What's new in v5.0.0
Virtual patching for fresh CVEs
When a CVE drops and you cannot update yet — template overrides, legacy builders, client freeze — virtual patching (Pro) closes the window: narrow per-CVE firewall rules block the exploit request itself until the real update lands.
How it works
Each rule names one component, one request parameter, and one tight pattern, and carries an expiry date. Shield evaluates rules before its generic signatures; the narrowest match wins, every match is logged with the CVE in the reason, and blocking applies only while the Block virtual-patch matches toggle is on under Site Protection > Request blocking. Expired rules automatically drop to log-only so a stale patch can never block legitimate traffic forever.
Verify before you trust
The Test-a-Request simulator (Settings > Analysis) evaluates the same rules against any URL you paste, showing exactly what a patch would block — and what it would leave alone — before you rely on it.
Joomla 3
Coming to the Joomla 3 edition with v3.0.0 (Shield rules with v2.2.0).
