Introduction
Protect your Joomla site’s /administrator area from relentless attacks with "System - AdminExile," a free, battle-tested plugin that once reigned as the #1 security extension in the Joomla Extension Directory. Though eclipsed by tools like AdminTools Pro (which offers similar functionality for a fee), AdminExile remains a robust, no-cost solution to safeguard your backend from drive-by and brute force attacks—keeping honest users honest and everyone else out!
How It Works
Without protection, anyone can target your /administrator login by simply typing “/administrator,” opening the door to easy exploitation. "System - AdminExile" puts a stop to that with URL access keys (query parameters), transforming your login URL into a fortress. Configure it to require a key (e.g.,?boofwang) or a key-value pair (e.g.,?boofwang=sadham), and only that exact URL grants access. Unauthorized attempts? Redirect them to your homepage, a 404 error, or even a playful diversion like nsa.gov or a massive file download (e.g., a Linux ISO)—it’s both secure and fun!
Unrivaled Protection, Proven Results
Check the 24-hour activity graph of richeyweb.com (updated live on the richeyweb.com plugin page)—you’ll see waves of attacks, sometimes hundreds or thousands per hour, targeting /administrator. AdminExile stops them all, silently logging failures without giving attackers feedback, causing them to give up in frustration. I’ve kept my server exposed to capture this data, using long, non-guessable keys to stay safe, but you can lock it down tighter with features like IPv4/6 CIDR whitelists and blacklists.
A Modern AdminExile for Joomla 5
With version 5, I’ve completely rewritten "System - AdminExile" using modern Joomla internals, making it faster, more reliable, and bug-free. I uncovered and fixed an unreported issue: without a key value set, the old version allowed authentication with any value—now, it fails as expected. I’ve also streamlined the plugin by removing features I never loved, like brute force detection (better handled by tools like Fail2Ban), frontend blocking, and link recovery, which were cumbersome or redundant. What’s left is a lean, focused tool for /administrator protection, free with no Pro version—ever.
Why Choose System - AdminExile?
This plugin exists for one mission: to shield your /administrator login page. It prevents session cookies, offers a re-entry period after logout, and logs failures, all while staying lightweight and Joomla 5-native. Whether you’re a small site or a high-target platform, AdminExile delivers peace of mind without a price tag.
Features
- /administrator key and/or key+value URL Protection
- Prevent /administrator session cookie
- Re-entry period after logout
- Failure Logging
- IPv4/6 Whitelist with CIDR capability
- IPv4/6 Blacklist with CIDR capability
AdminExile
- Version:
- 5.0.9
- Developer:
- Michael Richey
- Last updated:
-
Mar 02 2025
6 days ago - Date added:
- Nov 18 2014
- License:
- GPLv2 or later
- Type:
- Free download
- Related extension :
- AdminExile Pro
- Includes:
- p
- Compatibility:
- J3 J4 J5
Share