🌟 VistoShield
Joomla Edition

Security for Joomla 3, 4 and 5 — built especially for the older sites running paid frameworks that can't be safely upgraded. A Web Application Firewall virtual-patches the exploits that hit these sites on repeat, and self-healing hardening keeps any dropped shell inert. Managed from one EU-hosted cloud dashboard.

Joomla 3.9+ / 4.x / 5.x • PHP 7.1+ • One-line SSH install, no admin login needed.

✅ Logged-in administrators are never blocked — the WAF targets unauthenticated exploit traffic only. Connect to the Cloud Dashboard for centralized management.

Why EOL Joomla Sites Keep Getting Hit

Thousands of production Joomla sites run end-of-life Joomla with paid template frameworks and editors — SP Page Builder, Astroid, Helix3, and the JCE editor. Each of those versions has a known unauthenticated file-upload vulnerability. Upgrading breaks the paid layout (or forces buying a new licence), so the sites stay vulnerable, and automated bots hit them on rotation — switching vector every time the last one is closed. VistoShield closes all of these vectors at once, centrally, without touching the framework.

Six Layers of Joomla Protection

The permanent hardening we used to apply by hand — now managed centrally, per site, and self-healing.

🛡️

WAF Virtual Patching

Blocks the four recurring unauthenticated upload exploits before they reach the vulnerable code — JCE editor, SP Page Builder (asset/icon upload), Astroid media upload, and Helix3 com_ajax upload.

  • Runs before component dispatch (onAfterInitialise)
  • Guests only — legitimate admin and editor use is untouched
  • Blocked requests return 403 and raise a real-time event
🔒

Self-Healing Hardening

Writes and maintains .htaccess sentinels in every web-writable folder so a dropped shell.php or shell.php.json can never execute — the layer a WAF alone can't cover, since a direct hit to a dropped file never routes through Joomla.

  • images, tmp, cache, media, logs, templates, admin caches, demo folders
  • Re-verified daily — self-heals if an attacker or redeploy removes it
  • Preserves any existing rules; reports folders it can't write
🧿

Double-Extension Blocking

Rejects requests for disguised shells like bob_x.php.json or hx3_a.phar.json anywhere on the site, and denies their execution on disk — without affecting your real index.php.

  • Covers php, phtml, phar, pht, phps behind a second extension
  • Request-level 403 plus a docroot on-disk guard
👤

Rogue Super-Admin Detection

Baselines your Super Users on first run and alerts on any new administrator — or usernames and emails that match known attacker patterns (cmsadmin##, contentmgr##, @secure.local).

  • Real-time event the moment a suspicious admin appears
  • Catches direct-SQL account inserts, not just UI-created ones
🔍

File-Integrity Monitoring

Sweeps writable folders for dropped shells — executable extensions, double extensions, or plain files that contain PHP — and flags them as critical findings so you can clean up and close the entry point.

  • Bounded scan — never runs away on large sites
  • Findings and events surface in the cloud dashboard
📋

Configuration Audit & Login Monitoring

Weekly audit of the Joomla and PHP versions, debug/error exposure, HTTPS enforcement, configuration.php permissions, and the default table prefix — plus failed-login and admin-login events streamed to the dashboard.

  • EOL Joomla and end-of-life PHP flagged with severity
  • Security score and history in one place

Install in Minutes — No Admin Login Required

Add the site in your dashboard to get its Site Key, then choose either method.

Option A — One-line SSH install (recommended for managed sites)

Run from the site's document root. The installer auto-detects Joomla, validates the key against the cloud, installs and enables the plugin, and sends the first heartbeat:

curl -s https://api.vistoshield.com/api/plugin/installer -o vistoshield-install.php
php vistoshield-install.php --key=YOUR_SITE_KEY
rm vistoshield-install.php

Option B — Install from the Joomla administrator

  1. Download the Joomla package.
  2. In the administrator, go to System → Install → Extensions and upload the ZIP.
  3. Open System → Manage → Plugins → System - VistoShield, paste your Site Key, set it to Enabled, and save.
Create a Free Account → All Download Options

Stop the Repeat Attacks on Your Joomla Sites

Central WAF virtual patching and self-healing hardening for every Joomla 3/4/5 site you manage — without touching the framework and without waiting for an upgrade that breaks the layout.

Free plan covers up to 3 sites • No credit card required