Lyzerslab

What's new in v5.0.0

Privileged 2FA enforcement

Weak privileged credentials cause most Joomla compromises. 2FA enforcement (Pro, Site Protection > Hardening) makes sure every Super User and Administrator actually enrolls a two-factor method — in two stages, so nobody is surprised.

How it works

With the nag toggle on, privileged accounts without MFA see a backend banner linking straight to enrollment. With enforcement on, logins without MFA are signed out after a 7-day grace with a plain-English reason. A MFA-ENFORCE-BYPASS.txt file covers emergencies, and imported accounts without a grace record nag but never hard-refuse.

Pairs with the account audit

The account-hygiene audit (v4.6.0) already shows which privileged accounts lack MFA — use it to see the gap, enforcement to close it.

Joomla 3

Coming to the Joomla 3 edition with v3.0.0 (Shield hooks with v2.2.0).