HTProtect.org
HTProtect HTProtect JOOMLA SECURITY
htprotect.org ช่องโหว่ความปลอดภัย & คู่มืออัปเดต
ใหม่ htprotect.app - จัดการเว็บไซต์ Joomla หลายแห่งจากศูนย์กลางเดียว
HTProtect

Changelog

What's new — short and clear.

Every notable change to HTProtect, newest first. Compact and free of jargon. The protection core stays rock-solid between versions — updates bring new detections, convenience and polish.

NewImprovedSecurityFixed
v2.6.72026-08-10LatestSecurity
  • Protection against an actively exploited flaw in SP Page Builder. In versions 6.0.0 to 6.7.1, attackers could read data from the database without logging in. HTProtect blocks such requests until the vendor ships its patch (announced for 6.8.0).
  • Nothing for you to do. The protection arrives quietly through the automatic self-update - no login, no setting. The “load more” function on affected pages keeps working normally; only the attack attempts are rejected.
  • New protection for Fabrik (CVE-2026-66915). In every version up to 4.6.6, attackers could run their own code on the server without logging in - the highest severity, 10 out of 10. HTProtect’s built-in web firewall (WAF) blocks these attacks from now on: it pulls new rules by itself through its live feed, with no update required. Still recommended: update Fabrik to 4.6.7 or newer.
v2.6.62026-08-10NewImprovedFixed

Sites that no longer load at all can now be brought back remotely - and you fix the two most common causes of an outage straight from the dashboard.

  • Emergency remote rescue. If a site no longer loads at all, you can still reach it - through a tightly secured emergency access.
  • Fix two common causes of an outage with one click, for a single site or many at once: turn on the error display, which reveals what is behind a white screen and switches itself off again after 30 minutes - and re-enable Joomla’s compatibility plugin, whose absence makes older extensions crash.
  • Automatic core updates now drive Joomla’s own built-in feature. The overview therefore shows correctly where the core updates itself. Manual core updates are unchanged.
  • Also fixed: open post-install messages are recognised again and can be hidden, and the protection exceptions match more precisely.
v2.6.52026-08-09NewImprovedFixed

Mostly groundwork for the dashboard: the fleet overview now reliably spots when a site needs re-pairing, and gains new tool views. Plus a switch for automatic Joomla core updates - and the save error on large sites is structurally fixed.

  • Turn automatic Joomla core updates on and off (Joomla 5.4 and newer). The dashboard shows at a glance where they are active, and you switch them for one site or many at once. You reach that view via the "Tools" button in the search bar.
  • Save error on large sites fixed. Large machine-generated data blocks now live outside the 64 KB settings column; only the actual configuration stays there. The message "Settings could not be saved - database size limit reached" on sites with many extensions is a thing of the past. The switchover runs once by itself, with a fallback.
  • Polish for back-end access and the protection shield. If you deliberately skip the back-end password protection, that item now stays reliably green in the self-check - even if the site briefly cannot reach itself; remove the protection via the dashboard and it counts as skipped automatically. New: after writing the .htaccess the shield checks whether the administrator area is still reachable - if one of your own rules locks it out, the shield rolls back automatically and names the cause.
  • The overview now spots when a site needs re-pairing. With every routine status contact HTProtect reports a short checksum of the control key the site currently trusts. If it differs from the workspace key - after a reset or a lost connection, for instance - the dashboard flags it clearly, with no extra requests. Only the checksum of the public key is transmitted, never a secret.
  • Frugal status data for new dashboard views. HTProtect reports a compact bundle per site - back-end password protection, hosting server, write permissions, error display, open post-install messages, email delivery and, on Joomla 6, module versioning. Each status contact sends only a checksum; the full details only on an actual change. The email state comes from a daily connection test, without ever sending a mail. Plus two safe bulk actions: hide open post-install messages and (Joomla 6 only) enable module versioning.
v2.6.42026-08-07New
  • HTProtect now speaks many languages. The back end used to be German and English only - now 27 language packs are available. If your Joomla runs in another language, HTProtect offers the matching pack in the overview with a single click; it is downloaded signed and checked before installing. Regional variants such as Austrian German or Mexican Spanish automatically use the right pack, and you can hide the notice per language.
v2.6.32026-08-06ImprovedFixed
  • Fixed: false “file changed” alarm on the central protection file. Around HTProtect's own automatic update, it could wrongly report that the central protection file had been changed from outside - even though no one had changed anything (in the back end, and depending on your settings by email too). The cause was a brief time window during the self-update. This is now fixed; already-affected sites settle down on their own, and genuine outside changes are still detected and reported reliably. (Reported via the forum - thanks for that.)
  • After an update, all building blocks are immediately up to date. On an update, HTProtect now brings all its bundled background building blocks straight to the new version - especially handy if you look after many sites and don't open each one in the back end.
v2.6.22026-08-04NewImprovedFixed

Mainly for fleet operators: mass rollout in one go, back-end password protection for many sites at once, clearer malware findings, and hardening that leaves menus and design intact.

  • Mass rollout in one go. HTProtect can be deployed to many sites at once - each one adds itself to the dashboard automatically on install, with no individual pairing and without opening any back end (even across already-connected installs).
  • Back-end password protection for your whole fleet at once. You can now set up or remove the extra password prompt before the admin login for many sites at once, straight from the dashboard - each site its own password if you like, end-to-end encrypted and lockout-safe (tested first, rolled back automatically on failure).
  • Injected malware shown more clearly. Hidden JavaScript in page-builder/template options (e.g. YOOtheme) is now shown right at the exact spot and named plainly (e.g. “External script”) - with fewer false alarms; scripts you added yourself you can mark as harmless with one click.
  • Menus and design survive hardening. Some menus/templates (e.g. MaxiMenu CK) build their look via small PHP files; HTProtect now detects these when hardening and only releases the harmless ones - the layout no longer falls apart, and protection against real malware stays sharp.
v2.6.12026-08-03New

Brand new: AI control. You can connect your AI assistant - Claude or ChatGPT - to HTProtect and ask it in plain language about the security status of your entire Joomla fleet. Where you allow it, it can even help with content upkeep. You stay in control at all times.

  • Connect your AI assistant and just ask. Connect Claude or ChatGPT to HTProtect and ask in plain language about the security status of your whole Joomla fleet - and, where you allow it, let it help with content upkeep.
  • Connect in one click. You only enter one address in Claude or ChatGPT and confirm with a click - no password, no key to copy.
  • You stay in full control. The default is read-only; writing you enable per site individually, and the higher level (managing extensions) only on explicit request per site and for a limited time.
  • Securely built - and lockable anytime. The site only ever grants a tightly limited service account, never super-user rights - a full takeover is ruled out. Access is unlocked only by you (cryptographically in your browser, the server never sees credentials), and you can fully revoke it anytime with one click. Requires Joomla 4 or newer.
v2.6.02026-08-01SecurityNewImprovedFixed

A big update around automatic updates and the new remote management: on dashboard-connected sites security updates now apply reliably, failures are reported honestly, and large version jumps only happen when they actually close the gap.

  • Security updates now apply reliably on connected sites. On sites connected to the dashboard, HTProtect updates vulnerable extensions automatically - even when the local auto-update switch is off (security updates only).
  • Honest failure messages for updates. A failed update is now clearly reported as a failure with a reason - no more misleading “still running in the background”.
  • Large security updates safeguarded. A big version jump is only forced when it actually closes the gap - no risky wrong jump when the protection data lags behind briefly.
  • The dashboard “Auto” selection now takes effect reliably. The switch it needs is now set along with it; if something differs on the site, the dashboard detects it and enforces it with one click.
  • New “Remote management” menu item. Pairing with the dashboard is now reachable as its own component menu item.
  • Grace period now per extension. The waiting time before an update installs automatically can now also be set per extension via the dashboard. Security updates still run immediately.
v2.5.152026-07-30NewImprovedFixed
  • One-click login now works with a secretly protected back end too. If the back end is secured by a secret word in the address (e.g. with Akeeba Admin Tools), one-click login now works anyway - you store the word once in the dashboard, HTProtect appends it automatically when signing in and doesn't store it. Fixes a processing error from 2.5.14.
  • “Additional logins” is now collapsible. The extra back-end logins (since 2.5.14) now sit behind a link next to “Renew credentials” instead of in their own box; on its own line on mobile. Purely cosmetic.
v2.5.142026-07-30SecurityNewImprovedFixed

Highlight: you can now update the Joomla core of connected websites remotely from the dashboard - one at a time or several at once. Plus security findings reach the dashboard within seconds (and are named there specifically), broader detection of planted admin accounts, multiple back-end password logins, and slimmer update backups.

  • Update the Joomla core remotely (dashboard). From the dashboard you can now update the Joomla core of connected sites without logging in on site - one or several at once, with live progress and an optional full backup first. Deliberately conservative: only within the same major version (e.g. 5.4 to 5.4.7), no jump to the next generation; if something fails, the old version stays untouched.
  • Planted admin accounts from the Gridbox campaign: now the failed ones too. HTProtect now recognises the typical attacker accounts from the Balbooa Gridbox flaw regardless of their user group - including those whose escalation to administrator failed and looked harmless before. The pattern is tightly scoped (no false alarms); HTProtect only shows such accounts and never deletes automatically.
  • Security findings reach the dashboard immediately - and are named specifically. A new or resolved threat is now reported within seconds instead of at the next sync (up to half an hour later); the status flips at once. In the fleet overview the finding now appears in plain text on the tile (e.g. “New admin account”); only the category and count are transferred, never names or paths.
  • Fixed: regular administrators now appear in the hide list. The “hide HTProtect from individual users” list (available since 2.5.13) used to show only super users; regular administrators were missing. They are now listed correctly - protection and the default (super users only) stay unchanged.
  • Back-end password protection: multiple logins possible. The extra password prompt before the back end could previously use only one login; under “Back-end access” you can now add more (e.g. per staff member) and remove them individually. Each new login is tested first, and the last one can't be deleted - no one can lock themselves out.
  • Update backups considerably slimmed down. The rollback backups before auto-updates now consist of a single compressed archive each instead of tens of thousands of small files; HTProtect cleans up old ones automatically and tidies the existing stock once. A pure storage improvement - rolling back stays fully functional. (Spotted in the forum - thanks to webbie07.)
  • Help & support now points to the forum first. In the “Help & support” area, a note above the contact form now points to the htprotect.app forum (fastest help there); the contact form remains for personal matters. Just a note, no change in function.
Show older changelogs
v2.5.132026-07-29NewImprovedFixed

Two tangible improvements take centre stage: your settings now stay reliably in place (no more silent reset), and HTProtect can be hidden completely from regular administrators. Plus fewer false alarms and a bit of polish.

  • Saved settings no longer reset themselves to factory defaults. In rare cases HTProtect couldn't briefly read its saved configuration (e.g. during a database hiccup mid-update) and quietly fell back to factory settings, which then got written in - it looked as if settings reset themselves after an update (often: auto-updates back to “on”). HTProtect now distinguishes “nothing saved yet” from “existing settings temporarily unreadable” and overwrites nothing in the second case; your choice stays, and an affected site restores its state on the next save. (From the forum, several test sites.)
  • HTProtect can be restricted entirely to super users. From this version, HTProtect is visible and usable only to super users by default - regular administrators see neither the menu item nor the status tile. Under “Back-end access” you can grant it to regular administrators with one click; the visibility switch itself and the dashboard pairing always remain reserved for super users. Visibility only - protection keeps running for the whole site, and no one can lock themselves out.
  • The protection file now reliably catches up with new rules. New attack rules took effect immediately via the real-time guard, but the server-side rule file only updated on bigger changes and could visibly lag behind; it is now rewritten cleanly with all current rules at the next silent self-sync - without a false alarm. Protection was active throughout; all that's new is that the file no longer lags. (Spotted in the forum, thanks to Tom.)
  • Fewer malware-scanner false alarms (harmless graphics). Some extensions briefly place small icon graphics in temporary storage, which HTProtect used to flag as a precaution. The scanner now checks whether it really is a pure graphic with no embedded code and then raises no alarm - malicious files disguised as graphics are still detected. (Noticed via a swarm report.)
  • HTProtect is no longer a checkable row in the auto-update list. In the list of “additional extensions to update automatically”, HTProtect itself appeared as a tickable row - unnecessary, since its own “keep HTProtect itself up to date” switch handles that. Instead of the checkbox there is now just a fixed info line; what actually updates automatically doesn't change.
v2.5.122026-07-28SecurityNewImproved

New protection against actively exploited flaws in Balbooa Gridbox and Balbooa Forms, another vulnerability warning, and a dashboard that keeps site renames up to date automatically.

  • New protection against three actively exploited Balbooa Gridbox flaws. Even the current version 2.20.1 still has three open, currently exploited front-end entry points with no vendor fix: creating an account up to administrator without logging in, reading any of the site's files (including the central configuration file with the access data), or planting your own files. HTProtect blocks all three without disrupting anything legitimate (normal image display and the image editor keep working); each can be turned off individually. Reported to Balbooa.
  • New protection against a critical remote-execution flaw in Balbooa Forms. In all versions up to 2.4.2.1, an attacker could run arbitrary code on the server via a form with a signature field, without logging in - highest severity, actively exploited. HTProtect detects exactly this attack in the submitted form and blocks it; normal forms are unaffected. Recommendation: update to 2.4.3 or newer.
  • The site title in the dashboard now stays up to date automatically. HTProtect used to take the name shown in the dashboard only once, at connection time; if you renamed it later in Joomla, you kept seeing the old one. The dashboard now picks up a rename automatically - at the next status sync at the latest, or right away via “Refresh status”.
  • New vulnerability warning: Aimy Captcha-Less Form Guard. Versions 18.0 to 20.0 are affected (free and PRO edition); there is no workaround - only the update to 20.1 helps. HTProtect warns affected sites and points to 20.1.
v2.5.112026-07-28SecurityFixed

Two improvements: the exploit shield now detects attacks regardless of order, and one-click login works reliably on the first try even after a longer break.

  • Exploit shield: attack detection is now order-independent. Some protection rules recognise an attack by several markers in the web address that previously had to appear in a fixed order - an attacker could reorder them and slip past a single rule while the attack still worked. The rules now match regardless of order (in both protection layers, including submitted forms); the theoretical bypass is closed, and accuracy and false-alarm freedom are unchanged. Thanks to Tom from the community forum for the tip.
  • One-click login: reliable on the first try even after a longer break. If the previous Joomla session had expired after a longer period of inactivity, the direct entry from the dashboard occasionally showed the login screen first, so a second click was needed. This is fixed at the root - the first click now works reliably, even after a break, in every Joomla version.
v2.5.102026-07-27Improved

Housekeeping: HTProtect's large core reference copy now also lives in the central folder - so one exclusion in other backup tools still covers everything.

  • All large HTProtect files now in one place. The roughly 30 MB comparison copy of the Joomla core (used to check whether core files are unchanged) now also lives in the central folder administrator/_htprotect_backups. So a single exclusion in other backup tools still covers all of HTProtect's large files; function and checks are unchanged, and the copy is regenerated automatically when needed.
v2.5.92026-07-27SecurityNewImprovedFixed

Security and backup: an update is no longer rolled back by mistake (and backups stay malware-free), plus separate schedules for full and database backups, a continuous progress display, and one central, protected storage location.

  • Security: an automatic update is no longer rolled back by mistake - and backup packages stay free of malware. If foreign malware was already sitting in an extension folder before an update, HTProtect used to undo the (often security-critical) update as a precaution; it now only rolls back if the update itself planted or changed something - a pre-existing infection no longer blocks it (still reported by the scan), and a genuinely compromised update is still stopped. Known malicious files are also excluded from the rollback package, so restoring it can't reintroduce anything and no longer triggers antivirus false alarms.
  • Separate schedules for full and database backups. Both can now be scheduled independently (own rhythm and own keep count) and are retained separately - one never displaces the other. The incremental file backup is gone; existing schedules remain valid.
  • Database backup: continuous progress display, more robust and reliable. With very large databases the progress bar used to disappear at times; it now runs continuously to the end (even within huge tables) and no longer jumps back. The backup works in small chunks and never aborts midway, even on slow servers.
  • Backups clean up reliably and leave foreign backup archives out. Aborted backup remnants are now cleaned up daily (even without a backup schedule), and a running backup is never touched. Other backup tools' stores (Akeeba, JoomlaPack, XCloner) are now excluded so they don't bloat the backup - ordinary .zip files are included as normal again.
  • All large backups in one protected place. HTProtect's large backups are now bundled in one clearly named folder (administrator/_htprotect_backups) - so it can be excluded from other backup tools in one go. The location is shielded in several ways (a direct web download is impossible); existing backups are moved there safely during the update.
  • Warning list extended: SP Page Builder. Affected sites are now warned about two freshly disclosed flaws up to version 6.7.0 (including reading database contents without logging in). Recommendation: update to 6.7.1.
  • Clearer label: “Unify host names (www redirect)”. The field for a consistent www spelling now carries the “(www redirect)” hint - labelling only, function unchanged.
v2.5.82026-07-26SecurityNewFixed

Four improvements - the most important: an actively exploited HelixUltimate menu attack that secretly creates a hidden administrator is now detected and removable with one click.

  • Actively exploited HelixUltimate menu attack is now detected - and removable with one click. Through the HelixUltimate flaw, attackers inject a hidden script into the main-menu settings that hijacks a logged-in administrator's session to secretly create a hidden super administrator; the overview didn't flag it before because it carried no classic malware pattern and sat deep in a menu field. It's now reliably reported and can be removed precisely (reversible backup) - any account already created is additionally flagged by the account monitoring, and legitimate menu settings still don't trigger a false alarm. Reported from the forum (Chris), confirmed on an affected site.
  • One-click login now works reliably on the first try (Joomla 6). On Joomla 6, logging in directly from the dashboard occasionally showed the login screen first, so a second click was needed. That's fixed - the first click now works reliably, in every Joomla version.
  • A clean back-end scan result now appears in the dashboard immediately. After a clean scan in the Joomla back end, the malware tile in the dashboard used to stay on the old state until you ran another scan there. It now updates at once - only the time and the number of hits (0 = clean) are transferred, never file paths.
  • Full-backup downloads now work in Safari too. Downloading a complete website backup via the HTProtect.app dashboard didn't start in Safari before; HTProtect now requests it through a real browser window, so it runs just as reliably there as in other browsers. The backup itself is unchanged.
v2.5.72026-07-25Fixed

Storage fix: HTProtect's own update backups have shrunk drastically - and old ballast is cleaned up automatically.

  • HTProtect's own update backups massively reduced. The rollback backup taken before each self-update accidentally included HTProtect's own working cache (mainly a roughly 30 MB comparison copy of the Joomla core), which isn't needed for a rollback and is regenerated on demand. It's now excluded - a backup shrinks from around 33 MB to a few MB, and the rollback stays fully functional. Reported by a user (backup over 60 MB).
  • Already-accumulated backup ballast is cleaned up automatically. Older backups created before this update still contain the unnecessary cache; the daily cleanup now removes it after the fact and frees the space - the backups themselves stay intact and fully restorable.
v2.5.62026-07-25SecurityNewImproved

Less clutter, a complete storage analysis, and a new detection for disguised malicious scripts in templates.

  • An injected malicious script in the template settings is now detected - and removable with one click. A common trick hides a script in the Helix template options that quietly loads malware and runs on every page; the overview didn't flag it before because the visible part looked harmless. It's now reliably reported and can be cut out precisely - all other template settings stay untouched, with a reversible backup; legitimate scripts still don't trigger a false alarm. Reported via an affected customer site.
  • The storage analysis now always runs to completion - even on huge sites. Previously it stopped after a short while and showed only the largest folders, so a big space hog could be missed. It now measures everything in small chunks until the end - with a progress display and no abort, even on slow servers.
  • Old language caches are now cleaned up automatically. Because HTProtect updates itself several times a day, many outdated language caches piled up over time (normal Joomla behaviour, just amplified by the frequent updates). The daily cleanup now keeps only the current one per language and removes the old ones - other caches stay untouched.
v2.5.52026-07-25ImprovedFixed

A noticeably snappier dashboard, automatic cleanup of old backups, and a preventive hardening against a possible save error.

  • The backup storage analysis now responds quickly. When breaking down used space folder by folder, everything used to be re-measured on each expand - sluggish on large sites. The folder tree is now measured once and every expand is answered instantly from that result; sizes stay exact, and the backup contents never leave the website.
  • Dashboard actions now run immediately. Each action nudges the website to carry out the task right away instead of waiting for the next round (up to 10 minutes). A brief lock used to make a quick second click “hang”; it's now short enough that virtually every action runs at once - scans, one-click login and settings included.
  • Old backups and logs are cleaned up automatically. A daily cleanup now removes leftover update backups (e.g. from uninstalled extensions or aborted runs) and editor undo backups after 30 days, and caps internal logs - freeing up used space. Reported in the forum.
  • A possible “database error” when saving is additionally prevented. The SEO guard keeps a comparison snapshot of the home page; on very text-heavy sites this could grow so large that - as fixed elsewhere before - it blocked saving settings. The snapshot is now much more compact (without noticeably weakening detection); existing large snapshots shrink by themselves on the next run.
v2.5.42026-07-25ImprovedFixed

Fixes the “database error” when saving and makes sure findings can be removed even behind strict host firewalls.

  • “Database error” when saving fixed. HTProtect's ever-growing detection signatures gradually filled the storage they shared with your settings - after that, any further save (e.g. of a custom rule) failed with a “database error”. The signatures now live in their own unlimited, compressed storage; the switch happens automatically on first use after the update.
  • Plain text instead of “database error”. If a save does fail, HTProtect now names the actual cause instead of a generic message - and stops cleanly before the settings could be damaged.
  • Removing findings now works even with an active host firewall. On some servers the server firewall wrongly treated deleting a detected malicious file as an attack and blocked it (“403”). HTProtect now reliably works around this - deleting, clearing false alarms and the preview work again, and the safety check stays unchanged.
v2.5.32026-07-24NewFixed

Auto-update settings can now be edited in both places - in the dashboard and directly in the Joomla back end - and stay in sync for good.

  • Auto-update settings are now editable in both places - and always in sync. “Automatically update” per extension can now be set both in the HTProtect.app dashboard and directly in the Joomla back end; both views stay identical for good, and nothing resets unnoticed any more (the most recent change wins, with a change made directly on the website taking precedence in the rare tie). Vulnerable extensions with a known flaw are still always updated automatically - your manual “off” choice stays saved and applies again once the flaw is closed.
v2.5.22026-07-23ImprovedFixed

A small release focused on fixed false alarms and a noticeably faster status update in the dashboard.

  • Faster status update. When you actively poke a website from the dashboard - for example after fixing a red or yellow notice - it now reports its current state within seconds, instead of waiting up to 30 minutes for the next sign of life.
  • No more third-party scanner false alarms from update backups. The backup HTProtect creates before an update for the way back now holds only the necessary data and is stored compactly - foreign malware scanners no longer flag it by mistake. The rollback stays fully functional.
  • Fewer false-alarm emails from the protection-file guard. The guard now overlooks its own harmless timestamp and version markers - injected malicious rules are still detected immediately, but its own harmless changes no longer trigger a warning.
  • SEO guard: false alarm on embedded HTML fixed. Pages with embedded HTML blocks (common with page builders) are no longer wrongly judged as tampered with.
  • Clearer note about the free dashboard. The overview note now puts the benefit for each individual website first - security status, scans, one-click login, backups and auto-updates in one place, from your phone too, free for up to 5 websites. A discreet pointer now also appears in the help center.
v2.5.12026-07-20SecurityFixed

A small, targeted follow-up to 2.5.0: connecting to the dashboard now works even where it previously failed on the server, plus tighter security for the pairing and fewer false alarms.

  • Dashboard connection despite “error 406”. On some servers a protection module blocked the pairing before HTProtect even ran. The cause has been removed - affected websites now connect without trouble.
  • Dashboard pairing further secured. The pairing target is now read solely from the fixed, internal address - so a website's remote management cannot be diverted to a foreign server.
  • False alarm after an automatic release fixed. After automatically clearing safe content, the guard wrongly reported its own legitimate change as outside tampering (including a warning email). That no longer happens.
  • An aborted malware scan no longer reports “clean” by mistake. An interrupted scan is no longer saved as a result with zero findings - a possibly infected website therefore no longer appears clean by accident.
  • Three new warnings in the live feed: Events Booking, DJ-Classifieds and Balbooa Gridbox (each in older versions) - affected websites are warned.
v2.5.02026-07-18SecurityNewImproved

The biggest release so far: HTProtect's own backups — and a central dashboard for all your websites.

  • Backups straight from HTProtect. Full and top-up backups on your own schedule; downloads run straight from your website into your browser, and the current state is saved before any restore.
  • New: all your websites at a glance — at HTProtect.app. Entirely optional: update rules for all sites at once and one-click sign-in to the Joomla admin area. Control stays with you — every command must also be confirmed in your unlocked browser.
  • Scan all your websites for malware with one click. Optionally on an automatic schedule — and you get an email straight away if something turns up.
  • Full overview on your phone, too. The layout is built consistently for small screens — so you keep the complete picture on the go.
  • Security events in plain language. Events now read as plain text instead of codes — and you can mark a reported account change as known from afar.
  • Automatic updates now run on Joomla 3 as well.
v2.4.192026-07-18SecurityFixed
  • Better version detection. Security warnings now also reliably recognise version numbers with suffixes such as “Stable” (relevant e.g. for the jDownloads vulnerability). Maintenance update.
  • New security warnings in the live feed: JoomCCK and ChronoForms — existing installs see them immediately, no update required. The JoomCCK flaw is additionally blocked by an active protection rule.
v2.4.182026-07-16Fixed
  • No more false alarm with Imunify360. HTProtect's detection-signature file naturally contains many malware patterns — so the Imunify360 server scanner (used by some hosts) wrongly took it for something suspicious. It has been reworked so the false alarm no longer occurs — no more risk of being quarantined for no reason.
v2.4.172026-07-16Improved
  • No more endless failed update attempts. If an update repeatedly can't be installed automatically — e.g. a commercial extension whose download returns no package without a valid vendor key —, HTProtect no longer retries endlessly every hour: the gap grows (1 h → 2 h → … → max. 12 h), and after a fair window the automatic update is set neutrally to “manual required” (the exact reason is deliberately not asserted). No extra email — a newly offered version or a click on “check now” starts fresh again.
  • Tidier activity log. Repeated identical “skipped” entries are condensed into a single line with a counter — the history stays readable instead of being flooded by a constant skip.
  • Important: the security warning (red status + reminder) and the real-time protection keep running unaffected — only the automatic install stops; the vulnerability stays visible and is still blocked. The update package and feed remain cryptographically signed as before.
v2.4.162026-07-15SecurityNew
  • Vulnerable extension: snooze the warning. If you can't update a vulnerable extension (abandoned, breaking changes, licence), you can now silence its warning per extension with one click — no more recurring emails, and the status won't turn red. Still honest, though: if HTProtect's active shield already blocks the attack, the line shows green (“actively protected”); a genuine residual risk stays yellow — never glossed over as “all green”. It expires automatically when the version rises, the severity increases, or a new security advisory appears — reversible anytime via “re-enable”.
  • New security warning in the live feed: 4Analytics < 5.0.2 (critical, exploitable without login) — existing installs see it immediately, no update required.
v2.4.152026-07-14SecurityNewImproved
  • The protection shield keeps itself up to date. When HTProtect improves its .htaccess protection rules, the shield is now re-applied automatically — no more clicking “secure now” by hand on every site when the status briefly turns orange after an update. All fully automatic in the background, without any backend login (handy when you manage many sites).
  • Done safely: with a self-test and automatic rollback if something doesn't fit — externally managed or self-customised .htaccess files stay untouched. The “keep the ruleset up to date automatically” switch sits in the shield section (on by default, switch off anytime).
  • New: hidden malware in the database is found and removed. HTProtect now scans two previously blind spots: injected JavaScript in Helix Ultimate mega menus and tampered SP Page Builder entries. Findings can be cleaned up with one click — a backup is always made first and legitimate content stays untouched.
v2.4.142026-07-14SecurityNewFixed
  • New: Joomla core-file check. Compares your core files against the original, highlights changed lines in colour and restores them with one click — tampering is quick to spot and undo.
  • New protection against the DPCalendar flaw. Through the calendar, outsiders could read your database — HTProtect now blocks this automatically and warns you about a vulnerable version.
  • Keeps itself up to date out of the box. Freshly installed copies update themselves automatically — switchable off with one click anytime.
  • Fixed: missing design on some servers. A problematic setting was removed; affected sites load normally again and repair themselves.
  • A gentle invitation to leave a review in the Joomla Extensions Directory — only once the shield has proven itself (all-green, after at least 7 days), never during an open warning, and dismissible anytime.
v2.4.132026-07-13New
  • Update-source guardian: if Joomla accidentally disables an extension's update source after a brief server hiccup, HTProtect switches it back on automatically — so you never silently miss update notices. Includes an exceptions dialog for sources you want left alone.
v2.4.122026-07-11SecurityNewImproved
  • Security: HTProtect's own update packages are now cryptographically signed and verified BEFORE installation — a tampered package is refused.
  • New: a one-time welcome email after setup; recover backend password protection via a secure email link; optionally hold back big version jumps (major updates).
  • Improved: attack signatures and the vulnerable-extensions list now refresh every 3 hours (was 6) — new attack waves are blocked faster.
  • Gallery thumbnails work despite backend password protection; clearer texts and instructions.
v2.3.32026-06-22JED EditionImproved
  • Code cleanups for Joomla Extensions Directory conformance — no change to behaviour or protection.
Note: between the versions listed here there were sometimes quick internal iterations. What's shown is what matters to you as a user.
v2.2.542026-06-17Security
  • Detects obfuscated JavaScript malware injected into legitimate files (e.g. the “jmtouch” campaign) — reliably and without false alarms.
v2.2.532026-06-17ImprovedSecurity
  • The malware scanner now also catches empty “probe” PHP files in /images and back-tick command shells; plus a few false-alarm refinements.
v2.2.522026-06-17FixedNew
  • No more “update available” after purely cosmetic changes; a discreet donation note on the Help page; the dashboard tile now appears reliably on all Joomla 5/6 setups; no false “password changed” alert on login.
v2.2.512026-06-17SecurityImproved
  • Detects PHP shells disguised as images; the “protection out of date” hint now only appears on real rule changes; a simpler one-button malware scan with honest progress.
v2.2.502026-06-16FixedNew
  • The PHP shield no longer wrongly flags non-existent .php paths; the malware scanner now runs in resumable chunks (no timeouts on huge sites) with delta re-scans and a progress bar.
v2.2.492026-06-16New
  • Recognises EasyCalcCheck Plus token protection as valid backend protection (status turns green).
v2.2.482026-06-16SecurityNewFixed
  • New rogue-admin check for the SP Page Builder campaign (planted Super Users); a new status tile on the Joomla home dashboard; fixed a rare save race condition.
v2.2.472026-06-16Security
  • Blocks the SP Page Builder zero-day (unauthenticated icon upload → code execution) in real time — only guests are blocked, logged-in builders are unaffected.
v2.2.462026-06-15Security
  • Added iCagenda < 4.0.8 (unauthenticated upload) to the warning list — existing installs see it via the live feed, no update required.
v2.2.452026-06-15New
  • Makes its .htaccess files read-only — blocking the common trick of malware rewriting them, without ever locking you out.
v2.2.442026-06-15FixedNew
  • Removed a redirect that could break AJAX calendars; the malware scanner finds PHP files disguised as images across the whole site.
v2.2.432026-06-15NewImproved
  • Akeeba Panopticon monitoring works out of the box on Joomla 3–6; the scanner reports .shtml includes and a known backdoor filename.
v2.2.422026-06-15NewSecurityImproved
  • Trusted paths now work across all protection layers; the rebuilt “URL test” checks a full URL against every layer and shows exactly what blocked it; a new entry-point integrity guard; many more malware detections (still false-alarm-free); new Super-User account monitoring; support for Joomla's public folder (5.1+).
v2.2.402026-06-13Improved
  • The deep malware scan is now an opt-in (button-only) feature under “Site Scan”; hacked JCE profiles can be removed with one click.
v2.2.392026-06-13New
  • A per-site whitelist (“mark as safe”) for the malware scanner; the Blogvault/MalCare connector folder is excluded from scans.
v2.2.382026-06-13New
  • A new deep scanner searches the whole webspace for malicious PHP — with a content preview and safe one-click removal.
v2.2.372026-06-13Fixed
  • Reliable detection of the real malicious .htaccess artifact; the overview loads fast again.
v2.2.362026-06-13Improved
  • The malicious-.htaccess scan now runs recursively across the whole webspace, with one-click cleanup.
v2.2.352026-06-13Security
  • Detects active traces of the JCE hack (a public upload profile) and the planted malicious .htaccess files, removable with a click.
v2.2.342026-06-13Fixed
  • A safety net against redirect loops — automatically rolls back after a problematic rule.
v2.2.332026-06-13Improved
  • A calm “fully secured” success state on the overview instead of a permanent “secure now” button.
v2.2.322026-06-13New
  • After “secure now” it shows which of your custom .htaccess rules weren't carried over — with position-accurate one-click re-add; Joomla's SVG protection is preserved.
v2.2.312026-06-13Fixed
  • Joomla 5/6: removed an empty toolbar bar; fixed umlauts in the page title.
v2.2.302026-06-13Improved
  • The Joomla up-to-date check now pulls the latest version live from the official Joomla API — always correct, no manual upkeep.
v2.2.292026-06-13Fixed
  • Fixed the toolbar title display on Joomla 3–6 (short form on mobile).
v2.2.282026-06-13Improved
  • UI polish across Joomla 2.5–6 (light mode on old Joomla, dynamic on 5/6); fixed cramped fields on Joomla 3.
v2.2.272026-06-13Improved
  • Removed “paranoid mode”; the generic always-on protection signatures remain active.
v2.2.262026-06-13SecurityNew
  • Real-time firewall greatly strengthened (also inspects POST data, multi-layer decoding, ReDoS-safe); exploit signatures are cryptographically signed; bilingual definitions in the live feed; anti-spam notifications.
v2.2.25Fixed
  • Baseline of this changelog — the last previously released version.

HTProtect — server shield for Joomla. 100% free