Extensions Directory
Extensions are installable packages which give CiviCRM new functionality, and this directory provides a centralized list of extensions which the CiviCRM community has created. This listing displays CiviCRM extensions that work on all Content Management Systems (CMS).
The newest extensions · Create an extension · Add an extension to this directory
This implements a simple firewall for CiviCRM that blocks by IP address in various scenarios.
Provides a hotfix for the vulnerabilities (CIVI-SA-2026-35, CIVI-SA-2026-37) published on 5 August 2026.
Makes the permission flag on a contact's relationship work as a true ACL.
Adds the ACLS that allow a contact to only see contacts and groups associated with the domain.
Restrict users from viewing/editing contributions and other entities based on permission of financial types.
Allows permissions to be set by user role to add, view, edit and delete Activities. If a logged-in user has a role that provides permission for a specific activity type, then they are authorized to do it for all activities of that type.
Hierarchical ACL - Add ACL based on a Relationships Hierarchical Structure
Allows you to choose a set of groups which will be added to new contacts if the logged in contact is also in that group.
This extension fixes and fills some gaps for Groups (Static and Smart) in CiviCRM, when limited users with dynamic ACL list available groups
Provide single sign-on for CiviCRM using OAuth/OpenID Connect. Either Keycloak or Google are supported out of the box.
CiviVerify is a generic CiviCRM extension for issuing and redeeming single-use, time-limited verification links. A verification may refer to a contact, any APIv4 entity, or—when explicitly allowed—no entity at all. The extension never performs domain-specific follow-up work; consumers use its optional native CiviRules triggers or subscribe to its Symfony events.
This CiviCRM extension modifies the API permissions to allow it to be called with just the "Access AJAX API" permission instead of requiring the more restrictive default permissions. This extension modifies permissions on the following:
- ContributionRecur::getActions
- Contact::getActions
- Membership::getActions
- Membership::get
- Membership::getFields
- Membership::getLinks
Making these changes allows this data to utilized frontend-facing Formbuilder search displays.
- ContributionRecur::getActions
- Contact::getActions
- Membership::getActions
- Membership::get
- Membership::getFields
- Membership::getLinks
Making these changes allows this data to utilized frontend-facing Formbuilder search displays.
Selected activity types are privacy protected, e.g. for "counseling" type activities. Similar to Activity Type ACL, but provides a single, larger set of permissions that applies to all selected private activity types.
