Securing Your Joomla Site with miniOrange JoomShield
Overview
Joomla sites are a common target for brute force attacks, fake registrations, and bots that probe the default
admin login page. miniOrange JoomShield is a security plugin that closes these gaps by giving you a single
dashboard to manage login security, registration security, IP and browser blocking, database backups, and
login activity reports.
With JoomShield, you can hide your default admin login URL behind a
custom path and access key, enforce strong
passwords for admin and other users, block registrations from disposable or unwanted email domains, look up
and block suspicious IP addresses, restrict access by browser, back up your database on demand, and review a
full log of login attempts with usernames, IP addresses, and failure reasons. Premium features extend this
further with brute force protection, IP range and country blocking, scheduled automatic backups, and email
notifications for blocked IPs or unusual account activity.
JoomShield is compatible with Joomla 3, 4, 5, and 6. Here we will go through a step-by-step guide to configure
JoomShield and secure your Joomla site's login, registration, and admin access.
Installation Steps
- Login into your Joomla site’s Administrator console.
- From left toggle menu, click on System, then under Install section click on Extensions.
- Now click on Or Browse for file button to locate and install the plugin file downloaded from the Joomla Extensions Directory.
- Installation of plugin is successful. Now click on Start Using miniOrange JoomShield Plugin
Configuration Steps
Once JoomShield is installed on your Joomla site, navigate to Components > miniOrange - JoomShield in your Joomla admin panel to access all the security settings described below.
Step 1: Configure Login Security
- Navigate to the Login Security tab from the JoomShield settings menu.
- Under Customize Admin Login Page URL, enable Enable Custom Login Page URL to replace the default /administrator path with a custom URL and access key. Note that once this is enabled, you will no longer be able to log in using /administrator.
- Set the Redirect after Failure Response option to choose where users are redirected if access is denied.
- Under Enforce Strong Passwords, enable Enable strong passwords to require admin and other users to set strong passwords, then click Save.
- Brute Force Protection (Login Protection) is a Premium Feature that blocks an IP address after a set number of failed login attempts, for a configurable time period.
Step 2: Configure Registration Security
- Navigate to the Registration Security tab.
- Under Block Registrations from fake users, enable Enable blocking of registrations from specific email domains and enter the email domains you want to block, separated by semicolons.
- Click Save to apply the domain blocking rules.
- Under Enforce Strong Passwords, enable Enable strong passwords to require strong passwords for user registrations, then click Save.
Step 3: Configure IP Blocking
- Navigate to the IP Blocking tab.
- Under IP Lookup, enter an IP address and click Lookup IP to trace where a suspicious visitor is accessing your site from. Click Clear to reset the field.
- Manual Block IPs and Whitelist IPs are Premium Features that let you directly block specific IP addresses or allow trusted ones through.
Step 4: Configure Advanced Blocking
- Navigate to the Advanced Blocking tab.
- Under Browser Blocking, enable Enable Browser blocking and select the browsers you want to block. In the free version, only Microsoft Edge is available for testing; blocking other browsers requires the premium version.
- Click Save to apply the browser blocking rules.
- IP Address Range Blocking and Country Blocking are Premium Features that let you block a range of IP addresses or block visitors from specific countries.
Step 5: Configure Database Backup
- Navigate to the DB Backup tab.
- Under Database Backup, enter your Host Name, Database Username, Database Password, and Database Name, then click Backup to take a manual backup of your Joomla database.
- Automatic / Scheduled Database Backup is a Premium Feature that lets you schedule recurring database backups, such as hourly, instead of backing up manually each time.
Step 6: View Login Transaction Reports
- Navigate to the Reports tab to view the Login Transactions Report.
- This report logs every login attempt on your site, including the username, site URL, IP address, status, failure reason, and the date and time in UTC.
- Use the Search field to look up specific entries, or use Refresh Page, Clear Reports, and Download Reports to manage the report data.
Step 7: Notification and Alert Settings
- Navigate to the Notification/Alert tab.
- Email Notifications is a Premium Feature that notifies the administrator whenever an IP address is blocked, and notifies users when unusual activity is detected on their account.
You have successfully configured miniOrange JoomShield, securing your Joomla site's login, registration, and admin access against unauthorized attempts.
FAQs
More FAQs ➔How does JoomShield protect my Joomla admin login page?
JoomShield lets you add a secret access key to your admin login URL. Once enabled, the default administrator login page won't load for anyone without that key, which keeps bots and scanners from ever finding a login form to attack. You also get to decide what happens when someone tries the old login path without the key, such as redirecting them to your homepage instead of showing an error that confirms Joomla is running underneath.
Can JoomShield stop brute force login attacks?
Yes. JoomShield tracks failed login attempts by IP address and blocks the source once a set threshold is crossed, so repeated password-guessing attempts get shut down automatically. You can also choose to notify affected users by email when their account is targeted, so they know to check their password and account activity even if the attack didn't succeed.
Does JoomShield block fake or spam registrations?
Yes. You can block sign-ups from disposable email domains at the registration step, which keeps spam accounts and fake registrations from ever reaching your user list. This cuts down on the junk accounts that inflate your member count without ever engaging, and it reduces the spam activity that often follows once a fake account gets through.
Can I restrict site access to specific IP addresses with
JoomShield?
Yes. You can whitelist or block individual IP addresses or entire ranges, and import a list of addresses in bulk instead of adding them one at a time. By default every IP address can reach your site, so this feature gives you the option to lock things down to a known set of addresses, such as your office network or a client's location, or to keep out addresses you've flagged as a source of abuse.
Is JoomShield compatible with Joomla 6?
Yes. JoomShield supports Joomla 3, 4, 5, and 6, so it works regardless of which version your site is currently running. This means you can install JoomShield on an older site without planning a migration first, and it will keep working as you eventually upgrade to newer Joomla releases.
Will JoomShield slow down my Joomla site?
No. JoomShield's checks run in the background during login, registration, and request filtering, so normal visitors and logged-in users don't notice any added load time. The extension only does extra work at the specific points where security decisions need to be made, such as a login attempt or a new registration, rather than on every page load.
Thank you for your response. We will get back to you soon.
Something went wrong. Please submit your query again
