Introduction

Site protection, Access & Security, Site Security, Security Tools

SecurityFilter Pro is a professional security plugin for Joomla 4, 5, and 6, fully compatible with PHP 8.0 and later. Without modifying any Joomla core files, it delivers a comprehensive set of lightweight, fast, and fully configurable security features to safeguard your website against a wide range of threats.


In addition to protecting your website from common exploits, it provides advanced administrative controls, IP management, HTTP security headers, robust logging, and email notifications.

1. Smart Form Protection
- Contact forms, registration forms, and third-party extension forms are common entry points for malicious payloads such as JavaScript code or SQL injections.
- Real-Time Request Inspection: Automatically inspects all incoming GET and POST requests to detect dangerous patterns before they are processed.
- Custom Banned Words: Allows administrators to define custom prohibited words with case-sensitive matching.
- Flexible Actions: Configurable to either block the entire form submission or simply clear the suspicious input fields.
- Broad Integration: Protects both Joomla's built-in forms and third-party extension forms.

2. Brute Force Protection
Brute Force attacks involve automated bots repeatedly guessing username and password combinations to gain unauthorized access.
- Failed Login Monitoring: Tracks failed login attempts within a customizable time window.
- Multi-Stage Mitigation: Displays a CAPTCHA challenge first, followed by a temporary IP block if failed attempts persist.
- Dual-Zone Protection: Can be enabled independently for both the frontend and administrator login pages.
- Alerts & Logs: Supports detailed logging of failed attempts and automatic email notifications.

3. Rate Limiting
High-frequency requests from a single source can overload servers, leading to Layer 7 DDoS attacks.
- Request Thresholds: Define the maximum number of allowed requests per IP within a specified time window.
- Smart Responses: Return an HTTP 429 (Too Many Requests) error or slow down attackers by introducing a configurable response delay.

4. Bot Detection
Penetration-testing and hacking tools (like sqlmap, curl, Nikto, Scrapy, and wget) often identify themselves via their User-Agent strings.
- Signature Detection: Identifies and blocks or logs requests from known hacking tools and scrapers.
- User-Agent Validation: Detects and blocks requests that completely lack a User-Agent.
- Custom Lists: Easily configure custom allowlists and blocklists for specific bots.

5. URL Protection and Injection Prevention
Every incoming URL is inspected before Joomla processes the request to block malicious intent.
- Injection Mitigation: Protects against SQL Injection, Blind SQL Injection, and Object Injection.
- Execution & Traversal Prevention: Blocks Remote Code Execution (RCE), Directory/Path Traversal, and unauthorized access to sensitive system files.
- Granular Controls: Dedicated protection for Object Injection and Blind SQL Injection can be enabled independently.

6. XSS Protection
All user inputs are thoroughly inspected for malicious JavaScript, dangerous scripts, control characters, and common Cross-Site Scripting (XSS) patterns to prevent unauthorized code execution inside visitors' browsers.

7. Email Security & Validation
The plugin includes a comprehensive validation engine to block spam and malicious registrations via email forms:
- Domain & Temporary Mail Blocking: Blocks temporary/disposable email addresses and custom-defined email domains.
- Gmail Alias Normalization: Normalizes Gmail dot variations and prevents multiple account registrations using Gmail aliases.
- Session Limits: Limits the number of different email addresses used during a single user session.
- Violation Handling: Instantly blocks the entire form submission or clears only the violating email field.

8. Advanced File Upload Protection
Uploading malicious files is a highly common method used to compromise websites. SecurityFilter Pro enforces strict upload validation:
- Multi-Layer Verification: Verifies file extensions, validates real MIME types, and checks image integrity.
- Granular Restraints: Limits file sizes, maximum file counts, and filters out suspicious filenames.
- Access Control: Restricts uploads by user groups, specific components, and separate frontend/administrator settings.
- Instant Alerts: Blocked uploads generate a detailed security log and send optional email notifications to administrators.

9. WebShell and PHP Execution Protection
If an attacker manages to bypass filters and upload a PHP file, their next goal is execution.
- Protective .htaccess Rules: Automatically generates rules that prevent the direct execution of uploaded PHP files outside Joomla’s main index.php, effectively rendering Backdoors and WebShells useless.

10. Administrator Panel Protection
One of the plugin's strongest features is its comprehensive administrator area protection:
- Hidden Access Paths: Obfuscates the default /administrator path using a custom access key and redirect settings.
- Security Lock Page: Deploys a security lock screen with a unique password before the default Joomla login page is displayed.
- Super User Frontend Restriction: Prevents Super Users from logging in through the frontend.
- IP Access Control: Restricts admin access to whitelisted IPs and supports real client IP detection behind Cloudflare and other CDNs.

11. Super User Protection
To protect high-privilege accounts from compromise or unauthorized modifications:
- Prevent Identity Alteration: Blocks unauthorized changes to the Super User's username, email, and password.
- Restrict Privilege Escalation: Prevents the creation of new Super User accounts or new user groups with Super User privileges.

12. HTTP Security Headers
Configure critical browser security headers directly from the plugin settings without editing server configuration files:
- Clickjacking Protection: Configures anti-clickjacking headers.
- Transport & Content Security: Implements HTTP Strict Transport Security (HSTS) and Content Security Policy (CSP).
- Granular CSP Controls: Supports CSP Report-Only mode, Upgrade-Insecure-Requests, and source restrictions for images, fonts, inline JavaScript, and CSS.

13. Layer 7 Protection
By stopping certain attacks directly at the Apache and .htaccess level, the plugin offers enhanced server efficiency:
- Resource Optimization: Reduces server CPU usage by blocking bad bots before they reach PHP.
- DDoS Mitigation: Enhances defense against Layer 7 (Application Layer) DDoS attacks.
- API Compatibility: Allows administrators to define trusted User-Agent strings for licensing servers, APIs, webhooks, and external services.

14. Automatic Maintenance and Cleanup
To keep the database light and fast, SecurityFilter Pro automates background maintenance:
- Log Rotation: Automatically removes expired security logs and old email reports.
- Custom Retention: Allows administrators to set independent retention periods for different log types.

Content Order Manager
Free

Content Order Manager

By jomYekta
Admin Publishing
**Content Order Manager Plugin for Joomla 4.x and 5.x ** The Content Order Manager plugin is a powerful Joomla extension designed to enhance administrative efficiency by enabling advanced sorting capabilities across key areas of your Joomla backend — including Articles, Menus, Plugins, Modules, and Extensions. With this plugin, administrators can effortlessly define and enforce default sorting...
Ajax Search Module
Paid download

Ajax Search Module

By jomYekta
Search & Indexing
The Joomla Ajax Search Module is a powerful and efficient tool that elevates the search experience on Joomla websites to a new level. Leveraging Ajax technology, it displays search results in real time without requiring a page reload — significantly enhancing speed and user efficiency. The Joomla Ajax Search Module is a powerful and efficient tool that elevates the search experience on Joomla w...
Content Hits Change
Paid download

Content Hits Change

By jomYekta
Site Management
This Joomla plugin allows you to effortlessly change the number of hits (visits) for your content. It is particularly useful for website administrators who want more control over their content's visit statistics. With this plugin, you can reset hit counts, randomize them, or even input a custom number of your choice. 🔧 Plugin Features & Functionality ✨ Key Features: ✅ Modify hit counts –...
AutoLink Filter
Paid download

AutoLink Filter

By jomYekta
Content Links
The AutoLink Filter Plugin is a powerful tool designed to improve both SEO and user experience on Joomla-based websites. By using this plugin, you can automatically and accurately link relevant content across your website, helping search engines understand your site’s structure while guiding users to the content they’re looking for. The AutoLink Filter Plugin is a powerful tool designed to im...
Content Author Info
Free

Content Author Info

By jomYekta
Authoring & Content
The Content Author Info Plugin is a free extension for the Joomla Content Management System that helps webmasters display article authors’ information in a beautiful, user-friendly, and responsive way at either the beginning or the end of articles. This plugin is fully compatible with Joomla 4 and 5. The Content Author Info Plugin is a simple, secure, and user-friendly solution for displaying a...
Advanced Security Login
Paid download

Advanced Security Login

By jomYekta
Access & Security
The Advanced Security Login module is one of the most advanced and practical security tools for Joomla-based websites. Designed to ensure safe and secure user logins, this module can be fully customized to meet the specific needs of any website. By integrating this module, your login process will be optimized for both security and user experience. Enhanced Security & Unauthorized Access Preventio...

JY SecurityFilter

Version:
1.1.0
Developer:
jomYekta
Last updated:
Jul 20 2026
1 day ago
Date added:
Jul 17 2026
License:
GPLv2 or later
Type:
Free download
Includes:
c p
Compatibility:
J5 J6
Download

Uses Joomla! Update System