Akeeba Admin Tools PRO - Joomla site security component

Akeeba Admin Tools PRO - Joomla site security component v7.9.2

No permission to download
Decryption key:


Akeeba Admin Tools PRO - Joomla site security component v7.9.2
Admin Tools 7.9.2

Added Obsolete Core Files feature: removing leftover files after a Joomla! update
Added Bad Words: Escape Regular Expression; a plain word matches itself literally
Added Preferred fallback language option for notification emails, and an option to force it for all
Added New --exempt-ip option for the admintools:eek:ffline CLI command
Changed web.config Maker: remove naming of the rule blocking access to configuration.php-dist and htaccess.txt
Fixed [HIGH] admintools:temp:clear from the CLI never finished on sites with a lot to clean up
Fixed [HIGH] admintools:import from the CLI failed with a fatal error on any file admintools:export had produced
Fixed [HIGH] Emergency Off-Line Mode enabled from the CLI reported success but left the site fully accessible
Fixed [HIGH] Users were never deactivated after too many failed logins, whatever the threshold
Fixed [HIGH] Delete Inactive Users scheduled task always failed; its User Group filter also selected the wrong groups
Fixed [HIGH] PHP File Change Scanner: Mark All Safe ignored every alert with a zero threat score
Fixed [HIGH] PHP File Change Scanner: marking a file safe only worked from the most recent scan's report
Fixed [HIGH] Temporary Super Users: a past expiration date created a permanent, untracked Super User
Fixed [HIGH] Admin Tools' actions were not recorded in the Action Log on sites without Akeeba Backup installed
Fixed [HIGH] Admin Password validation accepted characters outside the allowed set
Fixed [HIGH] DFI Shield did not detect NUL bytes in the request
Fixed [HIGH] Bad Words containing a "#" character never blocked anything
Fixed [MEDIUM] Server configuration makers: exceptions for file / folder names with backslashes were generated wrong
Fixed [MEDIUM] Scheduled tasks: PHP File Change Scanner could give itself an unrealistic one second time limit
Fixed [MEDIUM] Scheduled tasks: Auto Import with invalid URL failed on every run, instead of doing nothing
Fixed [MEDIUM] Emergency Off-Line Mode sent visitors to a broken address
Fixed [MEDIUM] Notification emails were sent in the current site language instead of a predictable one
Fixed [MEDIUM] The email telling you a user account was reactivated after failed logins was never actually sent
Fixed [MEDIUM] PHP File Change Scanner: third party API application files, under api/components, were reported as Non-core
Fixed [MEDIUM] Possible fatal error on future Joomla versions which have removed CMSObject
Fixed [MEDIUM] Third party integration event onAdminToolsThirdpartyException wasn't handled
Fixed [MEDIUM] Third party integration: fatal error when blocked request's extra information was passed as an array
Fixed [MEDIUM] PHP File Change Scanner: internal warnings queue ignored its size limit and grew unbounded
Fixed [MEDIUM] WAF Exceptions and WAF Deny List: filtering the list by two or more columns at once returned the wrong rows
Fixed [MEDIUM] Server configuration makers: exception files list could be corrupted when upgrading
Fixed [MEDIUM] NginX Conf Maker and web.config Maker used .htaccess Maker's list for "Restrict access by IP"
Fixed [MEDIUM] Link Migration would rewrite rewrite look-alike domains such as example.com.evil.net
Fixed [MEDIUM] Folder path validation checked the administrator folder instead of the site folder
Fixed [MEDIUM] IP allow/disallow lists accepted invalid IP values, matching nothing
Fixed [MEDIUM] Quick Setup Wizard generated wrong site-relative paths on sites whose path ends in /api
Fixed [LOW] DFI Shield never detected Windows drive-letter paths such as “C:\Windows\system.ini”
Fixed [LOW] CLI commands displayed relative times in the wrong unit, e.g. "24 hours" instead of "1 day"
Fixed [LOW] Legacy Clean Temporary Files feature logged PHP warning on every pass
Fixed [LOW] Legacy Clean Temporary Files feature hang the page until whole temp directory was cleaned
Fixed [LOW] web.config Maker: blocking access to common server configuration files could also block unrelated files
Fixed [LOW] Configure WAF: Forgotten Users Lockout heading used outdated wording
Decryption key:


Akeeba Admin Tools PRO - Joomla site security component v7.9.1
= Admin Tools 7.9.1
  • Added PHP File Change Scanner: the scan report's Export CSV button is now a split button with two new options, Export Filtered CSV and Export Paths
  • Changed PHP File Change Scanner: the CSV export of a scan report now also includes the Type and Threat Score columns
  • Changed Workaround for Joomla erroneously reporting our database tables as out of date
  • Fixed [MEDIUM] PHP File Change Scanner: Non-core files were only reported by the scan which first saw them; they are now reported by every scan for as long as they exist on the site, unless they are Marked Safe. Test case NonCorePersistence.
  • Fixed [MEDIUM] PHP File Change Scanner: when the CoreSums checksum data could not be downloaded, Joomla's own files under includes/, administrator/includes/ and administrator/help/ were reported as Non-core
  • Fixed [LOW] PHP File Change Scanner: files under administrator/manifests were reported as Non-core, even though Joomla places them there itself when installing package, file, and library extensions
  • Fixed [LOW] PHP File Change Scanner: the CSV export of a scan report only exported the page of results currently displayed, and silently applied the filters left over in the session
  • Fixed [LOW] PHP File Change Scanner: the CSV export of a scan report escaped double quotes with a backslash instead of doubling them, per RFC 4180
Decryption key:


Akeeba Admin Tools PRO - Joomla site security component v7.8.7
No changelogs found!
Decryption key:


Akeeba Admin Tools PRO - Joomla site security component v7.8.3
- Security tightening .htaccess (Apache), nginx.conf (NginX) and web.config (IIS) file generator with a simple yet powerful user interface
- Restrict administrator with a secret URL parameter
- Web Application Firewall to block common exploits (SQL injection, XSS, DFI, RFI, malicious user agent, CSRF/spam-bot protection, uploads scanner etc)
- Bad word filtering
- IP Whitelisting for the administrator section
- IP Blacklisting
- Geographic block (deny access to specific countries/continents)
- Modification of Generator meta tag and other sensitive HTTP headers
- Email on administrator login
- Block front-end Super Administrator log-in
- Block Super Administrator user modification
- Block extensions installation
- Block visual fingerprinting (tmpl, template and tp URL parameters)
- Integration of the Bad Behavior anti-spam library
- Project Honeypot IP blacklist integration
- Automatic IP blocking of repeat offenders
- Email notifications of all detected security issues
- URL redirections (exclusive support for query parameters!)
- Scheduled site maintenance operations
Decryption key:


Akeeba Admin Tools PRO - Joomla site security component v7.8.1

Bug fixes​

  • [LOW] "Warn about use of well-known passwords" will throw a PHP error if the user groups for the feature have not been set
  • [LOW] Custom block page should never be triggered in the backend of the site
  • [LOW] Limit for disabled obsolete admins check was too low in the interface
  • [MEDIUM] Cannot mark a file safe from the Examine File page

Miscellaneous changes​

  • No longer report Joomla API application's NotAcceptable exception by email.
  • Preliminary support for Joomla 6
  • Like
Reactions: wesleyesaf

About us

  • Babiato Forum - The webmaster community has been around for many years and pride ourselves on offering unbiased, critical discussion among people of all different backgrounds. We are working every day, updating Daily resource to make sure our community is one of the best.

Quick Navigation

User Menu