Admin IP Restriction (SISL fork)
Restrict Magento 2 admin access to allowlisted IPs. Requests from other IPs get 403 - a stolen password alone won't get in. Safe default (disabled). Runs on 2.4.9.
Admin credentials leak more often than you'd think. Admin IP Restriction adds a second layer: /admin is reachable only from IPs/ranges on your allowlist (CIDR supported); everything else gets 403, storefront untouched.
Part of the MageSpecialist Security Suite. Maintained fork of the abandoned msp/adminrestriction (even the latest Packagist release blocks PHP 8.4). Verified on Magento 2.4.9 / PHP 8.4. Safe default: disabled after install so it can't lock you out. Install via VCS + dev-main.