Search Results :

×

Securing Your Joomla Site with miniOrange JoomShield

Joomla sites are a common target for brute force attacks, fake registrations, and bots that probe the default admin login page. miniOrange JoomShield is a security plugin that closes these gaps by giving you a single dashboard to manage login security, registration security, IP and browser blocking, database backups, and login activity reports. With JoomShield, you can hide your default admin login URL behind a custom path and access key, enforce strong passwords for admin and other users, block registrations from disposable or unwanted email domains, look up and block suspicious IP addresses, restrict access by browser, back up your database on demand, and review a full log of login attempts with usernames, IP addresses, and failure reasons. Premium features extend this further with brute force protection, IP range and country blocking, scheduled automatic backups, and email notifications for blocked IPs or unusual account activity.

JoomShield is compatible with Joomla 3, 4, 5, and 6. Here we will go through a step-by-step guide to configure JoomShield and secure your Joomla site's login, registration, and admin access.


  • Login into your Joomla site’s Administrator console.
  • From left toggle menu, click on System, then under Install section click on Extensions.
  • Now click on Or Browse for file button to locate and install the plugin file downloaded from the Joomla Extensions Directory.
  • Installation of plugin is successful. Now click on Start Using miniOrange JoomShield Plugin
Install JoomShield Extension

Once JoomShield is installed on your Joomla site, navigate to Components > miniOrange - JoomShield in your Joomla admin panel to access all the security settings described below.

  • Navigate to the Login Security tab from the JoomShield settings menu.
  • Under Customize Admin Login Page URL, enable Enable Custom Login Page URL to replace the default /administrator path with a custom URL and access key. Note that once this is enabled, you will no longer be able to log in using /administrator.
  • Set the Redirect after Failure Response option to choose where users are redirected if access is denied.
  • Under Enforce Strong Passwords, enable Enable strong passwords to require admin and other users to set strong passwords, then click Save.
  • Brute Force Protection (Login Protection) is a Premium Feature that blocks an IP address after a set number of failed login attempts, for a configurable time period.
JoomShield Login Security
  • Navigate to the Registration Security tab.
  • Under Block Registrations from fake users, enable Enable blocking of registrations from specific email domains and enter the email domains you want to block, separated by semicolons.
  • Click Save to apply the domain blocking rules.
  • Under Enforce Strong Passwords, enable Enable strong passwords to require strong passwords for user registrations, then click Save.
JoomShield Registration Security
  • Navigate to the IP Blocking tab.
  • Under IP Lookup, enter an IP address and click Lookup IP to trace where a suspicious visitor is accessing your site from. Click Clear to reset the field.
  • Manual Block IPs and Whitelist IPs are Premium Features that let you directly block specific IP addresses or allow trusted ones through.
JoomShield IP Blocking
  • Navigate to the Advanced Blocking tab.
  • Under Browser Blocking, enable Enable Browser blocking and select the browsers you want to block. In the free version, only Microsoft Edge is available for testing; blocking other browsers requires the premium version.
  • Click Save to apply the browser blocking rules.
  • IP Address Range Blocking and Country Blocking are Premium Features that let you block a range of IP addresses or block visitors from specific countries.
JoomShield Advanced Blocking
  • Navigate to the DB Backup tab.
  • Under Database Backup, enter your Host Name, Database Username, Database Password, and Database Name, then click Backup to take a manual backup of your Joomla database.
  • Automatic / Scheduled Database Backup is a Premium Feature that lets you schedule recurring database backups, such as hourly, instead of backing up manually each time.
JoomShield Database Backup
  • Navigate to the Reports tab to view the Login Transactions Report.
  • This report logs every login attempt on your site, including the username, site URL, IP address, status, failure reason, and the date and time in UTC.
  • Use the Search field to look up specific entries, or use Refresh Page, Clear Reports, and Download Reports to manage the report data.
JoomShield Login Transactions Report
  • Navigate to the Notification/Alert tab.
  • Email Notifications is a Premium Feature that notifies the administrator whenever an IP address is blocked, and notifies users when unusual activity is detected on their account.
JoomShield Notification and Alert Settings

You have successfully configured miniOrange JoomShield, securing your Joomla site's login, registration, and admin access against unauthorized attempts.




JoomShield lets you add a secret access key to your admin login URL. Once enabled, the default administrator login page won't load for anyone without that key, which keeps bots and scanners from ever finding a login form to attack. You also get to decide what happens when someone tries the old login path without the key, such as redirecting them to your homepage instead of showing an error that confirms Joomla is running underneath.

Yes. JoomShield tracks failed login attempts by IP address and blocks the source once a set threshold is crossed, so repeated password-guessing attempts get shut down automatically. You can also choose to notify affected users by email when their account is targeted, so they know to check their password and account activity even if the attack didn't succeed.

Yes. You can block sign-ups from disposable email domains at the registration step, which keeps spam accounts and fake registrations from ever reaching your user list. This cuts down on the junk accounts that inflate your member count without ever engaging, and it reduces the spam activity that often follows once a fake account gets through.

Yes. You can whitelist or block individual IP addresses or entire ranges, and import a list of addresses in bulk instead of adding them one at a time. By default every IP address can reach your site, so this feature gives you the option to lock things down to a known set of addresses, such as your office network or a client's location, or to keep out addresses you've flagged as a source of abuse.

Yes. JoomShield supports Joomla 3, 4, 5, and 6, so it works regardless of which version your site is currently running. This means you can install JoomShield on an older site without planning a migration first, and it will keep working as you eventually upgrade to newer Joomla releases.

No. JoomShield's checks run in the background during login, registration, and request filtering, so normal visitors and logged-in users don't notice any added load time. The extension only does extra work at the specific points where security decisions need to be made, such as a login attempt or a new registration, rather than on every page load.

 Thank you for your response. We will get back to you soon.

Something went wrong. Please submit your query again


ADFS_sso ×
Hello there!

Need Help? We are right here!

support