HTProtect.app DE Sign in
Multi-site management for Joomla security

Your entire fleet,
at a glance.
Uncompromisingly secure.

Monitor, update and scan many Joomla websites from one place - in bulk actions, and without ever handing over control of them.

Outbound-only · end-to-end signed · nothing runs without you.

Even a fully compromised dashboard server cannot hijack any of your websites.

The server holds no signing key and no site password. Remote commands are authorised by you alone - cryptographically, in your browser. That is what sets us apart from tools that store full access to every site.

Why HTProtect.app

Security built into the foundation - not bolted on as a feature.

Zero-trust control

Every command carries your Ed25519 signature. The website only runs what you have authorised - the server cannot forge anything.

Outbound-only

Your sites only ever connect outbound - no open port, no attack surface. Works behind any firewall and any CDN.

Security-native for Joomla

Not a generic WordPress tool. Vulnerability radar, core integrity, defacement and rogue-admin detection - straight from the HTProtect engine.

External monitoring

A 30-minute heartbeat from the outside. If a site goes down entirely, you see it - precisely when it can no longer report in itself.

Everything in one place

What you control for every website.

Control & trigger auto-updatesSet the policy per site, install pending updates with a single click.
Remote malware scansManually or on a schedule: every 3 days, weekly, monthly.
Fleet-wide vulnerability radar"3 sites are running a vulnerable com_xyz" → update every affected one.
Full-size site previewOn demand, the dashboard shows a current screenshot of every website - one click opens the enlarged lightbox view.
Outage detection from the outsideMore than two missed heartbeats → a problem, visible right away.
Core integrity & shield self-healingSpot injected code, keep protection rules current - all remotely.
1-click front end & back endStraight to the website or into the Joomla back end - one icon per row.
In three steps

From code to full control.

Pair

Click "Add website" in the dashboard, then enter the code in the Joomla back end. Done - no password, no port.

Monitor

Every site shows up as a traffic light: green, amber, red. Status, versions, pending updates, last scan - at a glance, on mobile too.

Take action

Trigger an update, a scan or a hardening run. Your browser signs the command, the website verifies it and executes. The server is only the messenger.

What you get out of it

Six moves that save you hours every week.

All of it is included in every plan - the free one too.

Your entire fleet at a glance

Every Joomla website in one view: green, amber, red. Pending updates, detected problems, last scan. You see where it hurts in seconds - instead of clicking through twenty back ends.

One click into the back end - password and all

HTProtect locks your /administrator behind an extra password. From the dashboard you still get in with a single click - nothing to type, and the protection never loosens for a moment.

Vulnerable extensions centrally under control

Which extension is vulnerable right now - and on which site? One list for the whole fleet. Automatic updates are yours to steer, per extension or across every website at once.

Core check in seconds, malware scan in a minute

One click compares every Joomla core file against the original (5 to 10 seconds) and searches the website for malicious code (30 to 60 seconds). Set it to weekly and both run on their own.

Backups that look after themselves

Full and database backups on your own schedule - compressed and easy on disk space. If something breaks, one click brings back the last clean state.

The safest dashboard of its kind

Sign in with a passkey, and every command carries your browser's signature - nobody can forge it, not even us. Bring your team in by invitation, with the rights each person needs.

Built for many sites

Not one website - your entire fleet, in one sweep.

From the second website on, every move counts. HTProtect is built from the ground up for managing many Joomla sites: bulk actions instead of single clicks, an overview instead of twenty open back ends - and a dashboard that stays fast while doing it.

Bulk actions across the whole fleet

Select, trigger once: updates, malware scans, core updates, backups, hardening or tags - for ten or a hundred websites at the same time, instead of site by site.

The right selection, instantly

Filtered views and a search bar show you exactly the sites that matter in one click - the vulnerable, outdated, offline or just-scanned ones. No scrolling through everything.

Onboard many at once

Whole client portfolios join in a batch: generate a package, hand out the install link - the sites pair themselves, with no logging into each single one.

Stays fast - no matter how many

Five websites or three hundred: the dashboard opens instantly and stays smooth. Built for speed and overview - not a list that gets slower with every site.

New · AI control

Your entire Joomla fleet - checked and maintained in plain language.

Connect Claude or ChatGPT to HTProtect: your AI assistant checks the security status of all your sites - and edits content only where you explicitly allow it.

At a glance: is everything green?

Just ask "show me the security status of all sites" - and you instantly see where everything is fine and where you should take a look.

Maintain content without logging in

Say "update the Pricing article on the club site" - and your assistant does it. A new category, a menu item or a module? One sentence is enough.

Connected in one click

Enter a single address, confirm once - done. No password, no key, nothing to copy or misplace.

Claude or ChatGPT - your choice

Both assistants work, with no detour. You decide which one you steer your sites with.

The AI may only do what you allow

  • The default is read-only. Your assistant can change something only once you explicitly enable it per site - time-limited and revocable at any moment.
  • AI access is deliberately kept weak and never has full administrator rights. Even a misused access would stay tightly limited - never a takeover of your site.
  • Instant off with one click: you revoke the entire access at any time, no detours.
  • Your credentials stay with you. Access is granted only in your own browser - our servers never get to see them.

Available for Claude (all plans, on desktop and in the browser) and ChatGPT (in the browser, paid plans, currently a beta feature) - for all websites on Joomla 4 and up.

Speaks your language

A dashboard that speaks your language.

Control it by voice, use it in English or German, get help in practically any language.

Watch the short demo

Speak, don't click

Steer the dashboard by microphone with spoken commands - recognised in 11+ languages. "Scan all sites", "show me the vulnerable ones" - HTProtect listens and acts.

Interface in English and German

The interface is crystal-clear in English or German - tidy, no jargon. You pick your language, the dashboard remembers it.

A forum in practically any language

The support forum understands practically any language: posts are translated automatically, and everyone reads and writes in their own.

And more

No surcharge, no add-on modules - already built in.

Debugging & rescue, remotelyTurn on debug mode and error reporting even when a site is already in an error state - and switch the compatibility plugin back on if disabling it has locked the site up. No detour through the database.
Auto-update rules, your wayOne rule for everything, override per site, and a grace period per extension before an update installs automatically.
A queue with an emergency brakeJobs run in order; whatever is still pending, you cancel or filter by type and site.
Update the Joomla core remotelyTriggered centrally, with a backup first and an automatic way back if something jams.
Back-end password protection, centrallySet or remove the extra password for /administrator across many sites at once.
A team with clear permissionsInvite colleagues and give each exactly the rights they need.
Enforce passkey-onlyOptionally require login by passkey alone, with recovery codes and an admin reset as a fallback.
Fully there on mobileEverything works on mobile too, with swipe gestures - plus an email the moment malicious code shows up anywhere.

If something ever slips through - we put it right.

If your website is ever hacked despite HTProtect, we clean it up - included, in every paid plan. Because behind HTProtect stands a real Joomla security and cleanup workshop, website-bereinigung.de - not an anonymous startup. The guarantee isn't a marketing promise - it's our craft.

The difference

Others store a master key. We don't.

The most modern, most complete dashboard for Joomla multi-site management - and the only one that needs no master key on the server to do it.

🗝️ Classic multi-site managers

  • Store full-access credentials for every website.
  • One server breach = access to the entire fleet.
  • Often need inbound connections / open endpoints.
  • Generic, WordPress-first - Joomla as an afterthought.
  • If a site gets hacked, you're on your own.

🛡️ HTProtect.app

  • No signing key, no site password on the server.
  • A server breach cannot hijack a single site.
  • Outbound-only - nothing has to be reachable from outside.
  • Security-native for Joomla, from the HTProtect engine.
  • Hacked? We clean it up - included. Nobody else offers that.

Ready to see your fleet?

Sign in and connect your first website in under a minute.

Go to dashboard →