Trader Information
Back to topOverview
Back to topminiOrange Credential Guard extension for Magento enables store owners, merchants, and security teams to protect admin accounts for Magento against the single most common cause of account takeover: reused and previously breached passwords.
Instead of relying on password complexity rules alone, the extension checks admin passwords against a global database of known leaked credentials at three critical checkpoints: account creation, login, and forgot/reset password. Each checkpoint can be enabled or disabled independently from the Credential Guard settings, so you decide exactly where breach checks run in your store.
All checks are performed in a fully privacy preserving way. The extension integrates with the HaveIBeenPwned (HIBP) Pwned Passwords API using the k-Anonymity model, which means the plaintext password and even its full hash is never transmitted to any third-party service. The password is hashed locally on your Magento server, only the first five characters of that hash are sent to the HIBP API over HTTPS, and the comparison happens entirely on your own server.
For every checkpoint, you choose how Credential Guard responds when a breached password is detected. In Block mode, the compromised password is rejected outright for example, at admin account creation the save fails and the user sees a clear, fully customizable error message prompting them to choose a stronger, uncompromised password. This keeps breached credentials out of your store from the very first moment an account is created.
In Warn mode, detection happens without disrupting access. When a breached password is detected after a successful admin login, the account is flagged and the admin sees a customizable warning banner directly on their dashboard asking them to reset their password. A configurable grace period defined by the maximum number of logins and the maximum number of days before a mandatory reset gives users a fair window to update their password on their own before a reset is enforced. This means accounts created before installation are progressively protected over time, without breaking the login experience.
The Forgot / reset password checkpoint closes the loop by checking passwords against known data breaches whenever an admin resets their password \ so a compromised credential can never be reintroduced through the reset flow.
Everything detection produces is visible and actionable from the admin panel. The User Management dashboard lists every flagged account along with the account type, email, the event that triggered the flag, the reason, the flagged date, and the remaining grace status. From the same screen you can Force Reset a password immediately, Clear the flag, or apply bulk actions across multiple accounts.
Whether you operate a high-value store or simply want to meet modern security expectations and reduce your exposure to credential-stuffing attacks, this extension provides a structured and reliable credential-protection layer for your Magento store.
Account & Pricing
You do not need to create an account or register with miniOrange to use our free version.
If you face any issues while setting up this extension, please contact us at magentosupport@xecurify.com
To use the extension's premium features, you can upgrade to our premium plans. You can check the features and pricing for the Premium versions.
Features
- Checks admin passwords against known data breaches at three checkpoints — account creation, login, and forgot/reset password
- Privacy preserving checks using the HaveIBeenPwned (HIBP) Pwned Passwords API with k-Anonymity, plaintext passwords never leave your server
- Enable or disable breach checks independently at each checkpoint
- Configurable response per checkpoint. Block the compromised password or warn the user
- Fully customizable error and warning messages shown to users.
- Configurable grace period:- set the maximum logins and maximum days before a mandatory password reset
- In-dashboard warning banner prompting flagged admins to reset their password
- Flagged Accounts dashboard showing account type, email, event, reason, flagged date, and remaining grace status
- One-click Force Reset and Clear Flag actions, with bulk actions for multiple accounts
- Audit logs recording every breach. Check event with result and message
- Enable/disable, clear, and download logs anytime from the Reports section
- No API key required for HIBP password checks — works out of the box
- Progressive protection of pre-existing admin accounts through login-time checks
- Reduced exposure to account takeover and credential-stuffing attacks
Custom feature requirements
If you want any custom changes or features in this extension, let us know your requirement on magentosupport@xecurify.com and we will add that feature in the extension for you.
Dependencies
NONE
24/7 Support
In case you face any issues or if you have any questions, please feel free to reach out to us on our 24*7 active support at magentosupport@xecurify.com or Contact us.
Website
Check out our website for other extensions or visit https://plugins.miniorange.com/magento to see all our listed extensions for Magento. For more support or info email us at magentosupport@xecurify.com. You can also submit your query from the extension's configuration page.
Technical Specifications
Back to topSeller profile
Seller contact
Current Version
1.0.0
Adobe Commerce platform compatibility
Adobe Commerce (cloud): 2.4 (current)
Adobe Commerce (on-prem): 2.4 (current)
Magento Open Source: 2.4 (current)
Type
Stable Build
Updated
20 July, 2026
Categories
Extensions, Content & Customizations, Personalization & Experience Management
Documentation
License Type
GNU General Public License 3.0 (GPL-3.0)
Policy
Quality Report
Back to topAll tests were conducted on the latest versions of Adobe Commerce that existed for the compatible release lines at the moment of the extension submission. Latest versions of all other software were used, as applicable.
Release Notes
Back to top1.0.0:
- Compatible with Adobe Commerce (cloud) : 2.4
- Compatible with Adobe Commerce (on-prem) : 2.4
- Compatible with Magento Open Source : 2.4
- Stability: Stable Build
-
Description:
- Initial Release
- Compatibility with Magento 2.4.9 & PHP 8.5
Support
Back to topThe best place to start if you need help with a specific extension is to contact the developer. All Adobe Commerce developers have both a contact email and a support email listed.
Contact Vendor