Authentication, Login protection

A real Two Step Verification system for Joomla!

  • Favourite
  • Report

Security experts agree that the first step to securing your site against unauthorized access is using a second step during the login process. Joomla 3.2 and later offer Two Factor Authentication which requires you to enter a security code along with your password to log into your site. However, Two Factor Authentication is susceptible to spoofing attacks. Moreover it does not let you use any second factor which is not a text code known to you before you login.

The solution to that is Two Step Verification. You login with just your username and password. However, at this point, you have a "captive login" and you cannot use the site unless you provide your second authentication factor. This could be a text code generated by Google Authenticator like what Joomla already allows, or something impossible to use with core Joomla such as a text code sent to you by SMS or push notification or even a secure hardware token following the FIDO U2F (Universal Second Factor) standard. After providing and validating the second factor your login becomes full features and you can use the site. This is very much like what Google does when you try to login to GMail; or what happens when you log into GitHub; or how Apple handles login to iCloud.

Akeeba LoginGuard currently supports the following second factors:
* Authenticator App (Google Authenticator, Authy, 1Password etc)
* YubiKey
* U2F (any USB or NFC token following the U2F protocol will do, including the cheap Amazon ones)
* Pushbullet (only with a paid PushBullet account)
* SMS Text Message (you need a paid subscription to the supported SMS service; read the documentation)
* Email
* Fixed Code (ONLY FOR DEMONSTRATION - this is the same as using a password; don't use on production sites)

This extension is brought to you by the same people who wrote Joomla's Two Factor Authentication feature.

With this extension, you can have a Two Step Verification with many systems :
YubiKey, Authenticator App, U2F, Pushbullet, SMS Text Message.
Ease of use
Support for this extension never used, Never used but the Akeeba site have a very good support for my other akeeba extensions.
I used this to: My site.
I prefer to use The Yukey extension because i can choose between "front only", "backend only" or Both for The "site section" parameter.
Akeeba Backup Akeeba Backup

Akeeba Backup

By Akeeba Ltd
Site Security
Akeeba Backup Core is the most widely used open-source backup component for the Joomla! CMS. Its mission is simple: create a site backup that can be restored on any Joomla!-capable server, making it ideal not only for backups but also for site transfers or even deploying sites to your clients' servers. Akeeba Backup creates a full backup of your site in a single archive. The archive contains all t...
Admin Tools Admin Tools

Admin Tools

By Akeeba Ltd
Site Security
Admin Tools is a true Swiss Army knife for your site. Our freely available Admin Tools Core will detect, notify you about new Joomla! releases, fix your files' and directories' permissions, protect your administrator directory with a password, change your database prefix, migrate links pointing to your old domain on-the-fly and perform database maintenance, all with a single click. Written and ma...
Admin Tools Professional Admin Tools Professional
Paid download

Admin Tools Professional

By Akeeba Ltd
Site Security
From the makers of Akeeba Backup Core/Professional and Admin Tools Core, this is the enhanced release of Admin Tools, available on a subscription basis. On top of what Admin Tools Core already offers, Admin Tools Professional has these exclusive features: - Security tightening .htaccess (Apache), nginx.conf (NginX) and web.config (IIS) file generator with a simple yet powerful user interface - Res...
Akeeba SocialLogin Akeeba SocialLogin

Akeeba SocialLogin

By Akeeba Ltd
Site Access
DEVELOPMENT HAS BEEN SUSPENDED ON THIS PRODUCT. The European Union's GDPR makes it unclear whether you can allow users to create accounts on your site using their social media profile since explicit consent to collect their information has not been provided. Moreover, it is not clear whether logging in with social media profiles is legal because if you do not already have an account / have not acc...

Akeeba LoginGuard

Akeeba Ltd
Last updated:
Jan 17 2019
Date added:
Mar 06 2018
GPLv2 or later
Free download
c p

Uses Joomla! Update System


Write a review