What's new in v5.0.0
Privileged 2FA enforcement
Weak privileged credentials cause most Joomla compromises. 2FA enforcement (Pro, Site Protection > Hardening) makes sure every Super User and Administrator actually enrolls a two-factor method — in two stages, so nobody is surprised.
How it works
With the nag toggle on, privileged accounts without MFA see a backend banner linking straight to enrollment. With enforcement on, logins without MFA are signed out after a 7-day grace with a plain-English reason. A MFA-ENFORCE-BYPASS.txt file covers emergencies, and imported accounts without a grace record nag but never hard-refuse.
Pairs with the account audit
The account-hygiene audit (v4.6.0) already shows which privileged accounts lack MFA — use it to see the gap, enforcement to close it.
Joomla 3
Coming to the Joomla 3 edition with v3.0.0 (Shield hooks with v2.2.0).
