What's new in v4.6.0
Incident response mode ("I'm hacked")
When you suspect the site is already compromised, Incident response mode (Pro) compresses the first panicked hour into one click plus a checklist. Find it on the dashboard's Incident Response card.
What "Activate containment" does
Three automatic steps run immediately, each reported individually so a hiccup on one never silently skips the others:
- Access baseline snapshot — records every current Super User (username, email, password hash, block state). Attackers demote or lock out the real admin first; the snapshot is what the protected-users watcher compares against afterwards.
- Admin Lockdown on — the extension installer and new-backend-user creation are blocked while Lockdown is enabled.
- Session sweep — every session except your own is destroyed, attacker sessions included. You stay logged in; everyone else must log in again.
Re-running containment while an incident is active simply refreshes all three steps.
The 8-step checklist
After containment, the card shows eight steps with per-step tracking. The three automatic steps above can never be ticked by hand — only a real containment run sets them, so containment evidence can't be faked. The five manual steps are yours to work top to bottom:
- Run a full scan
- Review every finding
- Clean or quarantine threats
- Rotate credentials
- Re-scan and confirm clean
Resolving
Resolve incident closes the checklist — and deliberately leaves Admin Lockdown on. Removing protection is a separate conscious decision on the Protection panel, never a side effect of declaring the incident over.
Joomla 3
Identical on the Joomla 3 edition (v2.3.0): same card, same steps, same Pro gate. Free viewers see a locked upsell card on both editions.
