JY SecurityFilter
Introduction
SecurityFilter Pro is a professional security plugin for Joomla 4, 5, and 6, fully compatible with PHP 8.0 and later. Without modifying any Joomla core files, it delivers a comprehensive set of lightweight, fast, and fully configurable security features to safeguard your website against a wide range of threats.
In addition to protecting your website from common exploits, it provides advanced administrative controls, IP management, HTTP security headers, robust logging, and email notifications.
1. Smart Form Protection
- Contact forms, registration forms, and third-party extension forms are common entry points for malicious payloads such as JavaScript code or SQL injections.
- Real-Time Request Inspection: Automatically inspects all incoming GET and POST requests to detect dangerous patterns before they are processed.
- Custom Banned Words: Allows administrators to define custom prohibited words with case-sensitive matching.
- Flexible Actions: Configurable to either block the entire form submission or simply clear the suspicious input fields.
- Broad Integration: Protects both Joomla's built-in forms and third-party extension forms.
2. Brute Force Protection
Brute Force attacks involve automated bots repeatedly guessing username and password combinations to gain unauthorized access.
- Failed Login Monitoring: Tracks failed login attempts within a customizable time window.
- Multi-Stage Mitigation: Displays a CAPTCHA challenge first, followed by a temporary IP block if failed attempts persist.
- Dual-Zone Protection: Can be enabled independently for both the frontend and administrator login pages.
- Alerts & Logs: Supports detailed logging of failed attempts and automatic email notifications.
3. Rate Limiting
High-frequency requests from a single source can overload servers, leading to Layer 7 DDoS attacks.
- Request Thresholds: Define the maximum number of allowed requests per IP within a specified time window.
- Smart Responses: Return an HTTP 429 (Too Many Requests) error or slow down attackers by introducing a configurable response delay.
4. Bot Detection
Penetration-testing and hacking tools (like sqlmap, curl, Nikto, Scrapy, and wget) often identify themselves via their User-Agent strings.
- Signature Detection: Identifies and blocks or logs requests from known hacking tools and scrapers.
- User-Agent Validation: Detects and blocks requests that completely lack a User-Agent.
- Custom Lists: Easily configure custom allowlists and blocklists for specific bots.
5. URL Protection and Injection Prevention
Every incoming URL is inspected before Joomla processes the request to block malicious intent.
- Injection Mitigation: Protects against SQL Injection, Blind SQL Injection, and Object Injection.
- Execution & Traversal Prevention: Blocks Remote Code Execution (RCE), Directory/Path Traversal, and unauthorized access to sensitive system files.
- Granular Controls: Dedicated protection for Object Injection and Blind SQL Injection can be enabled independently.
6. XSS Protection
All user inputs are thoroughly inspected for malicious JavaScript, dangerous scripts, control characters, and common Cross-Site Scripting (XSS) patterns to prevent unauthorized code execution inside visitors' browsers.
7. Email Security & Validation
The plugin includes a comprehensive validation engine to block spam and malicious registrations via email forms:
- Domain & Temporary Mail Blocking: Blocks temporary/disposable email addresses and custom-defined email domains.
- Gmail Alias Normalization: Normalizes Gmail dot variations and prevents multiple account registrations using Gmail aliases.
- Session Limits: Limits the number of different email addresses used during a single user session.
- Violation Handling: Instantly blocks the entire form submission or clears only the violating email field.
8. Advanced File Upload Protection
Uploading malicious files is a highly common method used to compromise websites. SecurityFilter Pro enforces strict upload validation:
- Multi-Layer Verification: Verifies file extensions, validates real MIME types, and checks image integrity.
- Granular Restraints: Limits file sizes, maximum file counts, and filters out suspicious filenames.
- Access Control: Restricts uploads by user groups, specific components, and separate frontend/administrator settings.
- Instant Alerts: Blocked uploads generate a detailed security log and send optional email notifications to administrators.
9. WebShell and PHP Execution Protection
If an attacker manages to bypass filters and upload a PHP file, their next goal is execution.
- Protective .htaccess Rules: Automatically generates rules that prevent the direct execution of uploaded PHP files outside Joomla’s main index.php, effectively rendering Backdoors and WebShells useless.
10. Administrator Panel Protection
One of the plugin's strongest features is its comprehensive administrator area protection:
- Hidden Access Paths: Obfuscates the default /administrator path using a custom access key and redirect settings.
- Security Lock Page: Deploys a security lock screen with a unique password before the default Joomla login page is displayed.
- Super User Frontend Restriction: Prevents Super Users from logging in through the frontend.
- IP Access Control: Restricts admin access to whitelisted IPs and supports real client IP detection behind Cloudflare and other CDNs.
11. Super User Protection
To protect high-privilege accounts from compromise or unauthorized modifications:
- Prevent Identity Alteration: Blocks unauthorized changes to the Super User's username, email, and password.
- Restrict Privilege Escalation: Prevents the creation of new Super User accounts or new user groups with Super User privileges.
12. HTTP Security Headers
Configure critical browser security headers directly from the plugin settings without editing server configuration files:
- Clickjacking Protection: Configures anti-clickjacking headers.
- Transport & Content Security: Implements HTTP Strict Transport Security (HSTS) and Content Security Policy (CSP).
- Granular CSP Controls: Supports CSP Report-Only mode, Upgrade-Insecure-Requests, and source restrictions for images, fonts, inline JavaScript, and CSS.
13. Layer 7 Protection
By stopping certain attacks directly at the Apache and .htaccess level, the plugin offers enhanced server efficiency:
- Resource Optimization: Reduces server CPU usage by blocking bad bots before they reach PHP.
- DDoS Mitigation: Enhances defense against Layer 7 (Application Layer) DDoS attacks.
- API Compatibility: Allows administrators to define trusted User-Agent strings for licensing servers, APIs, webhooks, and external services.
14. Automatic Maintenance and Cleanup
To keep the database light and fast, SecurityFilter Pro automates background maintenance:
- Log Rotation: Automatically removes expired security logs and old email reports.
- Custom Retention: Allows administrators to set independent retention periods for different log types.
JY SecurityFilter
- Version:
- 1.1.0
- Developer:
- jomYekta
- Last updated:
-
Jul 20 2026
1 day ago - Date added:
- Jul 17 2026
- License:
- GPLv2 or later
- Type:
- Free download
- Includes:
- c p
- Compatibility:
- J5 J6
Share