User Feedback
OcBox Antihack — every OpenCart attack-protection method rolled into one free module
This is a free Community Edition module. We gathered in one place every software tool and method for protecting an OpenCart store from attacks — WAF, virus and shell scanner, IP blocking, admin panel protection, traffic monitoring, Cloudflare integration. Instead of a dozen scattered rules in .htaccess and paid subscriptions — one module that installs in a few minutes.
The module is currently in open beta. That means: grab it, install it, test it on your store and send us feedback — everything you find, we will fix in the next versions. The module is not part of the paid OcBox build — it is a standalone free gift to the community. Download it, use it, share your impressions.
What you get — in detail
Below are all the protection layers the module adds to your store. Each one is turned on separately, so you decide how tight to make the screws.
WAF — blocks attacks right at the entrance, before they reach the engine
✓ Web application firewall on every request
The module inspects every incoming request for known attack patterns: SQL injections, XSS (attempts to inject <script>, iframe, svg payloads), directory traversal (../../etc/passwd), remote code execution (eval, system, shell_exec), shell command injections. A suspicious request is blocked before OpenCart even starts processing it.
⚠ Without this: plain OpenCart hands any request straight to the controller — one unpatched vulnerability in a third-party module, and the attacker is already running code on your server.
Auto IP blocking — whoever hammers the door locks themselves out
✓ Temporary and permanent IP blocking
After several WAF triggers or failed login attempts the IP is automatically banned — for a set period or permanently. The blocked list is visible in the admin panel, and any address can be unbanned manually from there. Ban duration and trigger threshold are configurable.
⚠ Without this: a bot brute-forces passwords and vulnerabilities for hours from a single address — and nothing stops it.
Virus and web shell scanner — finds what already slipped through
✓ Malicious code search across store files
The scanner walks through your files looking for signatures of known web shells (c99, r57, b374k, WSO, FilesMan and others), backdoor code, obfuscation (base64_decode, gzinflate, str_rot13, hex sequences), eval from $_GET/$_POST, PHP disguised as an image. Findings are shown as a list with a danger level. Runs manually or daily on a schedule.
⚠ Without this: an uploaded shell sits in a folder for months quietly leaking orders and databases — you find out from your host or your customers.
Admin panel protection — a secret token in the login URL
✓ Hidden admin login behind a token
The admin panel only opens through a special token-protected link — every attempt to reach the standard /admin without it is cut off. This shields the store from automated password brute-forcing, because the bot simply does not see the login form.
⚠ Without this: the admin URL is public knowledge and gets pounded with password dictionaries around the clock.
Traffic monitoring — see the spike before it takes the site down
✓ Request counter with baseline and status
The module counts requests per minute and per hour, keeps a baseline and shows a traffic status. An abnormal spike (bot swarm, DDoS attempt) is visible on the panel instantly — not once the store has already gone down.
⚠ Without this: the first sign of an attack is a customer telling you the site does not open.
IP allow list — your own always get through
✓ Trusted addresses outside the rules
Your office, the developer’s address, payment gateway or delivery service IPs — anything that must always pass through goes on the allow list and is never blocked, even if it accidentally trips a rule.
⚠ Without this: a firewall tuned too tight risks blocking you or a critical service.
Access tokens — protection for CRON and utility URLs
✓ Utility URLs open only with a token
CRON jobs, utility and admin routes are shielded by access tokens — a random visitor or bot cannot hit an important endpoint directly.
⚠ Without this: an open CRON URL is a button anyone can press.
Cloudflare integration — a ban at the network edge, not just the site
✓ Sync bans with Cloudflare
If the store sits behind Cloudflare, the module helps configure real-IP passthrough (mod_remoteip) and works together with the CF firewall — the attack is cut off at the network edge before it ever reaches your server.
⚠ Without this: behind Cloudflare without a proper mod_remoteip you see and ban the same proxy IP instead of the real attacker.
nginx / .htaccess editor — hardening without digging in configs by hand
✓ Ready-made server hardening rules
The module suggests and helps add rules to .htaccess (Apache) or the nginx config: forbid PHP execution inside upload folders, close utility files, mod_remoteip for Cloudflare. The install steps are spelled out right in the interface.
⚠ Without this: an image/ or download/ folder with PHP allowed is a classic path for launching an uploaded shell.
Event log — every repelled attack is on record
✓ Log of every protection trigger
Each block is recorded: IP, reason, attack type, danger level, time. You can see where and how they hit you, and judge whether your rules are tuned right.
⚠ Without this: you have no idea you were attacked, or how — until it is too late.
CRON automation — protection runs on its own
✓ Daily scanning, traffic baseline, auto-cleanup
On a schedule the module scans files for viruses (daily), updates the normal-traffic baseline (hourly) and clears out old records. Set CRON up once — and protection lives its own life.
⚠ Without this: a one-off scan does nothing — a shell gets uploaded after you have already checked.
What this means in plain terms
Previously, to protect OpenCart you had to hand-pick rules from a dozen forum threads, dig into .htaccess, install a scanner separately, worry about brute-force and Cloudflare on the side. OcBox Antihack pulls all those tools into a single admin panel: WAF, scanner, blocking, monitoring, hardening — everything in one place, tick the checkboxes you need and forget it.
Who this module is for
For any OpenCart or ocStore shop that has ever seen password brute-forcing in the logs, SQL injection attempts, or strange PHP files in folders. Especially — for stores without a dedicated security administrator, where protection has to work out of the box and by itself.
Compatibility
The module targets the 3.x branch — OpenCart 3.0 and ocStore 3.0. There is no OpenCart 2.x version yet. Works on Apache (.htaccess) and on nginx. Cloudflare integration included.
The module is in open beta — and it is free.
Install it on your store, test it, break it, find its weak spots — and post to us in the support topic. Every piece of feedback goes into work, every report of a false trigger or a missed attack makes the module better for the whole community. This is our contribution to the security of the Ukrainian OpenCart market, and it will always stay free.
File delivery rules
The module is free and delivered immediately after download from this page. No keys or activation are required — unpack it, upload upload/ to the store root, refresh modifications in the admin panel and turn on the protection layers you need.
Recommended paid OcBox modules
![]() Smart Related $30 — related products |
SEO FAQ AI $30 — AI FAQ + Schema.org |
AI Product Editor $40 — bulk editing |
![]() Image Pro $15 — WebP, watermark (beta) |
We recommend templates by 29aleksey
Works best with fast templates. 29aleksey makes top-tier OpenCart 2.3/3.0 templates focused on speed and out-of-the-box optimisation:
![]() Prime |
![]() UpStore |
![]() CyberStore |
![]() Chameleon |
![]() LuxShop |
![]() NewStore |
Характеристики
-
Recently Browsing 0 members
- No registered users viewing this page.







