Core Features

Feature Overview

  • Protection Mode -- companion plugin checks every site request, manual IP allow/block list with CIDR support, country blocking, bad user-agent/brute-force blocking.
  • Active Web Application Firewall (Pro) -- blocks generic SQL injection, XSS, local/remote file inclusion, and command-injection patterns in real time.
  • Filesystem Scan -- scans media, images, templates, tmp, cache, and webroot paths; cross-references Joomla's own extension registry.
  • Core Integrity -- checks Joomla entry points for prepended payloads, verifies supported core files with SHA-256 hashes.
  • File Integrity Monitoring (Pro) -- baseline-hashes every file once, then flags any that silently change since.
  • Database Scan -- finds Helix Ultimate mega-menu XSS payloads, SPPB asset table injections, template defacement strings.
  • Smart AI Assistant (Pro) -- chat with an assistant that can list, search, read, and edit your project files, with every action audited.
  • Backup & Restore (Pro) -- every AI repair and cleanup action automatically saves a verified, SHA-256-checked snapshot first, restorable with one click, per file or for a whole multi-file request.
  • Automations & Alerts (Pro) -- scheduled scans, email alerts, Slack/Discord/Telegram channels, Fleet Dashboard reporting.
  • Smart False-Positive Handling -- mark any finding as safe with one click, tied to the exact content reviewed.
  • .htaccess Hardening Advisor -- checks for PHP execution blocking in upload folders and other hardening gaps, suggests copy-paste rules.