CSP SRI Lock
falconmedia/magento2-csp-sri-lock 45
Adds Subresource Integrity (SRI) hash enforcement to Content Security Policy headers, ensuring that external scripts and stylesheets have not been tampered with before execution.
Quality-tested Magento 2 modules. Explore. Evaluate. Elevate. #magento2
falconmedia/magento2-csp-sri-lock 45
Adds Subresource Integrity (SRI) hash enforcement to Content Security Policy headers, ensuring that external scripts and stylesheets have not been tampered with before execution.
utanvet-ellenor/connector-magento 50
Integrates Utanvet Ellenor risk assessment into Magento 2 checkout, filtering available payment methods based on risk scores and sending order outcome signals on status transitions.
Detects a visitor's country using GeoIP data. Provides a REST API and PHP interface to retrieve the country code, with fallback options.
takyoncommerce/module-umami 77
Integrates Umami, a privacy-focused open-source web analytics service, with your storefront for cookie-free visitor tracking.
Blocks customer registration with disposable and temporary email addresses by validating against a database of 90,000+ known throwaway domains. Supports custom blocklists and whitelists for fine-grained control.
Tracks admin actions — add, edit, delete, view, mass updates, and failed logins — recording user, IP, and changed fields, with the ability to revert modifications. Maintained fork of the archived KiwiCommerce module.
Intercepts the customer address file upload endpoint and returns a 403 Forbidden response, effectively disabling address file uploads for security hardening.
magestyapps/module-disable-2fa 40
Allows administrators to disable two-factor authentication for specific admin users. Provides both admin panel and command-line options for managing user 2FA status.
Looking for contributors - Help fix build issues
Detects and blocks suspicious IP addresses based on failed login attempts. Sends warning emails to store owners about potential security threats.
Looking for contributors - Help fix build issues
Enforces stronger admin password rules (forbidden words, upper/lowercase and special-character requirements) and automatically deactivates admin users who have not logged in for 90 days.
Looking for contributors - Help fix build issues
wubinworks/module-session-reaper-patch 60
Patches the CVE-2025-54236 (Session Reaper) account-takeover/RCE vulnerability as a universal Magento 2.3/2.4 extension, without using preferences so the store stays upgradable.
Prevents Magento orders from being placed based on configurable rules, with pluggable matchers for blocking by IP, email, or geolocation.
Looking for contributors - Help fix build issues