FAQs

Frequently Asked Questions

Is MuRu Guard publicly accessible?

No. It runs inside the Joomla administrator and relies on Joomla authentication, sessions, ACL, and CSRF tokens.

Does it only scan SP Page Builder infections?

No. It includes targeted coverage for SPPB and JCE compromise patterns, but also checks common webshell signatures, core entry-point tampering, suspicious files, rogue Super Users, and database injections.

Can it block attacks in real time?

Yes, when the companion MuRu Guard Shield plugin is installed, enabled, and Protection Mode is turned on from the scanner settings.

Can admins delete any file with it?

No. Delete actions are scoped to items flagged in the current scan run, with protected Joomla folders kept out of destructive actions.

Should I update SP Page Builder before scanning?

Yes. Update SP Page Builder to 6.6.2 or later first, otherwise the same vulnerability can be exploited again after cleanup.

Can regular Administrators use this, or only Super Users?

By default, only Super Users. You can grant access to other groups afterwards through Joomla's own System > Users > Access Levels.

If I mark a finding as safe, could that hide a real future compromise?

No. Dismissals are fingerprinted against the exact finding text reviewed at the time. If that same file or database row is ever genuinely compromised later, its content changes, the fingerprint stops matching, and it reappears as a fresh finding automatically.

Does the Smart AI Assistant upload my whole site to the cloud?

No. Your codebase is never uploaded or indexed anywhere. The assistant runs its file tools locally on your own server, and only the tool it wants to run, the arguments it passes, and that tool's result travel over the network for each turn.

Can the AI assistant edit or delete anything on my site?

No. Joomla's core framework directories, configuration.php, entry-point index.php files, and MuRu Guard's own files are all off-limits. Destructive actions need your explicit confirmation, and every action is audit-logged.

What are AI Integrations for?

They connect your install to the AI provider that powers the Smart AI Assistant, configured once at the account level so every site under the same license can use it.

What happens to the Pro features if my license expires?

Scanning, cleanup, Protection Mode, and the .htaccess advisor keep working as normal. File Integrity Monitoring, the Web Application Firewall, the Smart AI Assistant, Fleet Dashboard reporting, and the alert channels lock until the license is active again. Your data stays on disk and comes back untouched when it is.

Do I need to create an account to use the free scanner?

No. Download it from GitHub, install it like any other Joomla extension, and every core scanning, cleanup, Protection Mode, and .htaccess advisory feature works immediately with no account or license key.