HTProtect.org
HTProtect HTProtect JOOMLA SECURITY
htprotect.org Biztonsági rések & frissítési útmutatók
Új htprotect.app - Központi Joomla oldalkezelés több weboldalhoz
HTProtect

Changelog

What's new — short and clear.

Every notable change to HTProtect, newest first. Compact and free of jargon. The protection core stays rock-solid between versions — updates bring new detections, convenience and polish.

NewImprovedSecurityFixed
v2.7.172026-09-26LatestFixedSecurity
  • A successful update is no longer rolled back just because the extension still reports the same version number. Reported in the HTProtect forum for J2Store: the update went through, the site ran, and HTProtect undid it anyway - again with every new release. The cause was an assumption about other vendors: HTProtect expected the extension to report a higher number afterwards. An update now counts as successful when Joomla’s installer confirms it, the site is healthy, and the number has not gone down. The protection still rests on the health check: an unhealthy site, a step backwards or a missing confirmation still lead to a rollback. Instead of a red “paused” you now get a neutral note - updated, but the extension still reports the old number. The attempt is not repeated, and it clears as soon as another version appears or you update by hand. For HTProtect’s own self-update the strict rule stays.
  • Three new malware signatures. An SEO injector that fetches foreign content on every page view and writes it straight into the page slipped past all 43 existing signatures - precisely because it obfuscates nothing. What is detected now is the method rather than the address, so it still works after the attacker moves servers. Plus a signature against a file manager planted as a backdoor; it keys on internal identifiers rather than the project name, which is removed in seconds. Measured against 168 real sites, not a single false alarm.
v2.7.162026-09-26ImprovedFixedNew
  • The status tile in the Joomla dashboard no longer loads half the program code. For one traffic-light colour that took around 150 milliseconds; now it is 0.2. It reads the status from a pre-calculated store and only works it out itself if that is missing or out of date. Because the tiles share a lock, the whole administration area started more slowly and the other tiles often stayed red - both are gone with this.
  • “Paused after repeated failures” never lifted again. After three failed automatic updates things were suspended; only a successful automatic update could lift it - which the suspension itself prevented. Updating by hand did not help either. The suspension now applies only to that one failed attempt: after a manual update, or as soon as a new version appears, it runs again. Existing suspensions are released with this update, and the display now names the cause.
  • Endless loop with cPanel and Plesk. The hosting panel wrote the chosen PHP version into the protection file, HTProtect removed it again, the panel put it back - an email every round, and by the time you looked the line was gone. Such lines are now adopted, but only if they affect PHP extensions alone: the same instruction can otherwise let images run as program code. Independently of that, the same change is reported twice at most.
  • The backward-compatibility plugin no longer switches itself back on. Anyone who turned it off did so deliberately. The option is off from now on - on new and existing sites alike, with nothing for you to do; if you want to keep it, simply tick it again. You can switch it back on at any time via /administrator?recompat. That emergency switch used to depend on the very same option and would have failed exactly when you needed it - it now always works, on Joomla 5 and 6, and still only for signed-in super users.
  • New: trusted paths for many sites at once. “Edit shield” in the fleet overview has a fifth field, and it is the most powerful one: it lets a path past every block, including the one for PHP - the dialog points that out separately. Sites on an older version do not get this part and are marked as partly done instead of reporting success.
  • Small things. The second, grey “HTProtect auto-updates” tile can now be switched off; the coloured status tile is unaffected. And the green “auto-updates” button in Joomla’s extension manager only appears when the matching setting is on - otherwise it led nowhere.
v2.7.152026-09-18FixedNew
  • “Page not found” instead of the back end, although the secret access link was correct. If you protect your back end with a secret access string, you open it through a link such as /administrator?mysecretlogin; HTProtect then grants permission and redirects to the normal back-end address. With a service such as Cloudflare in front, that redirect went to the unencrypted address - and in the switch the permission just granted was lost. You ended up at “page not found” even though everything was entered correctly. The redirect now recognises an encrypted connection even when only the upstream service reports it. The fix arrives with the update; you do not have to save the access string again.
  • Disabled update sources no longer stay disabled. Joomla switches a source off as soon as its server happens to be unreachable during a check - and never switches it back on. HTProtect now restores it hourly instead of once a day, gives up only after about four days of continuous silence instead of three attempts, picks an abandoned source back up as soon as it answers, and works on sites without visitors too.
  • New: shield exceptions for many sites at once. The fleet overview now offers “edit shield” under “more actions”: pick the sites, enter per list what should be added or removed, confirm - for all four exception lists. Existing entries stay, and the spelling does not matter. A confirmation step comes first and flags changes that lower protection separately; afterwards each site checks itself and takes the change back if it became harder to reach. Requires 2.7.15 on the site in question.
v2.7.142026-09-16NewFixed

New in the dashboard: a history showing what was updated and when - including what happened without HTProtect.

  • New: an update history in the dashboard. Until now the log lived only in the site’s back end and stopped after 60 lines; the dashboard showed only what was still pending, never what had been done when. HTProtect now reports every completed update with its timestamp to the dashboard, under “history” with filters for all, updates and actions. Everything is recorded - extensions, HTProtect itself, the Joomla core, language packs, the JoomShaper patch - including failures and rollbacks; the last three had no entry at all before. What happens without HTProtect shows up too, marked “not by HTProtect”: Joomla’s own automation, manual updates, actions by your host, restored backups. If a site was offline for a while, everything is delivered afterwards with its real timestamps. Only the name, versions, result and time are stored, for 24 months - no paths, no content, no visitor data. That is the basis for maintenance reports to your clients later on.
  • Sites on older PHP stopped receiving updates. The update file named PHP 7.4 as the minimum - Joomla then does not offer the update at all, and says nothing about it. Thirteen sites were quietly stuck on an old version that way, most of them since 2.6.17. The minimum is back at PHP 5.6, and HTProtect genuinely runs there. The recommendation is unchanged: PHP below 7.4 is still flagged red.
  • English interface on German language variants. This affected only sites whose administration language is the Austrian, Swiss, Liechtenstein or Luxembourg variant and where standard German is not installed. Joomla only places language files into language folders that already exist - without standard German there was none, and that was the only place HTProtect looked, although the file sat in the extension’s own folder the whole time. Both places are now checked; the shared folder keeps priority so your own adjustments still win. This also affected notification emails and the menu entry. Nothing to do: after the update the interface is German again on the next visit.
  • Small things. On PHP 8.5 a notice about an outdated function appeared in the middle of the administration area. An update that hung in its final phase was cancelled silently and then missing from the log although it had been installed. An extension name with invalid character encoding could silently wipe the auto-update’s working state. And the secret back-end access no longer expires unnoticed.
v2.7.132026-09-14Fixed
  • The connection to the dashboard now holds reliably. A storage fault could in rare cases make a site lose its connection. Fixed - and the connection is now additionally backed up and restored on its own.
v2.7.122026-09-10Fixed
  • Core file verification never finished on some sites. The progress bar climbed and fell back, and the “core integrity” tile stayed empty. Fixed - the malware scan was not affected.
  • Files reported but nowhere to be seen. The list of planted files gave a number at the top but showed none of them below. Every unexplained file now always gets a line of its own.
  • A broken connection to the dashboard now finds itself again. A site could lose the connection without that being visible anywhere - it simply stopped reporting in. HTProtect now restores it by itself; where that fails, it says so in the back end, with a button to reconnect. Applies only to sites using the htprotect.app dashboard.
v2.7.112026-09-08Fixed
  • On PHP 8.4 and 8.5, the malware scan and core file check broke off. With PHP error reporting set to maximum (not recommended on a live site), PHP points out outdated notations - and those notices landed in the middle of both checks’ responses, which then ended with “not possible” or “verification failed”. Fixed, and a notice like that can no longer bring the interface to a halt.
v2.7.102026-09-08NewSecurityFixed

The malware scan now also finds what nobody has seen before: three new methods that work without any known pattern.

  • Widening the search in time after a find - the timestamp-driven search. Whoever leaves a backdoor rarely leaves just one - the siblings are created in the same moment. After a confirmed find, HTProtect now shows every other program file created at practically the same time. On an infected site with 11,366 program files, a single anchor led to exactly the four backdoors, without one uninvolved file. If many files appear at once, that is an update, not an incident.
  • Spotting backdated files. A file’s modification time can be set freely; the moment the server first knew about it cannot. If a file claims to be much older than it is, that is deliberate. A migration or a restored backup is recognised and triggers nothing.
  • Checking Joomla’s guard line. Almost every Joomla program file starts with the line defined('_JEXEC') or die, which stops it being called directly in a browser - a backdoor leaves it out. The comparison runs folder by folder and only reports a file that additionally behaves like an entry point. Across 14 sites with around 180,000 program files not a single false alarm was left - but a disguised backdoor came to light that no signature had caught.
  • A suspicion stays a suspicion. Findings from these three methods sit in a section of their own, each line with its reason. They do not turn your site’s status red and they trigger no notification: they are pointers, not proof.
  • Core file verification now checks both directions. Until now it only looked at whether a file Joomla ships had been altered. But an intrusion rarely alters anything, it puts something alongside - so program files sitting in Joomla’s own folders without belonging there are now listed too. And a detected malware pattern now outweighs a file’s classification: findings could previously hide behind “template customisation”.
  • Newly detected: backdoors that fetch their payload. One site carried 86 of them - innocuously named, with no recognisable malicious code; the payload is only pulled from an archive next to it when the file is called. What is detected is the construction, not the name. This works immediately through the continuously updated definitions, even without this version.
  • Noticeably fewer false alarms. Joomla’s own log files, PDF libraries and inert leftovers in dependency and media folders no longer raise suspicion.
  • Long lists of findings can be worked through quickly. Expand all contents at once, filter by modification date - 86 findings from the same day are one incident, not 86 problems - and finally delete everything left in one go. Files locked by your host can now be removed as well.
v2.7.92026-09-07FixedImproved
  • Settings can be saved again. Joomla stores an extension’s entire configuration in a single database field of fixed size. On sites with many custom rules and settings grown over time that field was full, and saving was refused. Until now HTProtect moved out only a fixed list of known data types, so the problem could come back. It now works out the size before every save and moves out the largest blocks until there is room for certain - whatever they are, including very long custom rules. Affected sites tidy themselves up on the next save; settings and rules stay untouched.
  • HTProtect keeps the database and disk space tidy. Several places produced data that never went away again. Joomla’s task log gained around 35,000 lines a year from the quarter-hourly task, and Joomla has no retention limit for it - HTProtect now clears its own lines daily, leaving other entries alone. The file manager’s undo backups are removed after 14 days, sooner if together they exceed 200 MB. Interrupted file transfers and state files from interrupted checks are cleaned up, and a failed core update no longer leaves around 100 MB of unpacked files behind.
  • Confirmed exceptions in core file verification are kept. A finding you confirmed as harmless - a core file patched by your host, for instance - was lost after a short while and reported again. Those confirmations now stay for good.
v2.7.82026-09-05Fixed
  • Automatic Joomla core updates could not be switched on from the dashboard. Joomla then reported “automatic updates not available”. Since Joomla 5.3 a site has to register with the Joomla project’s automation service - HTProtect wrongly considered it already registered, so registration never happened. Only switching it off and on in the back end helped. Registration is now triggered when you switch it on, and withdrawn when you switch it off. If Joomla’s prerequisites are missing, HTProtect says so instead of reporting a success that is none.
  • SP Page Builder: findings show up again - and are removed completely. Newer versions changed their database structure; the check asked for something that no longer exists, stopped silently and reported “nothing found” - even with hundreds of planted entries. It now works regardless of the structure. Cleaning up also removes the planted files, not just the database entries, which clears the foreign references from the site’s source as well. Icon fonts you uploaded yourself are left alone.
  • On a fresh installation, the address for alerts is prefilled again. When you first open HTProtect it enters the signed-in administrator’s address - visibly, changeable at any time, and only if none is stored yet. This had been missing since 2.6.2, so alerts went to nobody unless you set it yourself.
Show older changelogs
v2.7.72026-09-04Fixed
  • RO CSVI: import and export work again. The extension calls an entry point of its own for this, and the protection shield had been blocking it with “403 access denied” - just as other security tools’ firewalls do. That one path is now permanently allowed; nothing else about the protection changes.
  • Notification emails show file names in plain text again. Instead of an internal placeholder you now get the readable name, in the same language as the rest of the email - no more mixed languages.
  • Small thing. On the auto-update switch, the “security only” level is now shown in gold, matching the dashboard.
v2.7.62026-09-03NewSecurityFixed

User accounts on all connected sites can now be managed straight from the dashboard - end-to-end encrypted.

  • One-click login now picks the right administrator. In the dashboard you set which account it should use - up to three identifiers, in the order that matters to you. The site works out the matching account itself and reports back only its number; email addresses stay on the site. Until now it simply took the oldest administrator. Applies to new sites, and to all existing ones with one click.
  • New: a user manager for the whole fleet. Per site you can view, create and edit accounts, set passwords, block, unblock and delete, with search and filters for active, blocked, unconfirmed and super user. On top of that, a search across all sites by name, username or email, and bulk actions for offboarding. No compromise on privacy: user data never reaches the HTProtect server, everything runs encrypted directly between your browser and the site. Management is off by default per site and can only be enabled for a limited time, and the last remaining administrator is always protected.
  • Outside changes to the protection file are reported. If it is altered outside the internal rule block, by hand or by an attack, you now get an email with the exact lines - before HTProtect restores the correct state automatically. HTProtect’s own updates still trigger nothing.
  • Small things. If the back end is protected by the secret access string, the self-test no longer treats that as a problem but checks availability correctly and reports green. And individual notes in the self-test show proper umlauts again.
v2.7.52026-09-02FixedImproved
  • No more false alarms when only the formatting of the protection file changes. Occasionally the monitoring sent an email about a change although the back end showed nothing of substance and the protection rules worked unchanged - mostly with hosts that reformat the file slightly on their own. The internal rule block does shift over time: new protection signatures, a different order, altered indentation. HTProtect now judges that section exactly as the back-end view does. A genuinely planted foreign rule - a redirect, malicious code, weakened protection - is still detected and reported reliably.
  • The notification now shows what changed. For a real change made outside HTProtect, the email lists the differing lines: what HTProtect expected and is missing, and what is there on top. You can see straight away whether it was a harmless adjustment or something planted, without comparing the files yourself.
v2.7.42026-09-02NewImproved
  • “Heal the shield” now recreates a missing protection file. If it is gone entirely - deleted by accident, renamed, or removed by an attack - “heal the shield” brings the protection back, for one site or for many at once. Until now it only refreshed a file that was still there but altered. Where that is not possible, for instance with externally managed configuration or on servers that work without this file, the dashboard now tells you why.
  • Restoring a backup, now with a choice. “Overwrite” leaves existing and newer files in place, as before. “Full restore” brings both the web space and the database to exactly the state of the backup and removes everything added since - including files and tables planted by an attack. After an incident that gives you a clean site straight away. HTProtect itself, its backups and its data folder are always kept, as are tables you deliberately excluded from the backup. “Overwrite” is preselected; “full restore” is a deliberate choice and clearly warned about. Before every restore, a backup of the current state is made automatically, as always.
  • Shorter unlock window. File and database management now stays unlocked for one hour instead of six. Unlocking again takes one click.
v2.7.32026-08-31Improved
  • Enabling is quicker, and the time window is predictable. File and database management is now enabled for a fixed period instead of extending itself every time you use it, so it reliably switches off again. The extra password or passkey prompt when enabling is gone. Protection stays high: every action is signed with your device key and end-to-end encrypted, and management is still off by default.
  • Database export and import are compressed. As .sql.gz the files are much smaller, so more data fits into one export. Uncompressed is still available.
v2.7.22026-08-30NewSecurity

File and database management straight from the dashboard - end-to-end encrypted, without a back-end login and without an extra tool on the site.

  • Manage files and the database from the dashboard. The file manager lets you browse, view, edit, upload, rename, move, copy and delete, several items at once as well; HTProtect’s own program folder and sensitive files stay protected. Database management opens full screen: view and edit tables, inspect the structure, run SQL, export as SQL or CSV, import, and search across all tables. It uses the database the site is connected to anyway, so you need no separate credentials.
  • Off by default, and only on for a while. Management stays switched off until you enable it for a site, with your identity confirmed beforehand. A visible countdown shows when it switches itself off again.
  • Small things. In Joomla’s global configuration, the “Site offline” field now carries a note: that offline mode stops no attacker - HTProtect’s emergency mode is there for that. And in the self-test, umlauts were sometimes shown as placeholders under “Which checks?”; that is fixed.
v2.7.12026-08-27NewSecurityFixed

Joomla 3 sites are now secured automatically against the current JoomShaper flaws, and the protection feed has been widely extended.

  • Joomla 3: Helix Ultimate and Helix3 are secured automatically. Joomla 3 has reached end of life and JoomShaper has stopped support - but published its own free security packages. Those official packages are what HTProtect now installs by itself: each is checked against a stored checksum first, the affected area is backed up, and if anything fails it is rolled back. This runs as part of automatic security updates; if you have those switched off on purpose, you trigger the patch per site with one click in the dashboard. SP Page Builder is deliberately not included: according to the vendor, the widely discussed upload flaw does not affect the Joomla 3 edition at all.
  • After a Helix update, HTProtect repairs the template itself. Such an update can reset the active template - header, logo and mega menu disappear and your own styling is no longer loaded. HTProtect notices this, restores the settings and refreshes the style cache; your own adjustments are kept. And a Joomla 3 site carrying the official patch now counts as secured in the security radar instead of being warned about for good.
  • Protection feed extended. Newly added: miniOrange OAuth and SAML, DPCalendar and Helix Ultimate. Plus wider version ranges for extensions HTProtect already warns about, Sourcerer up to version 16 among them. Where it works reliably, firewall protection comes on top of the warning.
v2.7.02026-08-26NewSecurityImproved

Joomla with a separate public folder is now fully supported, and the administration area can be protected with a secret access string instead of a second password.

  • Joomla in public folder mode is fully supported. If you run Joomla that way, you now get everything as usual: core verification, malware scanning, backups, automatic updates, back-end protection and real-time monitoring work just as reliably as on a classic installation. Nothing changes for ordinary installations.
  • New in back-end protection: a secret access string instead of a second password. The administration area can now be unlocked through a freely chosen, secret address: anyone who knows it signs in as normal, and for everyone else the login area simply is not there. Set up in seconds - in the back end, in the dashboard for one site or for many at once - and switched or turned off at any time. As with password protection, a confirmation email follows with an emergency link that turns the protection off again should you forget the string. One-click login from the dashboard keeps working seamlessly.
  • Core verification: mark your host’s patches as intended. Some hosts apply their own security patches straight to Joomla core files. You can now mark such changes as accepted, and verification stops reporting them as deviations. If the file changes again later, it reappears by itself - the exception is tied to exactly that one content.
  • Small things. When many sites sit on the same server, large core updates now run one after another instead of all at once, so the server is not overloaded; the overview shows which site is currently waiting. Access strings are stored encrypted in the dashboard. On top of that, numerous smaller hardening steps and fixes around the public folder and the new access string.
v2.6.192026-08-25FixedSecurity
  • Security updates for bundled extensions install automatically again. Some extensions ship as a package, a bundle of several parts - a component together with its plugins, as with JCE, Balbooa or language packs. Joomla keeps an internal record of which parts belong together, and that record can get out of step. HTProtect still spotted a due security update in those cases, but no longer installed it on its own. It now recognises from the vendor that the parts belong together and installs automatically again - the extra route only applies where the internal record really is missing. Sites where an update was left waiting catch up by themselves.
v2.6.182026-08-22NewSecurityImproved

Wider detection of injected administrator accounts, core updates now for Joomla 3 sites as well, and fresh protection warnings reach your site immediately.

  • Newly detected: injected administrator accounts using the address joomla@test.com. In a widespread wave of attacks, intruders create an admin account with exactly this email address on hijacked sites. HTProtect now flags such an account as injected in account monitoring and suspends it automatically where needed - always reversible, never the last remaining or the currently signed-in administrator, and released again at any time via “Confirm”. Deliberately limited to this one address so there are no false alarms.
  • Core updates now for Joomla 3 as well. Joomla 3 no longer receives official updates, but the community distribution “JoomlaWorks Joomla 3.x” keeps supplying security updates for Joomla 3.10+. With that source, or one of your own, entered in Joomla, HTProtect now updates the Joomla 3 core just as it does on Joomla 5/6: robust, resumable, for one site or the whole fleet, without a back-end login - within the same major version only. The overview lets you set the update server for all Joomla 3 sites in one go. Core verification supports Joomla 3 now too, without false alarms.
  • Fresh protection warnings take effect at once. Until now the protection feed was synced every six hours. On a manual “refresh status” - for one site or the whole fleet - and after every self-update of HTProtect, it is now reloaded immediately as well. Newly published or corrected warnings therefore take effect straight away instead of waiting for the next window. The automatic six-hour sync stays in place alongside it.
  • New warnings in the protection feed. HTProtect now also warns about vulnerabilities in JEM (Joomla Event Manager), JoomGallery and J2Store/J2Commerce, and points to the right update for Fabrik - each with a clear recommendation. These warnings arrive through the feed and reach you regardless of your version.
v2.6.172026-08-21FixedNewSecurity
  • Gridbox loads images again - and back-end protection can be set up again after a move. In Balbooa’s Gridbox builder a protection rule wrongly blocked certain image addresses: images went missing and changes could not be saved. Genuine images now always pass; only non-images and real attack patterns stay blocked. Also fixed: after a server move or a restored backup, password protection for the administration area sometimes could not be set up again - HTProtect now works out the right location itself. Standard installations were never affected.
  • Automatic advance fix for a Joomla bug in the template manager. An official Joomla security patch broke the template manager in Joomla 5.4.8 and 6.1.3 - creating overrides, managing folders and uploading files no longer worked. Joomla fixes this only with the next release; until then HTProtect applies the correction itself: only on exactly those two versions, once, reversibly and noted in the action log.
  • New warnings for YOOtheme Pro, Zoo and Convert Forms. In YOOtheme Pro an ordinary editor can already attack the database; in the Zoo content builder, malicious code can be injected through form fields without any login; and in Convert Forms, unauthorised visitors could read a form’s entries without logging in. Affected sites see the recommendation to update to the corrected version in the dashboard.
  • Small things. The notice "protection rules outdated" also appeared briefly after an update, although it resolves itself - it now shows only when something actually needs doing. And a clean self-update of HTProtect is accepted on the first attempt; one that genuinely fails is still rolled back.
v2.6.162026-08-19SecurityFixed
  • Joomla core updates now get through in more cases. Upload folder hardening is now guaranteed to protect only genuine upload folders, never a program directory such as the administration area - an entry like that could stop a core update with "access denied". The default was never affected. Remove a folder from the hardening list and its protection file now goes too, and a misplaced one is cleared away by HTProtect on its own. The core update tools of BackupMonkey and RemoteMonkey now run through without any setting.
  • New via the live feed, active immediately without an update. The firewall now blocks three attack routes: injected PHP code in Balbooa Forms (CVE-2026-67364, top severity 10.0, affected up to 2.4.3.1), deletion of arbitrary files in J-Business Directory by CMS Junkie (CVE-2026-75949, affected up to 6.2.2) and uploaded web shells in Zoo by YOOtheme (affected up to 4.1.63). Added as a warning: cross-site scripting in Phoca Cart (up to 6.1.7) and Phoca Download (up to 6.1.4). All five are only fully closed by updating to Balbooa Forms 2.4.3.2, J-Business Directory 6.2.3, ZOO 4.1.64, Phoca Cart 6.1.8 and Phoca Download 6.1.5. Everything reaches your sites by itself at the next quiet self-check; there is nothing to do.
v2.6.152026-08-18NewFixedImproved
  • Fleet-wide content search. From the dashboard, search the content of selected sites - articles, modules, custom fields - for a word or pattern. Searching for {source}, for example, shows which sites contain the Sourcerer building block. Executable code found in content is highlighted and listed first. The search only reads and changes nothing.
  • Core updates no longer break off when the administration area carries an extra password. That used to happen shortly after the start. The new files are now also copied in small, resumable steps.
  • Small thing. During a bulk core update in the dashboard, each site keeps its result message - updated, running or failed -, even after the progress bar disappears.
v2.6.142026-08-17SecurityImproved
  • Disguised spam pages inside a single language section are now found. Attackers like to slip such pages into one language section of a multilingual site, where they barely stand out. HTProtect now checks every active language instead of just the home page, spots pages that pose as yours while quietly redirecting their search-engine signals to a foreign address, and finds planted files inside a language section - continuously and during the file scan, each designed to avoid false alarms. The firewall already blocks the ways in; this catches what might still slip through.
  • New via the live feed, active immediately without an update. HTProtect now blocks two more flaws that need no login: in the iCagenda calendar (CVE-2026-67365) and in Cotton Cloud’s file access (CVE-2026-67283). It also warns about a critical flaw in Sourcerer by Regular Labs (severity 10 out of 10, CVE-2026-74253) - every version up to 13.1.1 is affected, and 14.0.0 is safe.
  • Important for Fabrik. The interim releases 4.6.7 and 4.6.8 do not fix the critical flaw from 2.6.7 - update to 4.7.0. HTProtect blocks the attack itself either way. Also, the wording of vulnerability notices is now shorter and clearer.
v2.6.132026-08-16SecurityNewImproved
  • Immediate protection against a critical flaw in Phoca Cart. Through the shop’s product filter, attackers could read the database without logging in (CVE-2026-74251, severity 9.3 out of 10). HTProtect’s firewall already blocks such attacks - the rule arrived automatically through the live feed, with no update or setup. Versions up to 6.1.6 are affected; for full protection update to Phoca Cart 5.2.4 or 6.1.7.
  • Design the maintenance page freely, images included. You edit text and headings in the familiar editor, and inserted images show up even while the site is locked. You can adjust it before locking, too. It now holds up reliably alongside your own server rules, and the “emergency mode active” notice appears dependably - whether you start it from the back end or the dashboard.
  • Also: a confirmation prompt before the automatic monitoring is switched off, a direct link to emergency mode on the overview, noticeably fewer dashboard queries when nothing is pending, and improved malware detection.
v2.6.122026-08-15Fixed
  • No more confusing bulk “updated” entries in the Joomla log. After automatic updates, many nameless entries could show up there. The cause was outside HTProtect: some extensions rebuild Joomla’s update sources during installation, and Joomla writes one entry per extension while doing so. HTProtect now switches that logging off during background installs. Not a security incident - the entries were merely misleading, not harmful.
  • Language packs stay current on their own again. They are now reliably kept up to date with HTProtect’s self-update.
v2.6.112026-08-15FixedImproved
  • Remote control from the dashboard is reliable again. Emergency mode, the error display and the backward-compatibility plugin sometimes arrived late or not at all when toggled quickly - now it takes effect within seconds, and both dashboard and site show the real state. In emergency mode the secret access link appears immediately again, arrives by email, and “end” reliably releases the site.
  • Also: editing accounts after a one-click login opens reliably again, and additional back-end language packs now update automatically.
v2.6.102026-08-14NewImproved

Emergency mode - taking your whole site offline for a while - has been rebuilt: a tool of its own, one click, and you still get in at any time.

  • One click, independent of back-end protection. Locking the site previously required the password protection for the back end. Now it stands on its own - your back-end protection is untouched.
  • You cannot lock yourself out. Instead of a password you get a secret access link: open it once and you are back in until you end emergency mode. The browser you activate from is cleared right away, the link is also emailed to you and available in the dashboard - and one click creates a new one, invalidating the old.
  • A maintenance page that does not hurt your ranking. Visitors see a plain maintenance page in German or English depending on their browser, with the correct “temporary” signal - your pages stay in the Google index. It even appears when the site itself is down. You can edit the heading and text yourself.
  • A reminder so you do not forget. While the site is locked, only you see a small notice with an “end” link - at the bottom of the site and in the HTProtect back end. You can switch it on and off from the dashboard too; ending it gets through reliably even with the site fully locked.
v2.6.92026-08-14SecurityNewImproved

HTProtect now watches over the administrator accounts on your sites: planted accounts are disabled automatically, and your own access is restored if needed.

  • Planted administrators are disabled. If an attack creates its own administrator - through an outdated extension or straight in the database, bypassing Joomla, often with an impossible creation date such as “30.11.-0001” - that account is deactivated and loses its rights. Nothing is deleted, and if it turns out to be legitimate you release it again with one click. Administrators you create yourself through Joomla are left alone.
  • You will not be locked out. If an attacker locks your own administrator account or strips its rights behind Joomla’s back, HTProtect restores your access by itself. Whatever you change through Joomla’s user manager stays untouched, the last active administrator is never touched, and everything can be undone.
  • Much faster. A foreign account is stopped at the very first login attempt and otherwise detected on the next visit to the back end - instead of only after a waiting period. This runs in the background without slowing your site down.
  • Clearing spam accounts, now with live progress. When removing many spam accounts you can see how far along it is. It finishes safely even on very large sites: if your host interrupts the run, HTProtect picks up again exactly where it left off. Removed accounts remain restorable from the backup.
  • Also: if you delete a disabled account yourself, HTProtect stops reminding you about it.
v2.6.82026-08-11NewImproved
  • New registrations. Shows per site whether user registration can be closed safely, switches it on and off, and clears out the leftovers after a spam wave - only provably inactive bot accounts, with a preview, a confirmation and 30 days to undo.
  • Files quarantined by your host. Reveals files that your host’s virus scanner only locked instead of deleting, checks them, and lets you delete, clean or - if it was a false alarm - release them again with one click.
  • Also: a more reliable self-update, far fewer mistaken rollbacks after updates, and a clearer troubleshooting tool.
v2.6.72026-08-10Security
  • Protection against an actively exploited flaw in SP Page Builder. In versions 6.0.0 to 6.7.1, attackers could read data from the database without logging in. HTProtect blocks such requests until the vendor ships its patch (announced for 6.8.0).
  • Nothing for you to do. The protection arrives quietly through the automatic self-update - no login, no setting. The “load more” function on affected pages keeps working normally; only the attack attempts are rejected.
  • New protection for Fabrik (CVE-2026-66915). In every version up to 4.6.8, attackers could run their own code on the server without logging in - the highest severity, 10 out of 10. HTProtect’s built-in web firewall (WAF) blocks these attacks from now on: it pulls new rules by itself through its live feed, with no update required. Still recommended: update Fabrik to 4.7.0.
v2.6.62026-08-10NewImprovedFixed

Sites that no longer load at all can now be brought back remotely - and you fix the two most common causes of an outage straight from the dashboard.

  • Emergency remote rescue. If a site no longer loads at all, you can still reach it - through a tightly secured emergency access.
  • Fix two common causes of an outage with one click, for a single site or many at once: turn on the error display, which reveals what is behind a white screen and switches itself off again after 30 minutes - and re-enable Joomla’s compatibility plugin, whose absence makes older extensions crash.
  • Automatic core updates now drive Joomla’s own built-in feature. The overview therefore shows correctly where the core updates itself. Manual core updates are unchanged.
  • Also fixed: open post-install messages are recognised again and can be hidden, and the protection exceptions match more precisely.
v2.6.52026-08-09NewImprovedFixed

Mostly groundwork for the dashboard: the fleet overview now reliably spots when a site needs re-pairing, and gains new tool views. Plus a switch for automatic Joomla core updates - and the save error on large sites is structurally fixed.

  • Turn automatic Joomla core updates on and off (Joomla 5.4 and newer). The dashboard shows at a glance where they are active, and you switch them for one site or many at once. You reach that view via the "Tools" button in the search bar.
  • Save error on large sites fixed. Large machine-generated data blocks now live outside the 64 KB settings column; only the actual configuration stays there. The message "Settings could not be saved - database size limit reached" on sites with many extensions is a thing of the past. The switchover runs once by itself, with a fallback.
  • Polish for back-end access and the protection shield. If you deliberately skip the back-end password protection, that item now stays reliably green in the self-check - even if the site briefly cannot reach itself; remove the protection via the dashboard and it counts as skipped automatically. New: after writing the .htaccess the shield checks whether the administrator area is still reachable - if one of your own rules locks it out, the shield rolls back automatically and names the cause.
  • The overview now spots when a site needs re-pairing. With every routine status contact HTProtect reports a short checksum of the control key the site currently trusts. If it differs from the workspace key - after a reset or a lost connection, for instance - the dashboard flags it clearly, with no extra requests. Only the checksum of the public key is transmitted, never a secret.
  • Frugal status data for new dashboard views. HTProtect reports a compact bundle per site - back-end password protection, hosting server, write permissions, error display, open post-install messages, email delivery and, on Joomla 6, module versioning. Each status contact sends only a checksum; the full details only on an actual change. The email state comes from a daily connection test, without ever sending a mail. Plus two safe bulk actions: hide open post-install messages and (Joomla 6 only) enable module versioning.
v2.6.42026-08-07New
  • HTProtect now speaks many languages. The back end used to be German and English only - now 27 language packs are available. If your Joomla runs in another language, HTProtect offers the matching pack in the overview with a single click; it is downloaded signed and checked before installing. Regional variants such as Austrian German or Mexican Spanish automatically use the right pack, and you can hide the notice per language.
v2.6.32026-08-06ImprovedFixed
  • Fixed: false “file changed” alarm on the central protection file. Around HTProtect's own automatic update, it could wrongly report that the central protection file had been changed from outside - even though no one had changed anything (in the back end, and depending on your settings by email too). The cause was a brief time window during the self-update. This is now fixed; already-affected sites settle down on their own, and genuine outside changes are still detected and reported reliably. (Reported via the forum - thanks for that.)
  • After an update, all building blocks are immediately up to date. On an update, HTProtect now brings all its bundled background building blocks straight to the new version - especially handy if you look after many sites and don't open each one in the back end.
v2.6.22026-08-04NewImprovedFixed

Mainly for fleet operators: mass rollout in one go, back-end password protection for many sites at once, clearer malware findings, and hardening that leaves menus and design intact.

  • Mass rollout in one go. HTProtect can be deployed to many sites at once - each one adds itself to the dashboard automatically on install, with no individual pairing and without opening any back end (even across already-connected installs).
  • Back-end password protection for your whole fleet at once. You can now set up or remove the extra password prompt before the admin login for many sites at once, straight from the dashboard - each site its own password if you like, end-to-end encrypted and lockout-safe (tested first, rolled back automatically on failure).
  • Injected malware shown more clearly. Hidden JavaScript in page-builder/template options (e.g. YOOtheme) is now shown right at the exact spot and named plainly (e.g. “External script”) - with fewer false alarms; scripts you added yourself you can mark as harmless with one click.
  • Menus and design survive hardening. Some menus/templates (e.g. MaxiMenu CK) build their look via small PHP files; HTProtect now detects these when hardening and only releases the harmless ones - the layout no longer falls apart, and protection against real malware stays sharp.
v2.6.12026-08-03New

Brand new: AI control. You can connect your AI assistant - Claude or ChatGPT - to HTProtect and ask it in plain language about the security status of your entire Joomla fleet. Where you allow it, it can even help with content upkeep. You stay in control at all times.

  • Connect your AI assistant and just ask. Connect Claude or ChatGPT to HTProtect and ask in plain language about the security status of your whole Joomla fleet - and, where you allow it, let it help with content upkeep.
  • Connect in one click. You only enter one address in Claude or ChatGPT and confirm with a click - no password, no key to copy.
  • You stay in full control. The default is read-only; writing you enable per site individually, and the higher level (managing extensions) only on explicit request per site and for a limited time.
  • Securely built - and lockable anytime. The site only ever grants a tightly limited service account, never super-user rights - a full takeover is ruled out. Access is unlocked only by you (cryptographically in your browser, the server never sees credentials), and you can fully revoke it anytime with one click. Requires Joomla 4 or newer.
v2.6.02026-08-01SecurityNewImprovedFixed

A big update around automatic updates and the new remote management: on dashboard-connected sites security updates now apply reliably, failures are reported honestly, and large version jumps only happen when they actually close the gap.

  • Security updates now apply reliably on connected sites. On sites connected to the dashboard, HTProtect updates vulnerable extensions automatically - even when the local auto-update switch is off (security updates only).
  • Honest failure messages for updates. A failed update is now clearly reported as a failure with a reason - no more misleading “still running in the background”.
  • Large security updates safeguarded. A big version jump is only forced when it actually closes the gap - no risky wrong jump when the protection data lags behind briefly.
  • The dashboard “Auto” selection now takes effect reliably. The switch it needs is now set along with it; if something differs on the site, the dashboard detects it and enforces it with one click.
  • New “Remote management” menu item. Pairing with the dashboard is now reachable as its own component menu item.
  • Grace period now per extension. The waiting time before an update installs automatically can now also be set per extension via the dashboard. Security updates still run immediately.
v2.5.152026-07-30NewImprovedFixed
  • One-click login now works with a secretly protected back end too. If the back end is secured by a secret word in the address (e.g. with Akeeba Admin Tools), one-click login now works anyway - you store the word once in the dashboard, HTProtect appends it automatically when signing in and doesn't store it. Fixes a processing error from 2.5.14.
  • “Additional logins” is now collapsible. The extra back-end logins (since 2.5.14) now sit behind a link next to “Renew credentials” instead of in their own box; on its own line on mobile. Purely cosmetic.
v2.5.142026-07-30SecurityNewImprovedFixed

Highlight: you can now update the Joomla core of connected websites remotely from the dashboard - one at a time or several at once. Plus security findings reach the dashboard within seconds (and are named there specifically), broader detection of planted admin accounts, multiple back-end password logins, and slimmer update backups.

  • Update the Joomla core remotely (dashboard). From the dashboard you can now update the Joomla core of connected sites without logging in on site - one or several at once, with live progress and an optional full backup first. Deliberately conservative: only within the same major version (e.g. 5.4 to 5.4.7), no jump to the next generation; if something fails, the old version stays untouched.
  • Planted admin accounts from the Gridbox campaign: now the failed ones too. HTProtect now recognises the typical attacker accounts from the Balbooa Gridbox flaw regardless of their user group - including those whose escalation to administrator failed and looked harmless before. The pattern is tightly scoped (no false alarms); HTProtect only shows such accounts and never deletes automatically.
  • Security findings reach the dashboard immediately - and are named specifically. A new or resolved threat is now reported within seconds instead of at the next sync (up to half an hour later); the status flips at once. In the fleet overview the finding now appears in plain text on the tile (e.g. “New admin account”); only the category and count are transferred, never names or paths.
  • Fixed: regular administrators now appear in the hide list. The “hide HTProtect from individual users” list (available since 2.5.13) used to show only super users; regular administrators were missing. They are now listed correctly - protection and the default (super users only) stay unchanged.
  • Back-end password protection: multiple logins possible. The extra password prompt before the back end could previously use only one login; under “Back-end access” you can now add more (e.g. per staff member) and remove them individually. Each new login is tested first, and the last one can't be deleted - no one can lock themselves out.
  • Update backups considerably slimmed down. The rollback backups before auto-updates now consist of a single compressed archive each instead of tens of thousands of small files; HTProtect cleans up old ones automatically and tidies the existing stock once. A pure storage improvement - rolling back stays fully functional. (Spotted in the forum - thanks to webbie07.)
  • Help & support now points to the forum first. In the “Help & support” area, a note above the contact form now points to the htprotect.app forum (fastest help there); the contact form remains for personal matters. Just a note, no change in function.
v2.5.132026-07-29NewImprovedFixed

Two tangible improvements take centre stage: your settings now stay reliably in place (no more silent reset), and HTProtect can be hidden completely from regular administrators. Plus fewer false alarms and a bit of polish.

  • Saved settings no longer reset themselves to factory defaults. In rare cases HTProtect couldn't briefly read its saved configuration (e.g. during a database hiccup mid-update) and quietly fell back to factory settings, which then got written in - it looked as if settings reset themselves after an update (often: auto-updates back to “on”). HTProtect now distinguishes “nothing saved yet” from “existing settings temporarily unreadable” and overwrites nothing in the second case; your choice stays, and an affected site restores its state on the next save. (From the forum, several test sites.)
  • HTProtect can be restricted entirely to super users. From this version, HTProtect is visible and usable only to super users by default - regular administrators see neither the menu item nor the status tile. Under “Back-end access” you can grant it to regular administrators with one click; the visibility switch itself and the dashboard pairing always remain reserved for super users. Visibility only - protection keeps running for the whole site, and no one can lock themselves out.
  • The protection file now reliably catches up with new rules. New attack rules took effect immediately via the real-time guard, but the server-side rule file only updated on bigger changes and could visibly lag behind; it is now rewritten cleanly with all current rules at the next silent self-sync - without a false alarm. Protection was active throughout; all that's new is that the file no longer lags. (Spotted in the forum, thanks to Tom.)
  • Fewer malware-scanner false alarms (harmless graphics). Some extensions briefly place small icon graphics in temporary storage, which HTProtect used to flag as a precaution. The scanner now checks whether it really is a pure graphic with no embedded code and then raises no alarm - malicious files disguised as graphics are still detected. (Noticed via a swarm report.)
  • HTProtect is no longer a checkable row in the auto-update list. In the list of “additional extensions to update automatically”, HTProtect itself appeared as a tickable row - unnecessary, since its own “keep HTProtect itself up to date” switch handles that. Instead of the checkbox there is now just a fixed info line; what actually updates automatically doesn't change.
v2.5.122026-07-28SecurityNewImproved

New protection against actively exploited flaws in Balbooa Gridbox and Balbooa Forms, another vulnerability warning, and a dashboard that keeps site renames up to date automatically.

  • New protection against three actively exploited Balbooa Gridbox flaws. Even the current version 2.20.1 still has three open, currently exploited front-end entry points with no vendor fix: creating an account up to administrator without logging in, reading any of the site's files (including the central configuration file with the access data), or planting your own files. HTProtect blocks all three without disrupting anything legitimate (normal image display and the image editor keep working); each can be turned off individually. Reported to Balbooa.
  • New protection against a critical remote-execution flaw in Balbooa Forms. In all versions up to 2.4.2.1, an attacker could run arbitrary code on the server via a form with a signature field, without logging in - highest severity, actively exploited. HTProtect detects exactly this attack in the submitted form and blocks it; normal forms are unaffected. Recommendation: update to 2.4.3 or newer.
  • The site title in the dashboard now stays up to date automatically. HTProtect used to take the name shown in the dashboard only once, at connection time; if you renamed it later in Joomla, you kept seeing the old one. The dashboard now picks up a rename automatically - at the next status sync at the latest, or right away via “Refresh status”.
  • New vulnerability warning: Aimy Captcha-Less Form Guard. Versions 18.0 to 20.0 are affected (free and PRO edition); there is no workaround - only the update to 20.1 helps. HTProtect warns affected sites and points to 20.1.
v2.5.112026-07-28SecurityFixed

Two improvements: the exploit shield now detects attacks regardless of order, and one-click login works reliably on the first try even after a longer break.

  • Exploit shield: attack detection is now order-independent. Some protection rules recognise an attack by several markers in the web address that previously had to appear in a fixed order - an attacker could reorder them and slip past a single rule while the attack still worked. The rules now match regardless of order (in both protection layers, including submitted forms); the theoretical bypass is closed, and accuracy and false-alarm freedom are unchanged. Thanks to Tom from the community forum for the tip.
  • One-click login: reliable on the first try even after a longer break. If the previous Joomla session had expired after a longer period of inactivity, the direct entry from the dashboard occasionally showed the login screen first, so a second click was needed. This is fixed at the root - the first click now works reliably, even after a break, in every Joomla version.
v2.5.102026-07-27Improved

Housekeeping: HTProtect's large core reference copy now also lives in the central folder - so one exclusion in other backup tools still covers everything.

  • All large HTProtect files now in one place. The roughly 30 MB comparison copy of the Joomla core (used to check whether core files are unchanged) now also lives in the central folder administrator/_htprotect_backups. So a single exclusion in other backup tools still covers all of HTProtect's large files; function and checks are unchanged, and the copy is regenerated automatically when needed.
v2.5.92026-07-27SecurityNewImprovedFixed

Security and backup: an update is no longer rolled back by mistake (and backups stay malware-free), plus separate schedules for full and database backups, a continuous progress display, and one central, protected storage location.

  • Security: an automatic update is no longer rolled back by mistake - and backup packages stay free of malware. If foreign malware was already sitting in an extension folder before an update, HTProtect used to undo the (often security-critical) update as a precaution; it now only rolls back if the update itself planted or changed something - a pre-existing infection no longer blocks it (still reported by the scan), and a genuinely compromised update is still stopped. Known malicious files are also excluded from the rollback package, so restoring it can't reintroduce anything and no longer triggers antivirus false alarms.
  • Separate schedules for full and database backups. Both can now be scheduled independently (own rhythm and own keep count) and are retained separately - one never displaces the other. The incremental file backup is gone; existing schedules remain valid.
  • Database backup: continuous progress display, more robust and reliable. With very large databases the progress bar used to disappear at times; it now runs continuously to the end (even within huge tables) and no longer jumps back. The backup works in small chunks and never aborts midway, even on slow servers.
  • Backups clean up reliably and leave foreign backup archives out. Aborted backup remnants are now cleaned up daily (even without a backup schedule), and a running backup is never touched. Other backup tools' stores (Akeeba, JoomlaPack, XCloner) are now excluded so they don't bloat the backup - ordinary .zip files are included as normal again.
  • All large backups in one protected place. HTProtect's large backups are now bundled in one clearly named folder (administrator/_htprotect_backups) - so it can be excluded from other backup tools in one go. The location is shielded in several ways (a direct web download is impossible); existing backups are moved there safely during the update.
  • Warning list extended: SP Page Builder. Affected sites are now warned about two freshly disclosed flaws up to version 6.7.0 (including reading database contents without logging in). Recommendation: update to 6.7.1.
  • Clearer label: “Unify host names (www redirect)”. The field for a consistent www spelling now carries the “(www redirect)” hint - labelling only, function unchanged.
v2.5.82026-07-26SecurityNewFixed

Four improvements - the most important: an actively exploited HelixUltimate menu attack that secretly creates a hidden administrator is now detected and removable with one click.

  • Actively exploited HelixUltimate menu attack is now detected - and removable with one click. Through the HelixUltimate flaw, attackers inject a hidden script into the main-menu settings that hijacks a logged-in administrator's session to secretly create a hidden super administrator; the overview didn't flag it before because it carried no classic malware pattern and sat deep in a menu field. It's now reliably reported and can be removed precisely (reversible backup) - any account already created is additionally flagged by the account monitoring, and legitimate menu settings still don't trigger a false alarm. Reported from the forum (Chris), confirmed on an affected site.
  • One-click login now works reliably on the first try (Joomla 6). On Joomla 6, logging in directly from the dashboard occasionally showed the login screen first, so a second click was needed. That's fixed - the first click now works reliably, in every Joomla version.
  • A clean back-end scan result now appears in the dashboard immediately. After a clean scan in the Joomla back end, the malware tile in the dashboard used to stay on the old state until you ran another scan there. It now updates at once - only the time and the number of hits (0 = clean) are transferred, never file paths.
  • Full-backup downloads now work in Safari too. Downloading a complete website backup via the HTProtect.app dashboard didn't start in Safari before; HTProtect now requests it through a real browser window, so it runs just as reliably there as in other browsers. The backup itself is unchanged.
v2.5.72026-07-25Fixed

Storage fix: HTProtect's own update backups have shrunk drastically - and old ballast is cleaned up automatically.

  • HTProtect's own update backups massively reduced. The rollback backup taken before each self-update accidentally included HTProtect's own working cache (mainly a roughly 30 MB comparison copy of the Joomla core), which isn't needed for a rollback and is regenerated on demand. It's now excluded - a backup shrinks from around 33 MB to a few MB, and the rollback stays fully functional. Reported by a user (backup over 60 MB).
  • Already-accumulated backup ballast is cleaned up automatically. Older backups created before this update still contain the unnecessary cache; the daily cleanup now removes it after the fact and frees the space - the backups themselves stay intact and fully restorable.
v2.5.62026-07-25SecurityNewImproved

Less clutter, a complete storage analysis, and a new detection for disguised malicious scripts in templates.

  • An injected malicious script in the template settings is now detected - and removable with one click. A common trick hides a script in the Helix template options that quietly loads malware and runs on every page; the overview didn't flag it before because the visible part looked harmless. It's now reliably reported and can be cut out precisely - all other template settings stay untouched, with a reversible backup; legitimate scripts still don't trigger a false alarm. Reported via an affected customer site.
  • The storage analysis now always runs to completion - even on huge sites. Previously it stopped after a short while and showed only the largest folders, so a big space hog could be missed. It now measures everything in small chunks until the end - with a progress display and no abort, even on slow servers.
  • Old language caches are now cleaned up automatically. Because HTProtect updates itself several times a day, many outdated language caches piled up over time (normal Joomla behaviour, just amplified by the frequent updates). The daily cleanup now keeps only the current one per language and removes the old ones - other caches stay untouched.
v2.5.52026-07-25ImprovedFixed

A noticeably snappier dashboard, automatic cleanup of old backups, and a preventive hardening against a possible save error.

  • The backup storage analysis now responds quickly. When breaking down used space folder by folder, everything used to be re-measured on each expand - sluggish on large sites. The folder tree is now measured once and every expand is answered instantly from that result; sizes stay exact, and the backup contents never leave the website.
  • Dashboard actions now run immediately. Each action nudges the website to carry out the task right away instead of waiting for the next round (up to 10 minutes). A brief lock used to make a quick second click “hang”; it's now short enough that virtually every action runs at once - scans, one-click login and settings included.
  • Old backups and logs are cleaned up automatically. A daily cleanup now removes leftover update backups (e.g. from uninstalled extensions or aborted runs) and editor undo backups after 30 days, and caps internal logs - freeing up used space. Reported in the forum.
  • A possible “database error” when saving is additionally prevented. The SEO guard keeps a comparison snapshot of the home page; on very text-heavy sites this could grow so large that - as fixed elsewhere before - it blocked saving settings. The snapshot is now much more compact (without noticeably weakening detection); existing large snapshots shrink by themselves on the next run.
v2.5.42026-07-25ImprovedFixed

Fixes the “database error” when saving and makes sure findings can be removed even behind strict host firewalls.

  • “Database error” when saving fixed. HTProtect's ever-growing detection signatures gradually filled the storage they shared with your settings - after that, any further save (e.g. of a custom rule) failed with a “database error”. The signatures now live in their own unlimited, compressed storage; the switch happens automatically on first use after the update.
  • Plain text instead of “database error”. If a save does fail, HTProtect now names the actual cause instead of a generic message - and stops cleanly before the settings could be damaged.
  • Removing findings now works even with an active host firewall. On some servers the server firewall wrongly treated deleting a detected malicious file as an attack and blocked it (“403”). HTProtect now reliably works around this - deleting, clearing false alarms and the preview work again, and the safety check stays unchanged.
v2.5.32026-07-24NewFixed

Auto-update settings can now be edited in both places - in the dashboard and directly in the Joomla back end - and stay in sync for good.

  • Auto-update settings are now editable in both places - and always in sync. “Automatically update” per extension can now be set both in the HTProtect.app dashboard and directly in the Joomla back end; both views stay identical for good, and nothing resets unnoticed any more (the most recent change wins, with a change made directly on the website taking precedence in the rare tie). Vulnerable extensions with a known flaw are still always updated automatically - your manual “off” choice stays saved and applies again once the flaw is closed.
v2.5.22026-07-23ImprovedFixed

A small release focused on fixed false alarms and a noticeably faster status update in the dashboard.

  • Faster status update. When you actively poke a website from the dashboard - for example after fixing a red or yellow notice - it now reports its current state within seconds, instead of waiting up to 30 minutes for the next sign of life.
  • No more third-party scanner false alarms from update backups. The backup HTProtect creates before an update for the way back now holds only the necessary data and is stored compactly - foreign malware scanners no longer flag it by mistake. The rollback stays fully functional.
  • Fewer false-alarm emails from the protection-file guard. The guard now overlooks its own harmless timestamp and version markers - injected malicious rules are still detected immediately, but its own harmless changes no longer trigger a warning.
  • SEO guard: false alarm on embedded HTML fixed. Pages with embedded HTML blocks (common with page builders) are no longer wrongly judged as tampered with.
  • Clearer note about the free dashboard. The overview note now puts the benefit for each individual website first - security status, scans, one-click login, backups and auto-updates in one place, from your phone too, free for up to 5 websites. A discreet pointer now also appears in the help center.
v2.5.12026-07-20SecurityFixed

A small, targeted follow-up to 2.5.0: connecting to the dashboard now works even where it previously failed on the server, plus tighter security for the pairing and fewer false alarms.

  • Dashboard connection despite “error 406”. On some servers a protection module blocked the pairing before HTProtect even ran. The cause has been removed - affected websites now connect without trouble.
  • Dashboard pairing further secured. The pairing target is now read solely from the fixed, internal address - so a website's remote management cannot be diverted to a foreign server.
  • False alarm after an automatic release fixed. After automatically clearing safe content, the guard wrongly reported its own legitimate change as outside tampering (including a warning email). That no longer happens.
  • An aborted malware scan no longer reports “clean” by mistake. An interrupted scan is no longer saved as a result with zero findings - a possibly infected website therefore no longer appears clean by accident.
  • Three new warnings in the live feed: Events Booking, DJ-Classifieds and Balbooa Gridbox (each in older versions) - affected websites are warned.
v2.5.02026-07-18SecurityNewImproved

The biggest release so far: HTProtect's own backups — and a central dashboard for all your websites.

  • Backups straight from HTProtect. Full and top-up backups on your own schedule; downloads run straight from your website into your browser, and the current state is saved before any restore.
  • New: all your websites at a glance — at HTProtect.app. Entirely optional: update rules for all sites at once and one-click sign-in to the Joomla admin area. Control stays with you — every command must also be confirmed in your unlocked browser.
  • Scan all your websites for malware with one click. Optionally on an automatic schedule — and you get an email straight away if something turns up.
  • Full overview on your phone, too. The layout is built consistently for small screens — so you keep the complete picture on the go.
  • Security events in plain language. Events now read as plain text instead of codes — and you can mark a reported account change as known from afar.
  • Automatic updates now run on Joomla 3 as well.
v2.4.192026-07-18SecurityFixed
  • Better version detection. Security warnings now also reliably recognise version numbers with suffixes such as “Stable” (relevant e.g. for the jDownloads vulnerability). Maintenance update.
  • New security warnings in the live feed: JoomCCK and ChronoForms — existing installs see them immediately, no update required. The JoomCCK flaw is additionally blocked by an active protection rule.
v2.4.182026-07-16Fixed
  • No more false alarm with Imunify360. HTProtect's detection-signature file naturally contains many malware patterns — so the Imunify360 server scanner (used by some hosts) wrongly took it for something suspicious. It has been reworked so the false alarm no longer occurs — no more risk of being quarantined for no reason.
v2.4.172026-07-16Improved
  • No more endless failed update attempts. If an update repeatedly can't be installed automatically — e.g. a commercial extension whose download returns no package without a valid vendor key —, HTProtect no longer retries endlessly every hour: the gap grows (1 h → 2 h → … → max. 12 h), and after a fair window the automatic update is set neutrally to “manual required” (the exact reason is deliberately not asserted). No extra email — a newly offered version or a click on “check now” starts fresh again.
  • Tidier activity log. Repeated identical “skipped” entries are condensed into a single line with a counter — the history stays readable instead of being flooded by a constant skip.
  • Important: the security warning (red status + reminder) and the real-time protection keep running unaffected — only the automatic install stops; the vulnerability stays visible and is still blocked. The update package and feed remain cryptographically signed as before.
v2.4.162026-07-15SecurityNew
  • Vulnerable extension: snooze the warning. If you can't update a vulnerable extension (abandoned, breaking changes, licence), you can now silence its warning per extension with one click — no more recurring emails, and the status won't turn red. Still honest, though: if HTProtect's active shield already blocks the attack, the line shows green (“actively protected”); a genuine residual risk stays yellow — never glossed over as “all green”. It expires automatically when the version rises, the severity increases, or a new security advisory appears — reversible anytime via “re-enable”.
  • New security warning in the live feed: 4Analytics < 5.0.2 (critical, exploitable without login) — existing installs see it immediately, no update required.
v2.4.152026-07-14SecurityNewImproved
  • The protection shield keeps itself up to date. When HTProtect improves its .htaccess protection rules, the shield is now re-applied automatically — no more clicking “secure now” by hand on every site when the status briefly turns orange after an update. All fully automatic in the background, without any backend login (handy when you manage many sites).
  • Done safely: with a self-test and automatic rollback if something doesn't fit — externally managed or self-customised .htaccess files stay untouched. The “keep the ruleset up to date automatically” switch sits in the shield section (on by default, switch off anytime).
  • New: hidden malware in the database is found and removed. HTProtect now scans two previously blind spots: injected JavaScript in Helix Ultimate mega menus and tampered SP Page Builder entries. Findings can be cleaned up with one click — a backup is always made first and legitimate content stays untouched.
v2.4.142026-07-14SecurityNewFixed
  • New: Joomla core-file check. Compares your core files against the original, highlights changed lines in colour and restores them with one click — tampering is quick to spot and undo.
  • New protection against the DPCalendar flaw. Through the calendar, outsiders could read your database — HTProtect now blocks this automatically and warns you about a vulnerable version.
  • Keeps itself up to date out of the box. Freshly installed copies update themselves automatically — switchable off with one click anytime.
  • Fixed: missing design on some servers. A problematic setting was removed; affected sites load normally again and repair themselves.
  • A gentle invitation to leave a review in the Joomla Extensions Directory — only once the shield has proven itself (all-green, after at least 7 days), never during an open warning, and dismissible anytime.
v2.4.132026-07-13New
  • Update-source guardian: if Joomla accidentally disables an extension's update source after a brief server hiccup, HTProtect switches it back on automatically — so you never silently miss update notices. Includes an exceptions dialog for sources you want left alone.
v2.4.122026-07-11SecurityNewImproved
  • Security: HTProtect's own update packages are now cryptographically signed and verified BEFORE installation — a tampered package is refused.
  • New: a one-time welcome email after setup; recover backend password protection via a secure email link; optionally hold back big version jumps (major updates).
  • Improved: attack signatures and the vulnerable-extensions list now refresh every 3 hours (was 6) — new attack waves are blocked faster.
  • Gallery thumbnails work despite backend password protection; clearer texts and instructions.
v2.3.32026-06-22JED EditionImproved
  • Code cleanups for Joomla Extensions Directory conformance — no change to behaviour or protection.
Note: between the versions listed here there were sometimes quick internal iterations. What's shown is what matters to you as a user.
v2.2.542026-06-17Security
  • Detects obfuscated JavaScript malware injected into legitimate files (e.g. the “jmtouch” campaign) — reliably and without false alarms.
v2.2.532026-06-17ImprovedSecurity
  • The malware scanner now also catches empty “probe” PHP files in /images and back-tick command shells; plus a few false-alarm refinements.
v2.2.522026-06-17FixedNew
  • No more “update available” after purely cosmetic changes; a discreet donation note on the Help page; the dashboard tile now appears reliably on all Joomla 5/6 setups; no false “password changed” alert on login.
v2.2.512026-06-17SecurityImproved
  • Detects PHP shells disguised as images; the “protection out of date” hint now only appears on real rule changes; a simpler one-button malware scan with honest progress.
v2.2.502026-06-16FixedNew
  • The PHP shield no longer wrongly flags non-existent .php paths; the malware scanner now runs in resumable chunks (no timeouts on huge sites) with delta re-scans and a progress bar.
v2.2.492026-06-16New
  • Recognises EasyCalcCheck Plus token protection as valid backend protection (status turns green).
v2.2.482026-06-16SecurityNewFixed
  • New rogue-admin check for the SP Page Builder campaign (planted Super Users); a new status tile on the Joomla home dashboard; fixed a rare save race condition.
v2.2.472026-06-16Security
  • Blocks the SP Page Builder zero-day (unauthenticated icon upload → code execution) in real time — only guests are blocked, logged-in builders are unaffected.
v2.2.462026-06-15Security
  • Added iCagenda < 4.0.8 (unauthenticated upload) to the warning list — existing installs see it via the live feed, no update required.
v2.2.452026-06-15New
  • Makes its .htaccess files read-only — blocking the common trick of malware rewriting them, without ever locking you out.
v2.2.442026-06-15FixedNew
  • Removed a redirect that could break AJAX calendars; the malware scanner finds PHP files disguised as images across the whole site.
v2.2.432026-06-15NewImproved
  • Akeeba Panopticon monitoring works out of the box on Joomla 3–6; the scanner reports .shtml includes and a known backdoor filename.
v2.2.422026-06-15NewSecurityImproved
  • Trusted paths now work across all protection layers; the rebuilt “URL test” checks a full URL against every layer and shows exactly what blocked it; a new entry-point integrity guard; many more malware detections (still false-alarm-free); new Super-User account monitoring; support for Joomla's public folder (5.1+).
v2.2.402026-06-13Improved
  • The deep malware scan is now an opt-in (button-only) feature under “Site Scan”; hacked JCE profiles can be removed with one click.
v2.2.392026-06-13New
  • A per-site whitelist (“mark as safe”) for the malware scanner; the Blogvault/MalCare connector folder is excluded from scans.
v2.2.382026-06-13New
  • A new deep scanner searches the whole webspace for malicious PHP — with a content preview and safe one-click removal.
v2.2.372026-06-13Fixed
  • Reliable detection of the real malicious .htaccess artifact; the overview loads fast again.
v2.2.362026-06-13Improved
  • The malicious-.htaccess scan now runs recursively across the whole webspace, with one-click cleanup.
v2.2.352026-06-13Security
  • Detects active traces of the JCE hack (a public upload profile) and the planted malicious .htaccess files, removable with a click.
v2.2.342026-06-13Fixed
  • A safety net against redirect loops — automatically rolls back after a problematic rule.
v2.2.332026-06-13Improved
  • A calm “fully secured” success state on the overview instead of a permanent “secure now” button.
v2.2.322026-06-13New
  • After “secure now” it shows which of your custom .htaccess rules weren't carried over — with position-accurate one-click re-add; Joomla's SVG protection is preserved.
v2.2.312026-06-13Fixed
  • Joomla 5/6: removed an empty toolbar bar; fixed umlauts in the page title.
v2.2.302026-06-13Improved
  • The Joomla up-to-date check now pulls the latest version live from the official Joomla API — always correct, no manual upkeep.
v2.2.292026-06-13Fixed
  • Fixed the toolbar title display on Joomla 3–6 (short form on mobile).
v2.2.282026-06-13Improved
  • UI polish across Joomla 2.5–6 (light mode on old Joomla, dynamic on 5/6); fixed cramped fields on Joomla 3.
v2.2.272026-06-13Improved
  • Removed “paranoid mode”; the generic always-on protection signatures remain active.
v2.2.262026-06-13SecurityNew
  • Real-time firewall greatly strengthened (also inspects POST data, multi-layer decoding, ReDoS-safe); exploit signatures are cryptographically signed; bilingual definitions in the live feed; anti-spam notifications.
v2.2.25Fixed
  • Baseline of this changelog — the last previously released version.

HTProtect — server shield for Joomla. 100% free