Lyzerslab

What's new in v4.6.0

Incident response mode ("I'm hacked")

When you suspect the site is already compromised, Incident response mode (Pro) compresses the first panicked hour into one click plus a checklist. Find it on the dashboard's Incident Response card.

What "Activate containment" does

Three automatic steps run immediately, each reported individually so a hiccup on one never silently skips the others:

  1. Access baseline snapshot — records every current Super User (username, email, password hash, block state). Attackers demote or lock out the real admin first; the snapshot is what the protected-users watcher compares against afterwards.
  2. Admin Lockdown on — the extension installer and new-backend-user creation are blocked while Lockdown is enabled.
  3. Session sweep — every session except your own is destroyed, attacker sessions included. You stay logged in; everyone else must log in again.

Re-running containment while an incident is active simply refreshes all three steps.

The 8-step checklist

After containment, the card shows eight steps with per-step tracking. The three automatic steps above can never be ticked by hand — only a real containment run sets them, so containment evidence can't be faked. The five manual steps are yours to work top to bottom:

  1. Run a full scan
  2. Review every finding
  3. Clean or quarantine threats
  4. Rotate credentials
  5. Re-scan and confirm clean

Resolving

Resolve incident closes the checklist — and deliberately leaves Admin Lockdown on. Removing protection is a separate conscious decision on the Protection panel, never a side effect of declaring the incident over.

Joomla 3

Identical on the Joomla 3 edition (v2.3.0): same card, same steps, same Pro gate. Free viewers see a locked upsell card on both editions.