Security Checklist ?

Discussion regarding Joomla! 5.x security issues.

Moderators: mandville, General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.
Windows Defender SmartScreen Issues <-- please read this if using Windows 10.
Post Reply
joomerguy
Joomla! Fledgling
Joomla! Fledgling
Posts: 3
Joined: Wed Mar 06, 2024 4:46 pm

Security Checklist ?

Post by joomerguy » Wed Mar 06, 2024 4:55 pm

Hello, Joomla People!

I am launching a Joomla 5 site soon. It is hosted with Scala Hosting. Presently in testing. I will likely launch multiple sites this year as well.

What essential security checks and precautions should I perform? I know some about web security and threats like XSS, DDoS (OWASP stuff) but I'm no expert. Are there anything particular to Joomla or CMS in general? Is there a checklist I can use for reference?

Thanks for any inputs!

joomerguy
Joomla! Fledgling
Joomla! Fledgling
Posts: 3
Joined: Wed Mar 06, 2024 4:46 pm

Re: Security Checklist ?

Post by joomerguy » Wed Mar 06, 2024 5:10 pm


User avatar
Webdongle
Joomla! Master
Joomla! Master
Posts: 44117
Joined: Sat Apr 05, 2008 9:58 pm

Re: Security Checklist ?

Post by Webdongle » Wed Mar 06, 2024 5:15 pm

Remember you have to be 'lucky' all the time but the hackers only once.
http://www.weblinksonline.co.uk/
https://www.weblinksonline.co.uk/updating-joomla.html
"When I'm right no one remembers but when I'm wrong no one forgets".

joomerguy
Joomla! Fledgling
Joomla! Fledgling
Posts: 3
Joined: Wed Mar 06, 2024 4:46 pm

Re: Security Checklist ?

Post by joomerguy » Wed Mar 06, 2024 10:50 pm

Webdongle wrote:
Wed Mar 06, 2024 5:15 pm
Remember you have to be 'lucky' all the time but the hackers only once.
Indeed, it's an assymetrical situation. Thanks for the docs!

helpwithjoomla
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 156
Joined: Sat Sep 21, 2019 7:29 pm
Contact:

Re: Security Checklist ?

Post by helpwithjoomla » Thu Apr 25, 2024 5:40 pm

I'll add a few thoughts:

- Have a good backup strategy in place so you can restore the site if needed. Frequent backups are best.
- Use a Content Delivery Network.
- Consider a firewall service like Sucuri. They can also help clean a hacked site. Some hosts also provide firewalls.
Joomla Developers Available To Help With Joomla!
https://www.helpwithjoomla.com

User avatar
AMurray
Joomla! Exemplar
Joomla! Exemplar
Posts: 9777
Joined: Sat Feb 13, 2010 7:35 am
Location: Australia

Re: Security Checklist ?

Post by AMurray » Thu Apr 25, 2024 9:42 pm

If you want further comprehensive security information, sign up for Mysites.guru.

It's a Swiss army knife of tools, but the primary feature is the security audit, which goes through your site with a fine-tooth comb and reports any potential security problems (either with your site's Joomla configuration/settings or potentially damaging issues (like hacking) and provides comprehensive details to fix the problems.
Regards - A Murray
General Support Moderator

User avatar
Per Yngve Berg
Joomla! Master
Joomla! Master
Posts: 30977
Joined: Mon Oct 27, 2008 9:27 pm
Location: Romerike, Norway

Re: Security Checklist ?

Post by Per Yngve Berg » Mon Apr 29, 2024 3:36 pm

https://developer.joomla.org/security.html

Check the vulnerable extensions list.


Post Reply

Return to “Security in Joomla! 5.x”