New: earn free months on your Pro license
Share MuRu Guard Pro in a Joomla community or leave a review, submit the link from My Products, and get 15 days added to your license once we verify it -- as many links as you want to share.
Need custom Joomla work too?
Joomla Customizations Support -- ongoing module/template tweaks, bug fixes, and small feature builds, submitted right from your dashboard. Starter plan from USD 30.00, lifetime.
Start protecting your site in 3 steps
Install in ~2 minutes
Download the Free package and install it from System > Install Extensions -- no account, no license key, no setup wizard.
Run your first scan
Open Components > MuRu Guard (Dashboard). Results are grouped by confidence so you know what to look at first -- and every finding shows why it was flagged.
Clean up & stay protected
Remove findings with guided actions, turn on Protection Mode to block live attacks, and let scheduled scans and alerts watch the site for you.
Before scanning a compromised site, close the entry point:
- 1.Update SP Page Builder to 6.6.2 or later.
- 2.Update or remove JCE if it is installed.
- 3.Take a full backup and run the first scan on staging when possible.
Which one sounds like you?
Pick your situation -- every path starts with the same free scan.
“My site was just hacked”
ProGoogle flagged you, your host suspended the account, or the homepage defaced overnight.
- One-click containment snapshots Super Users, locks the admin, and signs out every other session
- Guided 8-step recovery checklist: scan, review, cleanup, rotate credentials, re-scan
- Every cleanup is TimeMachine-snapshotted, so a wrong delete is one click to undo
“We run SP Page Builder / Helix sites”
Free + ProThe uploadCustomIcon RCE hit exactly your stack -- and generic scanners don't know these frameworks exist.
- Signatures built from that real campaign: SPPB asset rows, Helix mega-menu params, JCE paths
- File Integrity Monitoring baselines your template files to catch hand-inserted payloads
- The AI assistant explains findings in your actual SPPB/Helix codebase, not generic PHP
“I manage dozens of client sites”
ProLogging into every administrator to check scan state doesn't scale -- and clients ask for proof.
- Fleet Dashboard shows every site's scan state on one screen
- Bulk re-scan or push a hardening config to all licensed sites at once
- Scheduled scans alert Slack, Discord, or Telegram the moment a finding appears
“My host sent me a malware sample”
ProYou got an indicator of compromise and need to know everywhere it hides on the site.
- Search code by snippet finds every file containing the pasted fragment, literal or regex
- Suspicious hits go to Quarantine reversibly instead of a permanent delete
- Send any hit to the AI assistant for a plain-language verdict
“I'm not a security expert”
ProYou own the site but can't read a webshell -- you need the tool to explain and fix safely.
- Ask the Smart AI Assistant about any finding in plain language; it opens the file and explains
- Proposed fixes show a line-by-line diff and need your click before anything runs
- Joomla core, configuration.php, and the scanner itself are fenced off in code, not by promise
“Stay clean -- and prove it”
ProCompliance, clients, or your own sleep need evidence the site is watched, not just “we scanned once”.
- Scheduled scans plus File Integrity Monitoring catch drift between visits
- A weekly digest emails ALL-CLEAR or NEEDS-REVIEW -- silence itself means cron or mail broke
- Audit log records every AI change with approver and timestamp
SP Page Builder & Helix Expertise, Full Joomla Protection
Most Joomla security scanners are generic -- the same signature list regardless of what your site is actually built with. MuRu Guard isn't: it exists because of one specific, real campaign against SP Page Builder's uploadCustomIcon RCE and the Helix Ultimate mega-menu XSS payloads that followed it, and every detection signature in this scanner was built and refined against real infections from that campaign -- not a generic malware wordlist.
If your site (or a client's) runs SP Page Builder or a Helix-framework template, that's not a coincidence you have to explain to a generic scanner -- it's exactly the case this tool was built to understand. Core entry-point tampering, rogue iconfont registrations in the SPPB asset table, Helix-specific mega-menu injection markers, template-styles defacement -- these are checks a generic scanner doesn't run at all, because it doesn't know these frameworks exist.
No SP Page Builder or Helix? You don't need them.
MuRu Guard scans and protects your full Joomla site either way -- core files, third-party extensions, templates, the database, and incoming requests. The SP Page Builder and Helix checks above are extra coverage for those frameworks, not a requirement to use the scanner.
Built from a real campaign, not a wordlist
Every SPPB/Helix signature in this scanner traces back to an actual compromise, verified against real infected sites -- not copied from a generic malware-pattern list.
Pro extends that specialization further
File Integrity Monitoring baselines your SPPB/Helix template files specifically, so a payload hand-inserted into a file you already trust doesn't need to match a known pattern to get caught. The Smart AI Assistant reads and explains findings in the context of your actual SPPB/Helix codebase, not generic PHP.
Framework-aware, not just Joomla-aware
Checks the SP Page Builder asset table, Helix Ultimate's mega-menu params, and JCE's known secondary-infection paths specifically -- the places a compromise on these frameworks actually shows up.
Still free at its core
Every signature above -- SPPB, Helix, JCE -- runs in the free edition with no restrictions. Pro adds depth (integrity monitoring, an AI assistant that knows your stack, broader request-level protection), not the framework-specific detection itself.
Everything it does
Filter by job. Tags show what's free and what's Pro.
Filesystem scanFree
Media, images, templates, tmp, cache and webroot. Flags suspicious PHP, phtml, phar, shtml.
Core integrityFree
Entry-point payloads and SHA-256 checks of core files, including its own files.
Database scanFree
Helix mega-menu XSS, SPPB asset rows, template defacement strings.
Registry cross-checkFree
Spots fake templates, modules, plugins and components via Joomla's extension table.
Rogue users and signaturesFree
Attacker-pattern Super Users; eval/base64, c99/r57/WSO shells, stream wrappers, chr-array decoding.
Search code by snippetPro
Paste an indicator and find every file containing it, literal or regex.
Vulnerable-extension checkPro
Matches extensions against Joomla's Vulnerable Extensions List.
Update auditPro
PHP/Joomla versions, SPPB and JCE status, outdated extensions -- read-only.
Custom signaturesPro
Your own PCRE patterns, validated before they can touch a scan.
Content SEO-spam scanPro
Articles and Custom HTML modules checked through the standard finding pipeline.
Protection ModeFree
Shield plugin logs and optionally blocks webshell, SPPB RCE and drop-filename requests.
IP, country and bot rulesFree
CIDR allow/block lists, cached GeoIP, bad user agents and brute-force blocking.
Admin LockdownFree
Blocks the installer and new backend users; auto-reverts demoted Super Users.
Active WAFPro
SQLi, XSS, LFI/RFI and command injection, with CVE-2023-23752 coverage.
Virtual patchingPro
Per-CVE rules block the exploit request until you can update.
Privileged login alertsPro
Email on a privileged login from a never-before-seen IP or country. Alerting never blocks.
Temporary IP blocksPro
1h/24h/7d blocks straight from the Protection Log.
Guided cleanupFree
Scoped delete, menu params cleanup and rogue SPPB row removal.
Smart false positivesFree
Dismissals are fingerprinted to content and reappear if the file changes.
QuarantinePro
Renamed so it can't execute, skipped by scans, restorable in one click.
TimeMachinePro
Verified snapshots before every repair; restore files and database rows.
“I'm hacked” modePro
One-click containment and an 8-step recovery checklist.
Scheduled scans and emailFree
Secret cron-token URL; results by email.
Slack, Discord, TelegramPro
Webhook and bot alerts for the whole team.
Fleet DashboardPro
Every site in one view, with bulk re-scan and hardening push.
Autopilot ModePro
Removes near-zero-false-positive threats on schedule, AI-verified and restorable. Off by default.
Weekly security digestPro
Plain-text ALL-CLEAR or NEEDS-REVIEW email on a 6-day cadence.
Findings exportPro
CSV/JSON export of the exact finding set; snippets excluded by default.
.htaccess advisorFree
Reads your real file and suggests copy-paste rules. Never edits it.
File Integrity MonitoringPro
SHA-256 baseline drift catches payloads in trusted files.
Config, 2FA and exposure auditsPro
17 Global Configuration checks, 2FA enforcement, exposure probes with one-click deny.
Secret admin URL and canariesPro
Hidden /administrator plus honeypot file and decoy admin.
Account-hygiene auditPro
Privileged accounts missing MFA, still named admin, or dormant past your threshold.
Scheduled-task auditPro
Flags orphaned routines, failed runs, and overdue or brand-new tasks.
Runtime verification and TLS watchPro
Live probes of enforced headers and guards; warns inside the 14-day certificate window.
Reputation and blocklist watchPro
Google Safe Browsing and Spamhaus ZEN self-checks; emails only on transitions.
Smart AI AssistantPro
List, search, read, edit, rename and delete files by chat, with confirmation and audit log.
Hard fencesPro
Core, configuration.php, entry points and MuRu Guard are blocked in PHP and hidden.
Custom SkillPro
Your conventions (up to 64 KB) are added every turn and stored on your server.
Private by designPro
File tools run locally; only tool names, arguments and results cross the network.
AI IntegrationsPro
Account-level provider connection shared by every install under the license.
Free vs Pro — Full Breakdown
Free is a complete scanner, cleaner, and real-time shield for a single site. Pro is for teams that must stay clean and prove it — integrity monitoring, AI-assisted repair, scheduled scans with alerts, and multi-site reporting.
| Capability | Free | Pro |
|---|---|---|
| Scanning & detection | ||
| Filesystem, database & core-integrity malware scan | ||
| SP Page Builder, Helix & JCE compromise signatures | ||
| Webshell, rogue Super User & injection checks | ||
| Live VEL vulnerable-extension cross-check | — | |
| Search code by snippet (find any pasted IOC) | — | |
| Update audit (PHP, Joomla, SPPB, JCE, outdated extensions) | — | |
| New-since-last-scan filter & findings export | — | |
| Cleanup & recovery | ||
| Guided cleanup with protected-folder safety | ||
| Smart false-positive handling (fingerprinted dismissals) | ||
| Quarantine with one-click restore | — | |
| TimeMachine — verified one-click backup & restore | — | |
| “I'm hacked” incident mode — containment + 8-step recovery | — | |
| Real-time protection | ||
| Protection Mode plugin (IP, country & user-agent blocking) | ||
| Active Web Application Firewall (SQLi, XSS, LFI/RFI, command injection) | — | |
| Virtual patching — per-CVE firewall rules | — | |
| Temporary IP blocks | — | |
| Secret administrator URL | — | |
| Honeypot file & decoy-admin canaries | — | |
| .htaccess hardening advisor | ||
| AI & automation | ||
| Smart AI Assistant (chat triage, audited repair) | — | |
| Autopilot Mode (AI-verified auto-removal on scheduled scans) | — | |
| Custom detection signatures | — | |
| Scheduled scans | ||
| Scheduled email alerts | ||
| Slack, Discord & Telegram channels | — | |
| Weekly all-clear security digest | — | |
| Audits & hardening | ||
| File Integrity Monitoring (SHA-256 baseline drift) | — | |
| Privileged login alerts (new IP or country) | — | |
| Account hygiene, SEO-spam & scheduled-task audits | — | |
| Runtime hardening verification & TLS expiry watch | — | |
| Global Configuration security audit (17 checks) | — | |
| Privileged 2FA enforcement | — | |
| Sensitive-file exposure probes + one-click deny | — | |
| Reputation & blocklist self-watch | — | |
| Scale & support | ||
| Single-site operation | ||
| Fleet Dashboard multi-site reporting | — | |
| Native Joomla Extensions > Update delivery | ||
| Priority email support | — | |
Free stays free: scanning, cleanup, Protection Mode, and the .htaccess advisor keep working with no account or license. If a Pro license expires, the Pro rows above lock until it is active again — your integrity baseline, audit log, and custom Skill stay on disk untouched.
What's New
Latest fixes and additions, released to both Free and Pro unless noted:
Secret administrator URL (Pro)
Your /administrator login hides behind a secret address only you know -- strangers get a blank 404 with no MuRu branding, while a recovery file plus automatic login-page fallback mean you can never lock yourself out. Set it in one field under Site Protection.
Live vulnerable-extension cross-check (Pro)
Every installed extension is matched against Joomla's official Vulnerable Extensions List and flagged VULNERABLE or Verify with a link to the listing -- an independent second signal beside the built-in update audit. Read-only card in the Analysis tab.
Virtual patching for fresh CVEs (Pro)
Between a CVE disclosure and your update window, narrow per-CVE firewall rules block the exploit request itself -- named component, named parameter, tight pattern, automatic expiry. Test-a-Request previews exactly what each patch would block before you trust it.
Global Configuration security audit (Pro)
17 read-only checks over the hardening settings scans cannot see: debug output, error verbosity, cookie flags, session handling, forced HTTPS, FTP layer, webservices, MFA availability, and more -- each row deep-links to where you change it in Joomla.
Privileged 2FA enforcement (Pro)
Super Users and Administrators without multi-factor login first get a nag banner, then -- after a 7-day grace -- are signed out until they enroll. A bypass file covers emergencies, and imported accounts never hard-refuse without a grace record.
Sensitive-file exposure probes + one-click deny (Pro)
Live probes confirm whether configuration backups and other sensitive files are reachable over HTTP, and one click installs a managed, self-tested .htaccess deny block (backup and rollback included) -- plus a ready snippet for nginx.
Honeypot canaries (Pro)
Plant a self-tripping decoy file and a blocked decoy Super User account: real attackers touch them, legitimate traffic never does, and the scheduled check emails you the moment one trips.
Reputation and blocklist watch (Pro)
Scheduled self-checks against Google Safe Browsing and the Spamhaus ZEN list email you only on transitions -- newly listed or recovered -- with a two-read confirmation so a single flaky lookup never pages you.
Overview
MuRu Guard installs like a standard Joomla extension and runs inside the administrator area. It uses Joomla's own authentication and permission system, so there is no separate scanner URL, access key, or public file to remove later.
The scanner focuses on real-world compromise patterns linked to SP Page Builder's uploadCustomIcon vulnerability, suspicious JCE paths, core entry-point tampering, rogue Super Users, and database payloads commonly seen after Joomla attacks.
Finding the problem is only half the job, so the component also ships the parts that come after it: a live request-blocking plugin, scheduled scans that push results to your team's chat, and a Smart AI Assistant that can open the flagged file, explain what it is looking at, and write the fix -- without ever being able to touch Joomla core or the scanner's own code.
Detection Details
Content signatures
Detects eval/base64 payloads, cookie-gated backdoors, c99/r57/WSO-style shells, stream-wrapper loading, chr-array decoding, and script injection.
Extension registry cross-check
Cross-references Joomla's own #__extensions table to catch fake templates, modules, plugins, and components -- a harder-to-fake signal than filesystem structure alone, since an attacker can spoof a folder and its manifest but not an enabled registry row.
Filename patterns
Matches known malware-drop naming, duplicate configuration files, random numeric drop folders, and suspicious top-level webroot items.
JCE coverage
Applies tuned heuristics for its upload pipeline and editor bootstrap files -- including media/com_jce and components/com_jce.
Rogue users
Flags Super User accounts with attacker-pattern names or suspicious local email domains.
Confidence scoring
Labels findings as High or Medium so administrators can prioritize review.
Guided actions
Offers scoped delete or reversible quarantine, surgical menu params cleanup, rogue SPPB asset row deletion, custom-signature matching, and one-click false-positive dismissal for current scan findings.
Protection Mode
On-demand scanning finds problems after they happen. Protection Mode, powered by the optional MuRu Guard Shield plugin, checks requests as they reach Joomla and records matches in a sectioned Protection Log.
Protection Mode
Master switch that detects and logs every match.
Attack Blocking
Optional 403 block for high-confidence webshell, SPPB RCE, and known drop-filename matches.
Brute-Force Blocking
Optional IP blocking after repeated failed administrator login attempts.
Manual IP Access List
Always-allow or always-block specific IPs or CIDR ranges, checked before any pattern or threshold rule -- an allow entry bypasses everything else.
Country Blocking
Reject requests from chosen countries via a free IP-to-country lookup, cached per IP so it's a one-time check, not a per-request dependency. Fails open if the lookup service is ever unreachable.
Bad User-Agent Blocking
Actively reject known scanner/bot user agents, kept as its own switch since a User-Agent string alone is easier to spoof than a real attack payload.
Admin Lockdown
Blocks the extension installer and creating new backend users while on, so a compromised admin session can't install a malicious extension or plant a fresh Super User account. Never blocks Joomla's own core updates or editing an existing user -- including your own profile.
Protected User Snapshot & Auto-Revert
Snapshots every Super User and auto-reverts a blocked or demoted account immediately. An email/password change or deletion is alerted, never silently reverted, since that could just as easily be something you did yourself.
Test a Request
Paste a URL, IP, User-Agent, or Referer and see exactly what Protection Mode would do with it -- blocked, flagged, or allowed -- before you turn any blocking switch on. Runs the same frontend checks the live gate uses (backend gates like the secret admin URL cannot be simulated from a pasted request); never affects real traffic.
All protection switches are off by default, and authenticated non-guest admin sessions are exempt from request-pattern and country blocking, so you can never lock yourself out by travelling or using a VPN.
Active Web Application Firewall
ProProtection Mode's own signatures are deliberately narrow -- webshell interaction, SP Page Builder's own RCE, known drop filenames -- matching this scanner's original webshell-cleanup focus. The Web Application Firewall adds a second, broader pass: generic injection-class patterns any Joomla site is exposed to, regardless of which extensions it runs.
SQL Injection
UNION SELECT, boolean-tautology (' OR '1'='1), and time-based blind injection (SLEEP/BENCHMARK/WAITFOR DELAY).
Cross-Site Scripting
Inline <script> tags and event-handler attributes (onerror=, onload=, ...) in request parameters.
Local & Remote File Inclusion
PHP stream wrappers (php://, data://, expect://, ...) and remote-URL include/require attempts.
Command Injection
Shell metacharacters (;, |, `, &&) chained with a recognized command -- deliberately excludes a plain & and generic words like “id” to avoid flagging ordinary Joomla query strings.
Known-CVE Coverage
Includes a signature for Joomla's CVE-2023-23752 unauthenticated webservices probe.
Runs Last, Not Twice
Only checked when Protection Mode's own signatures find nothing on that same request -- after the virtual-patch rules, which run first -- and never double-scores a match.
Broad, proximity-based matches -- where a signature can't confirm two suspicious things are actually the same parameter -- log for review instead of blocking, so a false positive never reaches the blocking path.
File Integrity Monitoring
ProSignature-based scanning only catches content matching a known pattern. A payload hand-inserted into an already-trusted file can dodge every signature check while still being a real backdoor. File Integrity Monitoring catches that class of compromise instead: hash every file once as a known-good baseline, then flag any file whose content no longer matches -- independent of whether the new content looks malicious by pattern-matching at all.
Create Baseline
One click hashes every scanned file with SHA-256 and stores it as your site's known-good snapshot.
Check Integrity Now
Re-hashes and compares against the baseline on demand, or automatically as part of a scheduled check.
Narrow, High-Signal
Only files present in BOTH the baseline and the current scan, with a different hash, are reported -- a brand-new file is left to the regular scanner's own checks.
Never Auto-Updates
The baseline only moves forward when you explicitly rebuild it -- a legitimate update changes files too, so this never silently re-baselines on its own.
Rides Existing Alerts
Drift found during a scheduled check sends the exact same email/Slack/Discord/Telegram alert as a signature-based finding -- no separate notification habit to learn.
Medium Confidence By Design
Flagged at medium, not high -- a legitimate extension update also changes files, and this can't tell the difference from tampering on its own.
Smart AI Assistant
ProA scan tells you which file is suspicious. The Smart AI Assistant is the step after that: its own panel in the left sidebar (Components > MuRu Guard > Smart AI Assistant) where you can ask about a finding in plain language, have the assistant open the file, search the rest of the project for related code, and write the correction back to disk -- all from inside the Joomla administrator.
It works as a multi-turn loop. Each turn, the assistant decides which single tool it wants to run next, that tool executes locally on your own server, and the result feeds into the next turn. Your codebase is never uploaded, indexed, or mirrored anywhere -- only the tool name, its arguments, and its result cross the network, which means the model sees the contents of files it explicitly reads or writes during your conversation and nothing else.
What it can do
Browse the project
Shallow, one-level directory listings so it can walk the tree the way you would, without dumping the whole filesystem into a single request.
Read files
Reads up to 256 KB of a file and tells you plainly when a file was truncated, instead of silently reasoning about a partial view.
Search the project
Matches on both filenames and file contents across PHP, JS, TS, CSS, HTML, XML, INI, JSON, Markdown, and text files, returning the first matching line and its number.
Create and edit files
Writes new files or overwrites existing ones, up to a 256 KB limit per write.
Rename files
Moves or renames a file, and refuses if something already exists at the destination rather than overwriting it.
Delete files
Removes a single file at a time. No recursive directory deletion, so a wrong instruction can't cascade.
What it cannot do
Giving an assistant write access to a production site is only reasonable if the fences are real, so they are enforced in the extension's own PHP -- not requested politely in a prompt the model is free to ignore.
Joomla core is off-limits
libraries, includes, api, cli, the language folders, and administrator/manifests are all blocked. Core updates overwrite these anyway, so hand-editing them is risky with no upside.
Entry points are protected
configuration.php and the root, administrator, and api index.php files can't be touched. Corrupting one of those takes the whole site down, including the assistant you'd need to fix it.
No self-tampering
The assistant can't edit MuRu Guard's own component files or the Shield plugin that is actively protecting the site -- so it can't be talked into disabling the thing watching for the attack.
Blocked paths are hidden, not locked
Denied files and folders are left out of listings and search results entirely, so the assistant never learns they exist to try in the first place.
No escaping the webroot
Paths are normalised and resolved against the real webroot, which rejects both ../ traversal in the input and symlinks planted inside the site that point elsewhere on disk.
Nothing destructive without a yes
Writes, renames, and deletes need your explicit confirmation in the chat before they are executed.
Audit log
Every file the assistant creates, edits, renames, or deletes is recorded with the action, the path, the Joomla username who approved it, and a timestamp. The last 1,000 entries are kept and shown newest first in the panel's own audit tab. Approving a change in a chat window shouldn't mean losing the paper trail you would get from a normal form submission.
Custom Skill
Write your project's own conventions once -- coding standards, which template to touch, what never to change -- or upload them as a .md or .txt file, up to 64 KB. They are added to the assistant's instructions on every turn, so you don't repeat yourself each session. Because a Skill describes this specific install's codebase, it is stored on your own server rather than on your account.
TimeMachine (Backup & Restore)
ProAn AI assistant with write access to your site is only worth using if a bad edit costs you nothing to reverse. TimeMachine is the safety net underneath every repair MuRu Guard makes -- not a separate tool you have to remember to run, but a step the extension takes for you automatically, before it lets anything touch disk.
It covers more than the Smart AI Assistant: bulk file deletion, Clean Code, Clean Menu XSS, and the rest of the scanner's own one-click cleanup actions all get the same protection. Whether the change came from a conversation with the AI or a button click on a scan result, there is always a way back.
What it actually does
Snapshots before every repair
The instant before a file is written, renamed, or deleted -- or a cleanup action touches the database -- its exact prior state is saved. This happens server-side, unconditionally, for every AI edit and every cleanup action. There is no setting to forget to turn on.
Verified, not just stored
Every snapshot is SHA-256 hashed at the moment it's taken and re-verified against that hash before a restore is ever allowed to trust it. A corrupted or tampered snapshot is refused, even if you force the restore.
One click, per file or per whole request
A single AI turn that edits three files is one transaction. Undo the whole thing in one click, or reach into it and restore just one of the three -- your call.
Won't silently clobber a later change
If a file was edited again -- by you, by hand, by anything -- after the repair it's restoring, the restore stops and asks first instead of quietly overwriting work you did afterward.
A real diff before you approve, not just after
The same confirmation step where you approve an AI edit now shows you a line-by-line diff of what's about to change, or a size/hash comparison for binary files -- computed locally, never sent anywhere.
Keep the ones that matter
Snapshots age out automatically on a retention window you control (days and a maximum count) -- but pin any specific repair to Keep, and it's exempt from cleanup for as long as you need it.
How you recover
Every restorable repair shows up in a Protected Repairs list -- a shortcut view right inside the Smart AI Assistant panel showing the most recent ones, and the full history under Settings > Backup & Restore. Each entry shows what changed, who approved it, and when. Restoring it is one button: Restore puts the file (or the whole transaction) back exactly as it was, verified against its saved hash first. If something changed again since, you'll see a conflict warning before anything is overwritten, not after.
Undo an AI edit
Approved a fix that turned out wrong? Open the Smart AI Assistant panel, find the entry in Protected Repairs, click Restore. The file goes back to exactly what it was before the AI touched it -- no need to ask the assistant to reverse itself, and no risk it reconstructs the original slightly differently than it actually was.
Undo a cleanup mistake
Bulk-deleted a file that turned out to be legitimate, or a Clean Menu XSS pass stripped more than it should have? Same list, same Restore button -- database rows are put back with the exact values they had before, never a best-effort reconstruction.
Retention is configurable from Settings > Backup & Restore: how many days a snapshot is kept, and a maximum count so storage never grows unbounded on a site the assistant works on heavily. Every snapshot, repair, and restore is also written to the same Protection Log the rest of MuRu Guard uses -- one audit trail, not a second one to check separately.
AI Integrations
ProSettings > AI Integrations is where the Smart AI Assistant gets its connection. The AI provider is configured once at the account level rather than per site, so a new install covered by the same license can use the assistant immediately, with no credentials to copy between sites and no API key sitting in each site's database.
Connect once, use everywhere
Account-level configuration means every install under an active license shares the same connection.
Per-turn, stateless requests
Each turn of the conversation is a separate request. Nothing about your project is retained between sessions on the service side.
Your files stay on your server
File tools execute locally. Only tool names, arguments, and results travel over the network -- never a bulk copy of your site.
Site-specific context stays local
Your custom Skill is written to the install itself, not to your account, because it describes this codebase and no one else's.
Unlocks the moment the license validates
Activate or correct a license and the AI Integrations and Pro Features tabs open on the same page load -- no second refresh needed.
Optional by design
Skip it entirely and the scanner, cleanup tools, Protection Mode, and .htaccess advisor all work exactly as they always have.
Automations & Alerts
ProA scanner only helps if someone runs it. Scheduled scanning runs the same checks on your own cron schedule and tells you where you already are -- inbox, team chat, or a dashboard covering every site you maintain. Scheduled scans and email alerts work on the Free plan; chat channels, Fleet reporting and bulk actions, and Autopilot are Pro.
Scheduled scans
Turn on scheduled scanning and MuRu Guard generates a secret token. Point a cron job or your host's scheduled task at the tokenized URL and the scan runs unattended. The dashboard shows when it last completed.
Email alerts
Send results to any address when a scheduled run finishes, so a new finding reaches you without anyone logging in to look.
Slack
Post findings into a channel through an incoming webhook, so the whole team sees a compromise at the same time.
Discord
Same webhook-based delivery for teams and communities that live in Discord instead.
Telegram
Deliver alerts through a bot to a person or a group chat, useful when the site owner isn't in your workspace at all.
Fleet Dashboard reporting
Opt an install in to report its scan status back to your dashboard account, so agencies can see every site's state on one screen instead of opening each administrator in turn.
Fleet bulk actions
Select any number of sites on the Fleet Dashboard and trigger a re-scan or push a recommended hardening config (Protection Mode, attack blocking, brute-force blocking, bad user-agent blocking) across all of them at once, instead of logging into each site's admin individually.
Slack, Discord, Telegram, Fleet Dashboard reporting, and Fleet bulk actions are Pro features and unlock with an active license; scheduled scanning and email alerts work on every plan. A bulk action can't be pushed into a site instantly -- there's no way to reach into a site directly, so it's picked up and executed the next time that site checks in on its own schedule.
False-Positive Handling
Every finding row -- files, Super Users, menu items, database rows -- has a one-click “Mark as Safe” action. Most scanners that offer this just remember a filename or row ID forever, which quietly creates a blind spot: if that exact path is ever genuinely compromised later, a stale dismissal would hide the real problem.
MuRu Guard fingerprints the exact finding text being dismissed, not just its location. If the same file or database row later matches something different -- because its content actually changed -- the fingerprint no longer matches and it reappears as a fresh finding automatically. A dedicated management screen lists every current dismissal with a one-click restore, so nothing stays permanently hidden without a trail.
.htaccess Hardening Advisor
A read-only advisory panel that reads your site's actual root .htaccess and checks it against a focused set of recommendations: PHP execution blocked inside writable upload directories (the single most direct way to stop a dropped webshell from ever running), directory listing disabled, and sensitive files (.env, .git, backup/SQL files) blocked from direct access -- plus optional security headers.
Every missing check shows a copy-ready rule. MuRu Guard never writes to .htaccess itself -- a wrong edit to that one file can take an entire site down with no way to test a rewrite rule safely before it's live, so this stays report-and-suggest only.
Cleanup Workflow
- 1
Review High-confidence findings before Medium-confidence findings.
- 2
Treat core entry-point tampering as the top priority because it can execute on every page load.
- 3
Delete confirmed malware files or folders only through current scan results.
- 4
Ask the Smart AI Assistant to open anything you're unsure about -- it can read the file and explain what the flagged code actually does before you delete it.
- 5
Clean injected menu params with the dedicated clean action instead of deleting whole menu items.
- 6
Remove rogue Super Users from Joomla Admin, then rotate credentials from configuration.php.
- 7
Force logout sessions, check scheduled jobs, and re-scan after cleanup.
Frequently Asked Questions
Stop worrying about your site -- it's free
The core toolkit is free and open-source, setup takes about two minutes, and every finding shows the exact reason it was flagged. Install it once, switch on protection, and get back to running your site -- MuRu Guard keeps watch from there.
- No account or card required
- Read-only scanning -- nothing executes
- Installs like any Joomla extension
