Jump to content
Search In
  • More options...
Find results that contain...
Find results in...

OcBox Antihack — every OpenCart attack-protection method in one free module (Community Edition, beta)

OcBox ★★★★★ 2 reviews 181 завантажень 1,347 08/13/2026
1.7.0 Ioncube Loader: Ні
Безкоштовно
OpenCart3.0, 2.3, 2.2, 2.1, 2.0
ocStore3.0, 2.3.0.2.4, 2.3, 2.2, 2.1
License type
Activation methodБез активації
Ioncube LoaderНі
Get request to server of developerНі
Downloads181
Submitted07/22/2026
Updated08/13/2026
File Size313.08 kB

User Feedback

OcBox Antihack — every OpenCart attack-protection method rolled into one free module

This is a free Community Edition module. We gathered in one place every software tool and method for protecting an OpenCart store from attacks — WAF, virus and shell scanner, IP blocking, admin panel protection, traffic monitoring, Cloudflare integration. Instead of a dozen scattered rules in .htaccess and paid subscriptions — one module that installs in a few minutes.

The module is currently in open beta. That means: grab it, install it, test it on your store and send us feedback — everything you find, we will fix in the next versions. The module is not part of the paid OcBox build — it is a standalone free gift to the community. Download it, use it, share your impressions.

What you get — in detail

Below are all the protection layers the module adds to your store. Each one is turned on separately, so you decide how tight to make the screws.

WAF — blocks attacks right at the entrance, before they reach the engine

✓ Web application firewall on every request
The module inspects every incoming request for known attack patterns: SQL injections, XSS (attempts to inject <script>, iframe, svg payloads), directory traversal (../../etc/passwd), remote code execution (eval, system, shell_exec), shell command injections. A suspicious request is blocked before OpenCart even starts processing it.
⚠ Without this: plain OpenCart hands any request straight to the controller — one unpatched vulnerability in a third-party module, and the attacker is already running code on your server.

Auto IP blocking — whoever hammers the door locks themselves out

✓ Temporary and permanent IP blocking
After several WAF triggers or failed login attempts the IP is automatically banned — for a set period or permanently. The blocked list is visible in the admin panel, and any address can be unbanned manually from there. Ban duration and trigger threshold are configurable.
⚠ Without this: a bot brute-forces passwords and vulnerabilities for hours from a single address — and nothing stops it.

Virus and web shell scanner — finds what already slipped through

✓ Malicious code search across store files
The scanner walks through your files looking for signatures of known web shells (c99, r57, b374k, WSO, FilesMan and others), backdoor code, obfuscation (base64_decode, gzinflate, str_rot13, hex sequences), eval from $_GET/$_POST, PHP disguised as an image. Findings are shown as a list with a danger level. Runs manually or daily on a schedule.
⚠ Without this: an uploaded shell sits in a folder for months quietly leaking orders and databases — you find out from your host or your customers.

Admin panel protection — a secret token in the login URL

✓ Hidden admin login behind a token
The admin panel only opens through a special token-protected link — every attempt to reach the standard /admin without it is cut off. This shields the store from automated password brute-forcing, because the bot simply does not see the login form.
⚠ Without this: the admin URL is public knowledge and gets pounded with password dictionaries around the clock.

Traffic monitoring — see the spike before it takes the site down

✓ Request counter with baseline and status
The module counts requests per minute and per hour, keeps a baseline and shows a traffic status. An abnormal spike (bot swarm, DDoS attempt) is visible on the panel instantly — not once the store has already gone down.
⚠ Without this: the first sign of an attack is a customer telling you the site does not open.

IP allow list — your own always get through

✓ Trusted addresses outside the rules
Your office, the developer’s address, payment gateway or delivery service IPs — anything that must always pass through goes on the allow list and is never blocked, even if it accidentally trips a rule.
⚠ Without this: a firewall tuned too tight risks blocking you or a critical service.

Access tokens — protection for CRON and utility URLs

✓ Utility URLs open only with a token
CRON jobs, utility and admin routes are shielded by access tokens — a random visitor or bot cannot hit an important endpoint directly.
⚠ Without this: an open CRON URL is a button anyone can press.

Cloudflare integration — a ban at the network edge, not just the site

✓ Sync bans with Cloudflare
If the store sits behind Cloudflare, the module helps configure real-IP passthrough (mod_remoteip) and works together with the CF firewall — the attack is cut off at the network edge before it ever reaches your server.
⚠ Without this: behind Cloudflare without a proper mod_remoteip you see and ban the same proxy IP instead of the real attacker.

nginx / .htaccess editor — hardening without digging in configs by hand

✓ Ready-made server hardening rules
The module suggests and helps add rules to .htaccess (Apache) or the nginx config: forbid PHP execution inside upload folders, close utility files, mod_remoteip for Cloudflare. The install steps are spelled out right in the interface.
⚠ Without this: an image/ or download/ folder with PHP allowed is a classic path for launching an uploaded shell.

Event log — every repelled attack is on record

✓ Log of every protection trigger
Each block is recorded: IP, reason, attack type, danger level, time. You can see where and how they hit you, and judge whether your rules are tuned right.
⚠ Without this: you have no idea you were attacked, or how — until it is too late.

CRON automation — protection runs on its own

✓ Daily scanning, traffic baseline, auto-cleanup
On a schedule the module scans files for viruses (daily), updates the normal-traffic baseline (hourly) and clears out old records. Set CRON up once — and protection lives its own life.
⚠ Without this: a one-off scan does nothing — a shell gets uploaded after you have already checked.

What this means in plain terms

Previously, to protect OpenCart you had to hand-pick rules from a dozen forum threads, dig into .htaccess, install a scanner separately, worry about brute-force and Cloudflare on the side. OcBox Antihack pulls all those tools into a single admin panel: WAF, scanner, blocking, monitoring, hardening — everything in one place, tick the checkboxes you need and forget it.

Who this module is for

For any OpenCart or ocStore shop that has ever seen password brute-forcing in the logs, SQL injection attempts, or strange PHP files in folders. Especially — for stores without a dedicated security administrator, where protection has to work out of the box and by itself.

Compatibility

The module targets the 3.x branch — OpenCart 3.0 and ocStore 3.0. There is no OpenCart 2.x version yet. Works on Apache (.htaccess) and on nginx. Cloudflare integration included.

The module is in open beta — and it is free.

Install it on your store, test it, break it, find its weak spots — and post to us in the support topic. Every piece of feedback goes into work, every report of a false trigger or a missed attack makes the module better for the whole community. This is our contribution to the security of the Ukrainian OpenCart market, and it will always stay free.

File delivery rules

The module is free and delivered immediately after download from this page. No keys or activation are required — unpack it, upload upload/ to the store root, refresh modifications in the admin panel and turn on the protection layers you need.

Recommended paid OcBox modules

Smart Related
Smart Related
$30 — related products
SEO FAQ AI
SEO FAQ AI
$30 — AI FAQ + Schema.org
AI Product Editor
AI Product Editor
$40 — bulk editing
Image Pro
Image Pro
$15 — WebP, watermark (beta)

We recommend templates by 29aleksey

Works best with fast templates. 29aleksey makes top-tier OpenCart 2.3/3.0 templates focused on speed and out-of-the-box optimisation:

Prime
Prime
UpStore
UpStore
CyberStore
CyberStore
Chameleon
Chameleon
LuxShop
LuxShop
NewStore
NewStore

Характеристики

System requirementsPHP 7.0+, MySQL 5.6+, Apache/nginx
Activation methodБез активації
Ioncube LoaderНі
OpenCart3.0, 2.3, 2.2, 2.1, 2.0
ocStore3.0, 2.3.0.2.4, 2.3, 2.2, 2.1
OpenCart.Pro, ocShopНе проверялось
Get request to server of developerНі
If the developer server is unavailableДополнение работает
СкидкаNo
Template compatibleDefault, Journal3, Cyberstore, Luxshop, Unishop, Cameleon, Upstore, OctDeals
AdaptationПлатна
LocalisationУкраїнська, Англійська, Російська
Версія1.7.0
File Size313.08 kB
Submitted07/22/2026
Updated08/13/2026

OcBox's Other Downloads


  • Recently Browsing   0 members

    • No registered users viewing this page.
Guest
×
  • Create New...

Important Information

On our site, cookies are used and personal data is processed to improve the user interface. To find out what and what personal data we are processing, please go to the link. If you click "I agree," it means that you understand and accept all the conditions specified in this Privacy Notice.