What's new in v4.6.0
Privileged login alerts
Brute-force blocking assumes the attacker guesses wrong. Privileged login alerts (Pro) cover the scarier case: a login with the right (stolen) password, which otherwise walks past every block silently.
How it works
When a Super User, Administrator, or Manager logs in from an IP address or country never seen for that account, MuRu Guard emails the alert address a "was this you" notice — account, location, and time — and remembers the location so it alerts only once per new location.
- Opt-in, off by default: enable Privileged login alerts under Site Protection → Login protection. Saving forces it back off if the Pro license isn't active.
- Requires a Pro license, Shield 1.6.0 or later installed and enabled, and an alert email address configured.
- Never blocks: alerting is notify-only. If the database, mailer, or helper is unavailable, the login proceeds 100% unaffected.
- An absent country signal (no GeoIP data for the IP) is never treated as a "new country" — missing signal must not page you.
What counts as "privileged"
Anyone with the core.admin privilege (Super Users), plus members of the Administrator and Manager groups by Joomla's default titles.
Storage
First-seen locations live in a stub-protected data file under the component: up to 25 remembered IPs and 25 countries per user, 500 users max, entries idle over a year pruned automatically.
Joomla 3
Same feature on the Joomla 3 edition (v2.3.0), needing Shield 2.1.0 or later instead of 1.6.0.
