Download the PHP package one4vision/t3lockdown without Composer

On this page you can find all versions of the php package one4vision/t3lockdown. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package t3lockdown

TYPO3 extension t3lockdown

Total downloads TYPO3 extension Stability TYPO3 versions Latest version

T3LockDown protects TYPO3 installations against suspicious requests such as SQL injection, cross-site scripting, and malicious header payloads by inspecting incoming requests before they reach application logic. The extension can log attacks to the database, send alert emails, rate-limit abusive traffic, and temporarily block IP addresses after repeated attack attempts.

Purpose

The extension is intended for administrators who want an additional request-level protection layer in TYPO3. It focuses on practical mitigation: detect suspicious payloads, record what happened, alert administrators, and optionally enforce temporary IP blocking when a threshold is reached.

Installation

Install the extension with Composer in the TYPO3 project and activate it in the TYPO3 backend. TYPO3 extension configuration is managed through ext_conf_template.txt, and the saved values are stored in TYPO3 system settings for runtime use.

After installation, open the TYPO3 backend and configure the extension in Admin Tools > Settings > Extension Configuration.

Configuration areas

The extension configuration is grouped into several administrator-friendly sections in ext_conf_template.txt.

Area Purpose
Detection Enables SQL injection, XSS, header, and cookie inspection.
Blocking Controls whether repeated attacks should lead to temporary IP blocking and defines thresholds.
Notifications Defines whether alert emails are sent and which sender/recipient addresses are used.
Rate limiting Limits repeated requests inside a configurable time window.
Header inspection Defines allowed header exceptions and headers that should be skipped during inspection.
Lists Maintains blacklists, whitelists, and URL whitelists.

Key settings

Detection

Blocking

Notifications

If mailFrom is empty, the extension should fall back to TYPO3's global MAIL.defaultMailFromAddress.
If mailFromName is empty, it should fall back to MAIL.defaultMailFromName, and finally to T3LockDown as a last-resort display name.

Rate limiting

Header inspection

Lists

Email behavior

The extension uses TYPO3's Mail API for sending alert emails. A practical fallback strategy for sender data is:

  1. Use the sender address and name defined in T3LockDown.
  2. Fall back to TYPO3 global mail defaults.
  3. Use T3LockDown as final sender name if no global name is defined.

Administrators should ensure that TYPO3 global mail transport is configured correctly; otherwise alert delivery may fail even when the extension configuration is valid.

Logging and response behavior

When a request is identified as malicious, the extension can log details such as request method, URL, IP address, matched rules, and additional request context into the database. A blocked request should return a visible HTTP 403 response with a human-readable message instead of an empty response body, which improves both user feedback and operational debugging.

TYPO3 backend module

The extension also provides a TYPO3 backend module for administrators to review logged attacks centrally. This module can be used to inspect recorded attack entries, review request details, identify attack types such as SQL injection, XSS, and header attacks, and monitor activity over time through aggregated backend views.

The backend module is especially useful for operational monitoring because it complements email alerts with a persistent analysis interface inside TYPO3. It gives administrators direct access to logged request data such as timestamps, methods, IP addresses, request URIs, user agents, and attack classifications without requiring direct database access.

Recommended defaults

The following baseline is suitable for most productive installations.

Setting Recommended value
checkSqlInjAttacks 1
checkXss 1
checkHeaders 1
logAttacksInDB 1
blockRequests 1
sendMailEveryRequest 1
sendBlockMail 1
rateLimitingEnabled 1
ignoreHeaderStringParsing empty
allowedHeaderExceptions force-revalidate only if this is known to prevent real false positives

Configuration example

An example extension configuration could look like this:


All versions of t3lockdown with dependencies

PHP Build Version
Package Version
Requires typo3/cms-core Version ^13.4 || ^14.3
php Version >=8.2 <8.5
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package one4vision/t3lockdown contains the following files

Loading the files please wait ...