What's new in v5.0.0
Secret administrator URL
The secret administrator URL (Pro, Site Protection) hides your backend login behind an address only you know. Strangers hitting plain /administrator get a blank, brand-free 404 — no MuRu fingerprint, nothing to probe further.
Setting it up
Enter a secret (or hit generate) and save. An amber banner shows the full URL with a copy button until you have demonstrably used it, dismissed it, or changed the secret. Arriving via the secret URL sets a session flag and strips the key from the address bar.
You cannot lock yourself out
Three safety nets: expired sessions fall through to Joomla's normal login page via an automatic marker cookie (instead of a dead-end 404); creating an empty ADMIN-SECRET-BYPASS.txt file in the extension's data folder via FTP reopens everything; and corrupt values fail open rather than denying the backend. Saving the secret never logs out your own session.
Joomla 3
Coming to the Joomla 3 edition with v3.0.0 (Shield gate with v2.2.0).
