Select your language

Extensions

AdminExile

Free v5.1.4 J4–J6 4

A system plugin that hides the Joomla administrator login: the /administrator form opens only via a URL carrying a secret key, and other requests go to the home page, a 404 or another URL.

AdminExile is a system plugin by Michael Richey that keeps strangers away from the Joomla administrator login. Without protection, any bot can load /administrator and start guessing passwords. With the plugin enabled, the login form is served only when the address contains a secret key; everything else is sent wherever the administrator decides. It suits any site whose backend is reachable from the internet.

Version 5 is a complete rewrite on modern Joomla internals. The author dropped brute force detection, frontend blocking and link-based recovery, recommending that password guessing be handled at server level, for example with Fail2Ban.

Features

  • Access to /administrator only with a key in the query string (?key) or a key=value pair.
  • Requests without the key can be redirected to the home page, answered with a 404 or sent to any custom address.
  • No backend session cookie is issued until the key is supplied.
  • A re-entry window after logging out of the backend.
  • Logging of failed attempts, while the attacker gets no hint about why access was refused.
  • IPv4 and IPv6 allow and block lists with CIDR ranges.

Compatibility

Joomla 4, 5 and 6 (JED also lists Joomla 3). Current version 5.1.4, last updated in JED on 27 October 2025. The plugin is free, and the author states plainly that there will never be a Pro edition.

Similar

More from Michael Richey

AdminExile
Download
Version
v5.1.4
Compatibility
J4–J6
Updated
2026-09-24
Views
4