now shows a **Fill item with AI** button beside Save. It generates values for the item's empty text fields from the collection name, the item title and your hint, validates them against the real field definitions (unknown fields dropped, option labels mapped, email/date/number checked), saves through SP Page Builder's own item service and reloads. Fields that already have values are never overwritten; media, relationships, alias and layout fields are left untouched and reported as skipped.

    19. CompletedAddedShipped in v1.6.0MEDIUM priority

      Fill works on the new-item form too.

      The `items/create` route now shows **Fill item with AI** instead of the collection button; filling there creates the item (published, via SP Page Builder's own item service with the alias placeholder, so detail links keep working) and opens it. Creating needs SP Page Builder create rights, and the modal warns that anything already typed into the unsaved form is not used — save first to keep it.

    20. CompletedAddedShipped in v1.6.0MEDIUM priority

      AI-generate page images.

      Every row in the Page images block now has a **Generate** button next to Choose: describe the image, and it is generated (DALL-E 3, landscape, via the configured API key), verified, saved under `images/muruai/` and filled into the row — the page itself is untouched until Apply images. Needs an OpenAI key, so Gemini-configured sites get a clear message instead of a broken button.

    21. CompletedAddedShipped in v1.6.0MEDIUM priority

      Privacy note:

      AI image generation sends your image description to OpenAI's Images API along with nothing else from the site.

    22. CompletedAddedShipped in v1.6.0MEDIUM priority

      New-collection window matches the page window.

      It now uses the same two-column layout (prompt left, Options rail right) with collection template presets (blog, portfolio, team, products, testimonials, FAQ, events) on the left and Tone plus a Sample-records count (none / 3 / 5 / 8) on the right. The tone now flows into the sample records and the generated index/detail pages.

    23. CompletedAddedShipped in v1.6.0MEDIUM priority

      Privacy note:

      item autofill sends the item's current values to your configured AI provider along with the prompt — the same disclosure as Regenerate-section, Improve and Translate. Nothing else leaves the site, and nothing is sent for training or telemetry.

    24. CompletedChangedShipped in v1.6.0MEDIUM priority

      License check now follows the shared MuRu contract exactly.

      The verification call sends `extensionVersion` (read from this plugin's own manifest) alongside `productSlug`, so the dashboard can enforce version-scoped keys; the `version_mismatch` verdict (with its `maxVersion` echo) is recognised instead of degrading to `unreachable`; and `license_expires_at`, `license_product` and `license_max_version` are cached in the plugin params alongside the status, same as `com_muruguard`. No behaviour change for valid keys.

    25. CompletedChangedShipped in v1.6.0MEDIUM priority

      Generate window is now full-width with a scrollable body.

      The dialog uses the available width, while the header (with the existing close icon) and footer stay visible and all generation settings/controls remain reachable by scrolling the body.

    26. CompletedChangedShipped in v1.6.0MEDIUM priority

      Generate window reorganised into two columns.

      The prompt, templates, history, images and messages stay on the left; tone, section picker, Replace/Append mode and translate live in an "Options" rail on the right (stacked below on narrow screens). The rail hides itself when it has nothing to show.

    27. CompletedFixedShipped in v1.6.0MEDIUM priority

      Improve / regenerate-section no longer white-screens the editor.

      Both modes echo existing JSON back through the model, which sometimes returned a repeatable settings value (accordion items, filter facets, …) as an object, string or null — the editor then crashed on `e.map is not a function` after reload. Settings values that were lists in the original page but come back as non-lists are now restored from the original (matched by addon id + name; genuine model edits, including legitimately refilled repeaters, still apply). Node-level lists the sanitiser previously passed through (`child_nodes`, EasyStore `items`, `div` children) are now coerced to lists as well.

MuRu Compliance Auditor

Joomla11 items
  1. Live now11 items
    1. CurrentHIGH priority

      Whole-Site Accessibility Scan

      WCAG 2.2 A/AA static analysis of images, headings, links, forms, frames, language, page title and zoom, via a same-origin, SSRF-safe crawler.

    2. CurrentMEDIUM priority

      Findings Dashboard

      Score with breakdowns by criterion and page, trend across scans, and "how to fix in Joomla" on every finding.

    3. CurrentMEDIUM priority

      Reports & Statement

      Accessibility Statement generator (public-sector EU model template), printable HTML report, and JSON/CSV export of every finding.

    4. CurrentTarget: v1.2HIGH priority

      [Free] Table, landmark, contrast + ARIA checks

      New static checks: data-table headers, skip links and landmarks, a labeled contrast estimate, and ARIA validity.

    5. CurrentTarget: v1.2HIGH priority

      [Free] Consent Mode v2 single-signal teaser

      Free single-signal check flagging a missing ad_storage consent signal; the full four-signal audit is Pro.

    6. CurrentTarget: v1.2HIGH priority

      [Free] EAA-style statement template

      Second Accessibility Statement template for private-sector EAA conformity documentation, alongside the public-sector EU model.

    7. CurrentTarget: v1.2MEDIUM priority

      [Free + Pro] Admin quick-icon with live score

      Joomla control-panel quick-icon showing the latest site score at a glance.

    8. CurrentTarget: v1.2HIGH priority

      [Pro] Dated PDF audit report

      Scoped, standard-mapped PDF stamped with the scan date — the record a regulator, insurer or procurement officer asks for.

    9. CurrentTarget: v1.2HIGH priority

      [Pro] Report integrity hash + public verification page

      SHA-256 of the exact scan embedded in every PDF; a public page re-computes and confirms it.

    10. CurrentTarget: v1.2HIGH priority

      [Pro] Scheduled scans (Joomla Scheduler)

      Recurring scans through Joomla's native Scheduler — the basis of stay-compliant monitoring.

    11. CurrentTarget: v1.2HIGH priority

      [Pro] Regression alerts (email + webhook)

      Alerts on new findings or score drops; Slack, Discord and Telegram channels follow in 1.3.

Wordpress Debug Manager Pro

WordPress8 items
  1. Live now8 items
    1. CurrentHIGH priority

      Debug Controls

      Toggle WP_DEBUG, WP_DEBUG_LOG, and SCRIPT_DEBUG with automatic backup and no file editing.

    2. CurrentHIGH priority

      Error Tracking

      PHP errors captured with full stack traces, grouped duplicates, and Critical/Warning/Notice severity labels.

    3. CurrentMEDIUM priority

      Log Viewer

      Browse and search debug.log in-dashboard with type and severity filters, download, and one-click clear.

    4. CurrentMEDIUM priority

      Performance Monitoring

      Per-request execution time with memory and peak usage, updated live in the admin panel.

    5. CurrentMEDIUM priority

      Auto Disable Debug

      Timer-based auto-disable so debug mode never stays on in production by accident.

    6. CurrentLOW priority

      Email Alerts

      Notifications for critical PHP errors with configurable recipients and threshold.

    7. CurrentLOW priority

      Snapshot Export

      Full debug state exported as JSON to share with developers.

    8. CurrentLOW priority

      Event Timeline

      Chronological log of system changes and debug-setting toggles.

MuRu Guard - J3

Joomla16 items
  1. Live now15 items
    1. CurrentHIGH priority

      Joomla 3 Compatible Pro Build

      Full MuRu Guard Pro protection for Joomla 3 sites that can no longer update.

    2. CurrentHIGH priority

      Legacy Stack Coverage

      Built for sites stuck on un-updatable SP Page Builder, Helix, EasyStore, or SP Property Finder versions.

    3. CurrentHIGH priority

      Protection Mode

      Companion plugin inspects every site request, with manual IP allow/block lists (CIDR), cached fail-open country blocking, and scanner, bot, and brute-force login blocking.

    4. CurrentHIGH priority

      Active Web Application Firewall (Pro)

      Blocks SQL injection, XSS, file inclusion, and command-injection patterns in real time, including a signature for Joomla's CVE-2023-23752 webservices probe; broad matches log only.

    5. CurrentHIGH priority

      Filesystem Scan

      Scans media, images, templates, tmp, cache, and webroot; cross-references Joomla's extension registry to catch spoofed extensions; flags suspicious PHP, phtml, phar, and shtml files.

    6. CurrentMEDIUM priority

      Core Integrity

      Checks Joomla entry points for prepended payloads, verifies supported core files with SHA-256 hashes, and scans MuRu Guard's own extension files too.

    7. CurrentMEDIUM priority

      File Integrity Monitoring (Pro)

      Baseline-hash every file once, then flag silent changes; drift alerts use the same email, Slack, Discord, and Telegram pipeline as scheduled scans.

    8. CurrentMEDIUM priority

      Database Scan

      Finds Helix Ultimate mega-menu XSS payloads, checks SP Page Builder asset rows for injected code, and reports template defacement strings.

    9. CurrentHIGH priority

      Smart AI Assistant (Pro)

      Chat assistant that lists, searches, reads, and edits project files with guarded paths, explicit confirmation for destructive actions, and a full audit log.

    10. CurrentHIGH priority

      TimeMachine Backup & Restore (Pro)

      Every AI repair saves a verified snapshot first; one-click undo for a single file or a whole request, covering files and database rows.

    11. CurrentMEDIUM priority

      Autopilot Mode (Pro)

      Scheduled scans auto-remove near-zero-false-positive threats after an independent AI-verification pass; opt-in, everything restorable via TimeMachine.

    12. CurrentMEDIUM priority

      Automations & Alerts (Pro)

      Cron-token scheduled scans with email, Slack, Discord, and Telegram alerts, Fleet Dashboard reporting, and bulk re-scan and hardening pushes.

    13. CurrentMEDIUM priority

      Smart False-Positive Handling

      One-click safe marking tied to exact reviewed content, with automatic re-alerts if the same file is compromised later.

    14. CurrentLOW priority

      .htaccess Hardening Advisor

      Read-only checks for PHP execution blocking and sensitive-file protection, with copy-paste rules that never edit the file.

    15. CurrentMEDIUM priority

      Pro Analysis Toolkit (Pro)

      Snippet and IOC code search, reversible quarantine, custom PCRE signatures, and a read-only PHP, Joomla, and extension update audit.

  2. Planned1 item
    1. PlannedTarget: v3.0.0HIGH priority

      v5.0.0 feature parity port (Pro)

      Port of the v5.0.0 feature set to the Joomla 3 line: VEL cross-check, virtual patching, configuration audit, secret admin URL, 2FA enforcement, exposure probes, honeypots, reputation watch, and the weekly digest.

MuRu Reviews

Joomla31 items
  1. Recently shipped21 items
    1. CompletedAddedShipped in v1.0.0MEDIUM priority

      Show Google reviews anywhere.

      Module position, `{murureviews}` shortcode in any article, full-page menu item, or the MuRu Reviews SP Page Builder addon — all reading the same data, so they never disagree.

    2. CompletedAddedShipped in v1.0.0MEDIUM priority

      5-minute setup.

      Paste your Google Place ID + API key (finder and setup links built in), pick your layout and count, hit Refresh Now. Done — your average rating, total count, and reviews appear.

    3. CompletedAddedShipped in v1.0.0MEDIUM priority

      Layouts for every spot.

      Cards, List, and a Basic carousel in Free; Masonry, Testimonial, and Badge in Pro. Star ratings fill accurately (a 4.8 shows four full stars plus a partial one), with your exact score kept for screen readers and search engines.

    4. CompletedAddedShipped in v1.0.0MEDIUM priority

      Show what matters.

      Minimum-rating and review-count controls everywhere (`0` = show everything); Pro adds keyword search and per-source filtering.

    5. CompletedAddedShipped in v1.0.0MEDIUM priority

      Your own reviews too (Pro).

      Paste custom testimonials as JSON (sample file included) and they merge with Google reviews under one combined score.

    6. CompletedAddedShipped in v1.0.0MEDIUM priority

      More sources coming.

      Settings already lists Trustpilot, JED, Facebook, Tripadvisor, Yelp, G2, and Capterra — each will simply switch on in a future update. No reinstall, no new setup.

    7. CompletedAddedShipped in v1.0.0MEDIUM priority

      Simple admin.

      A clean Dashboard (status, score, cache, one-click refresh) plus a Settings page with General options and a License tab — all in familiar Joomla styling, no learning curve.

    8. CompletedAddedShipped in v1.0.0MEDIUM priority

      Fast and private.

      Reviews are fetched on your server and cached — visitors never wait on Google, and no visitor data goes to Google.

    9. CompletedAddedShipped in v1.0.0MEDIUM priority

      Never a broken page.

      Clear, friendly messages explain every state (not configured yet, no texts returned, filters too narrow) instead of blank areas or errors.

    10. CompletedAddedShipped in v1.0.0MEDIUM priority

      Show Google reviews anywhere.

      Module position, `{murureviews}` shortcode in any article, full-page menu item, or the MuRu Reviews SP Page Builder addon — all reading the same data, so they never disagree.

    11. CompletedAddedShipped in v1.0.0MEDIUM priority

      5-minute setup.

      Paste your Google Place ID + API key (finder and setup links built in), pick your layout and count, hit Refresh Now. Done — your average rating, total count, and reviews appear.

    12. CompletedAddedShipped in v1.0.0MEDIUM priority

      Layouts for every spot.

      Cards, List, and a Basic carousel in Free; Masonry, Testimonial, and Badge in Pro. Star ratings fill accurately (a 4.8 shows four full stars plus a partial one), with your exact score kept for screen readers and search engines.

    13. CompletedAddedShipped in v1.0.0MEDIUM priority

      Show what matters.

      Minimum-rating and review-count controls everywhere (`0` = show everything); Pro adds keyword search and per-source filtering.

    14. CompletedAddedShipped in v1.0.0MEDIUM priority

      Your own reviews too (Pro).

      Paste custom testimonials as JSON (sample file included) and they merge with Google reviews under one combined score.

    15. CompletedAddedShipped in v1.0.0MEDIUM priority

      More sources coming.

      Settings already lists Trustpilot, JED, Facebook, Tripadvisor, Yelp, G2, and Capterra — each will simply switch on in a future update. No reinstall, no new setup.

    16. CompletedAddedShipped in v1.0.0MEDIUM priority

      Simple admin.

      A clean Dashboard (status, score, cache, one-click refresh) plus a Settings page with General options and a License tab — all in familiar Joomla styling, no learning curve.

    17. CompletedAddedShipped in v1.0.0MEDIUM priority

      Fast and private.

      Reviews are fetched on your server and cached — visitors never wait on Google, and no visitor data goes to Google.

    18. CompletedAddedShipped in v1.0.0MEDIUM priority

      Never a broken page.

      Clear, friendly messages explain every state (not configured yet, no texts returned, filters too narrow) instead of blank areas or errors.

    19. CompletedTarget: v1.0.0HIGH priority

      Google reviews end to end

      Place ID + API key setup, fetch and normalize reviews, average rating, total count, and Google attribution on every render.

    20. CompletedTarget: v1.0.0HIGH priority

      Module, shortcode, menu page & SP Page Builder addon

      Four display paths sharing one setup and one cache, so placements never disagree.

    21. CompletedTarget: v1.0.0HIGH priority

      Pro: manual reviews, extra layouts & smart filters

      Custom testimonials merged under one combined score, Masonry/Testimonial/Badge layouts, and keyword + source filters on every path.

  2. Up next4 items
    1. UpcomingHIGH priority

      Multiple Google locations

      Connect more than one Business Profile location under a single setup. Pro.

    2. UpcomingHIGH priority

      Trustpilot + JED connectors

      First new review sources behind their official APIs -- no scraping, ever. Pro.

    3. UpcomingMEDIUM priority

      More layouts: Slider, Minimal, Dark, Summary, Wall

      Five more one-click layouts across all four display paths. Pro.

    4. UpcomingMEDIUM priority

      Date filter & review moderation

      Narrow by recency and curate which reviews show. Pro.

  3. Planned6 items
    1. PlannedMEDIUM priority

      Facebook, Yelp & Tripadvisor connectors

      Local and hospitality review sources via official APIs. Pro.

    2. PlannedMEDIUM priority

      G2, Capterra & more software sources

      Software-review platforms for SaaS and agency sites. Pro.

    3. PlannedMEDIUM priority

      Aggregated multi-source rating wall

      One combined score and wall across every connected source. Pro.

    4. PlannedLOW priority

      Scheduled refresh & advanced cache

      Automatic refresh on a schedule with per-source TTL control. Pro.

    5. PlannedLOW priority

      Review-request tools: QR, links & landing page

      Collect more reviews with shareable request links, QR codes, and a landing page. Pro.

    6. PlannedLOW priority

      Analytics dashboard & white label

      Rating trends over time plus unbranded output for client work. Pro.