Skip to main content
mySites.guru
New features added last monthRelease RadarFile ManagerImpostor FilesUpdate QueueRogue AdminsMCP & APIJoomla VELCVE Index

Security

112 articles tagged Security, newest first.

Regular Labs Publishes 24 Joomla Extension Updates Including 10 Security Fixes

Regular Labs Publishes 24 Joomla Extension Updates Including 10 Security Fixes

Regular Labs shipped 24 Joomla extension updates on 13 September 2026. Ten fix security issues across nine CVEs, and four change behaviour on update.

Unauthenticated SQL Injection in SP Property Finder found by mySites.guru

Unauthenticated SQL Injection in SP Property Finder found by mySites.guru

mySites.guru found an unauthenticated blind SQL injection in JoomShaper's SP Property Finder. Any visitor could read the database. Fixed in 4.1.4.

Digital Peak patches four Joomla extensions after a Claude audit

Digital Peak patches four Joomla extensions after a Claude audit

Digital Peak shipped out-of-band fixes for DPCalendar, DPMedia, DPAttachments and DPCases on 10 September. DPAttachments is the one to do first.

J2Store 3 Stops Getting Security Fixes on 19 October 2026

J2Store 3 Stops Getting Security Fixes on 19 October 2026

J2Commerce ends J2Store 3 support on 19 October 2026. Six in ten of the J2Store installs we monitor are on that line, and most are two releases behind.

T4 Page Builder 2.3.0 Fixes an Unauthenticated Mail Relay

T4 Page Builder 2.3.0 Fixes an Unauthenticated Mail Relay

JoomlArt's T4 Page Builder 2.3.0 closes an unauthenticated open mail relay we reported in August. A week on, five in six installs we see are still older.

One Search Finds That User on Every Site You Manage

One Search Finds That User on Every Site You Manage

Search one person across every connected Joomla and WordPress site, then add, edit, block or delete accounts and change group membership without logging in.

J2Store 3.3.22, 4.0.22 and 4.1.7 fix five flaws we reported

J2Store 3.3.22, 4.0.22 and 4.1.7 fix five flaws we reported

J2Store 3.3.22, 4.0.22 and 4.1.7 fix five flaws mySites.guru reported, including anonymous PayPal order confirmation and a 9.5 backend escalation.

A Web File Manager for Your Joomla and WordPress Sites

A Web File Manager for Your Joomla and WordPress Sites

mySites.guru now includes a secure, opt-in web file manager for Joomla and WordPress: browse, edit, upload and delete files with no SFTP client needed.

Joomla 3 Didn't Fail. Your Retainer Did.

Joomla 3 Didn't Fail. Your Retainer Did.

We monitor 30,305 live Joomla 3 sites. They are five times more likely to be hacked than Joomla 6, and the agencies who migrated are doing worse.

Impostor Files: How to find every file in a core folder that core never shipped

Impostor Files: How to find every file in a core folder that core never shipped

Joomla 5.4.7 ships exactly one file directly in /administrator/. Impostor Files lists everything else sitting in folders the CMS itself owns.

What Site Audits Reveal About Joomla and WordPress Security

What Site Audits Reveal About Joomla and WordPress Security

99% of Joomla sites don't force MFA and 91.8% of WordPress sites skip DISALLOW_FILE_MODS. Real audit data on which security features get used.

DPCalendar 10.12.0 fixes an SQL injection and an XSS

DPCalendar 10.12.0 fixes an SQL injection and an XSS

Digital Peak fixed a blind SQL injection and a stored XSS in DPCalendar 10.12.0, backported to 8.19.5 for Joomla 3. Both need a logged-in user.

Helix Ultimate 2.2.10 Fixes Twelve Security Issues, Including a Pre-Login Bypass

Helix Ultimate 2.2.10 Fixes Twelve Security Issues, Including a Pre-Login Bypass

Helix Ultimate 2.2.10 is a security release for the Joomla template framework. Every version below it is affected. Here is what it fixes and how to update.

Helix Ultimate's Third Joomla 3 Patch Since JoomShaper Said There Would Be None

Helix Ultimate's Third Joomla 3 Patch Since JoomShaper Said There Would Be None

JoomShaper said its Joomla 3 products would get no security patches regardless of severity. The Helix Ultimate template framework has now had four.

Finding Rogue Admin Accounts Across Every Joomla Site You Manage

Finding Rogue Admin Accounts Across Every Joomla Site You Manage

Attackers plant admin accounts to walk back in after you clean the files. How to find rogue admins across every Joomla site you manage, from one screen.

Three CVEs in miniOrange Extensions for Joomla, All Now Fixed

Three CVEs in miniOrange Extensions for Joomla, All Now Fixed

Two CVSS 10.0 authentication bypasses and a remote uninstall flaw naming 23 extensions. Every affected free edition now has a fixed version, released 31 August.

Summer 2026: Everything New in mySites.guru

Summer 2026: Everything New in mySites.guru

Everything new in mySites.guru this summer: 38 new tools, 40 improvements, and the 19 Joomla extension vulnerabilities we found and disclosed ourselves.

Fabrik 4.7.2 for Joomla: A Long List of Security Fixes

Fabrik 4.7.2 for Joomla: A Long List of Security Fixes

Fabrik 4.7.2 for the Joomla extension closes a long list of unauthenticated vulnerabilities, most of them found and reported by mySites.guru. Update now.

Five Security Issues in JEM (Joomla Event Manager), and No Stable Fix Yet

Five Security Issues in JEM (Joomla Event Manager), and No Stable Fix Yet

mySites.guru found and reported multiple security issues in JEM (Joomla Event Manager), including an unauthenticated article overwrite. No stable fix yet.

A CVSS 10.0 Unauthenticated Upload in YOOtheme ZOO, Fixed in 4.1.66

A CVSS 10.0 Unauthenticated Upload in YOOtheme ZOO, Fixed in 4.1.66

YOOtheme ZOO (com_zoo) up to 4.1.63 had an unauthenticated file upload RCE scored CVSS 10.0, plus a SQL injection, fixed in 4.1.64. Install 4.1.66.

iCagenda 4.0.12 fixes an unauthenticated SQL injection

iCagenda 4.0.12 fixes an unauthenticated SQL injection

CVE-2026-67365 is an unauthenticated SQL injection in the iCagenda Calendar module for Joomla, scored 9.2 Critical. Fixed in 4.0.12.

Sourcerer 14 and 15 did not fix CVE-2026-74253. 16.0.0 does.

Sourcerer 14 and 15 did not fix CVE-2026-74253. 16.0.0 does.

Sourcerer 14 and 15 were both published as the fix for CVE-2026-74253 and neither closed it. It is exploited in the wild. Update now to 16.0.0.

Why PHP 8.5.7 Shows Amber When PHP 8.4.24 Shows Green

Why PHP 8.5.7 Shows Amber When PHP 8.4.24 Shows Green

PHP 8.5.7 shows amber while 8.4.24 shows green because the badge checks whether you are on the newest patch in your branch, not which branch you picked.

Phoca Cart 5.2.4, 6.1.7 and 4.0.13 fix a front-end SQL injection

Phoca Cart 5.2.4, 6.1.7 and 4.0.13 fix a front-end SQL injection

Phoca Cart 5.2.4, 6.1.7 and 4.0.13 patch an unauthenticated SQL injection in the Joomla extension's product filter. Joomla 5 on 6.x isn't offered it.

Unauthenticated Remote Code Execution in SP Page Builder found by mySites.guru

Unauthenticated Remote Code Execution in SP Page Builder found by mySites.guru

mySites.guru found a pre-authentication remote code execution flaw in SP Page Builder for Joomla, in the same release that fixed our earlier reports.

Cotton Cloud Patched the Login, Then the Data

Cotton Cloud Patched the Login, Then the Data

Two access control flaws in Cotton Cloud for Joomla. The first fix closed the door, not the room. CVE-2026-67283 and CVE-2026-67284 are fixed in 2.0.3.

Twenty Rules for Joomla Extension Developers Handling a Security Report

Twenty Rules for Joomla Extension Developers Handling a Security Report

A new Joomla Manual page sets out 20 rules for how extension developers should handle a security report. Republished here in full under the JEDL.

The Fabrik Fiasco: Announced, Restricted, Relabelled

The Fabrik Fiasco: Announced, Restricted, Relabelled

Two CVSS 10.0 RCEs in the Fabrik Joomla extension, and a chaotic run of security releases since. The vendor has moved past 4.7.0; be on 4.7.2.

Another 23 Critical Security Vulnerabilities in Gridbox for Joomla

Another 23 Critical Security Vulnerabilities in Gridbox for Joomla

Balbooa asked mySites.guru to audit Gridbox for Joomla. We found 23 vulnerabilities, including a pre-auth RCE, some exploited already. Fixed in 2.20.2.

JCE 2.9.99.10 Fixes Another Security Issue

JCE 2.9.99.10 Fixes Another Security Issue

JCE 2.9.99.10 patches a file rename flaw letting a privileged user create a hidden file in the folder they were browsing. The release hardens more too.

Pre-Authentication SQL Injection and Mail Relay in SP Page Builder found by mySites.guru

Pre-Authentication SQL Injection and Mail Relay in SP Page Builder found by mySites.guru

mySites.guru found four vulnerabilities in SP Page Builder for Joomla: a SQL injection and a mail relay, fixed in 6.7.1. A fifth survived to 6.8.0.

Exposed Customer Invoices, Order Forgery and SQL Injection in EasyStore for Joomla found by mySites.guru

Exposed Customer Invoices, Order Forgery and SQL Injection in EasyStore for Joomla found by mySites.guru

Before EasyStore 2.0.2, any logged-in customer could read every other customer's invoice by editing one URL. mySites.guru found this and two more flaws.

Regular Labs Patched Its Whole Joomla Extension Catalogue at Once

Regular Labs Patched Its Whole Joomla Extension Catalogue at Once

Regular Labs shipped a security-hardening update across its Joomla extension range on 22 July 2026: SSRF, command injection, stored XSS and more. No CVEs.

PageBuilder CK RCE fixed - again - correctly this time

PageBuilder CK RCE fixed - again - correctly this time

PageBuilder CK's 3.6.0 fix for its file-upload RCE (CVE-2026-56290) added just a login check; any Editor could still run code. Fixed in 3.6.3. Be on 3.6.5.

Events Booking for Joomla exposes personal and financial data from invoices

Events Booking for Joomla exposes personal and financial data from invoices

An unauthenticated flaw in Events Booking for Joomla let anyone download any registrant's invoice, with their name, address, email and payment. Fixed in 5.8.2.

One VEL for Every Joomla and WordPress Site

One VEL for Every Joomla and WordPress Site

The Joomla VEL (Vulnerable Extension List) only covers Joomla and never checks your sites. mySites.guru tracks both CMSes and flags yours directly.

Your .htaccess Won't Stop a Joomla Hack

Your .htaccess Won't Stop a Joomla Hack

A hardened .htaccess feels safe, but Joomla attacks ride straight through index.php. Here is why the file protects far less than most site owners think.

Membership Pro 4.6.2: A Quiet Fix for Anonymous File Uploads

Membership Pro 4.6.2: A Quiet Fix for Anonymous File Uploads

Membership Pro 4.6.2 quietly fixes the same anonymous upload flaw we reported in Events Booking. Now CVE-2026-62415, rated critical. What to do about it.

Gridbox for Joomla: One Cookie and You Are a Super User

Gridbox for Joomla: One Cookie and You Are a Super User

A critical unauthenticated authentication bypass in Gridbox for Joomla let anyone become a Super User by setting a single cookie. Fixed in 2.20.1. Update now.

Events Booking for Joomla: Anyone Could Upload Files to Your Server

Events Booking for Joomla: Anyone Could Upload Files to Your Server

mySites.guru found two unauthenticated flaws in Events Booking for Joomla: file upload enabled by default, and a leak of every user's name and email.

DJ-Classifieds Unauthenticated File Upload

DJ-Classifieds Unauthenticated File Upload

DJ-Classifieds below 3.11.2 let anyone upload files to your Joomla site with no login, and it was being used in the wild. Update to 3.11.2 now.

jDownloads 4.1 Shipped an Unauthenticated Upload Endpoint, Now Fixed in 4.1.6

jDownloads 4.1 Shipped an Unauthenticated Upload Endpoint, Now Fixed in 4.1.6

jDownloads 4.1.0 to 4.1.5 shipped a leftover test script that let anyone upload files to your Joomla site with no login. Update to 4.1.6, which removes it.

We Are Not the Only Ones Auditing Joomla Extensions

We Are Not the Only Ones Auditing Joomla Extensions

Two Joomla extension flaws went public via the Joomla CNA: a SQL injection in JoomCCK and a stored XSS in ChronoForms. Neither was ours. Update now.

Unauthenticated SQL Injection in Quix Page Builder found by mySites.guru

Unauthenticated SQL Injection in Quix Page Builder found by mySites.guru

mySites.guru found and reported CVE-2026-58078, an unauthenticated SQL injection in Quix Page Builder for Joomla. Fixed in 6.2.1; update to 6.2.2.

JoomShaper Patched the Joomla 3 It Said It Never Would

JoomShaper Patched the Joomla 3 It Said It Never Would

Six days after ruling out Joomla 3 security patches, JoomShaper shipped them for Helix Ultimate, Helix3 and SP Page Builder. What is in them.

Unauthenticated SQL Injection in EDocman found by mySites.guru

Unauthenticated SQL Injection in EDocman found by mySites.guru

mySites.guru found an unauthenticated SQL injection in EDocman for Joomla that let anyone read the whole database. Fixed in 3.9.0 - update now.

The One-Click Way to Patch JoomShaper Extensions on Joomla 3

The One-Click Way to Patch JoomShaper Extensions on Joomla 3

mySites.guru backports JoomShaper's security fixes into SP Page Builder, Helix3 and Helix Ultimate on Joomla 3, across every site in your account.

Nineteen and Counting: Joomla Extension Vulnerabilities We Found and Disclosed in a Month

Nineteen and Counting: Joomla Extension Vulnerabilities We Found and Disclosed in a Month

In just over a month mySites.guru found and responsibly disclosed nineteen security issues in popular Joomla extensions, most of them critical.

Unauthenticated SQL Injection in DPCalendar found by mySites.guru

Unauthenticated SQL Injection in DPCalendar found by mySites.guru

mySites.guru found and reported an unauthenticated SQL injection in the DPCalendar Joomla extension's public events feed. Fixed in 10.11.2 and 8.19.4.

What Are the .myjoomla.configuration.php.md5 Files?

What Are the .myjoomla.configuration.php.md5 Files?

Found .myjoomla.configuration.php.md5 files in your Joomla webspace? They are not malware. They are mySites.guru file-integrity lock files. Here's what they do.

Phoca Download 6.1.3 Fixes an Authenticated Upload RCE

Phoca Download 6.1.3 Fixes an Authenticated Upload RCE

Phoca Download for Joomla (com_phocadownload) up to 6.1.2 let a logged-in member upload a PHP file and run code on the server. Fixed in 6.1.3, update now.

RSFiles! Fixes an Unauthenticated File Upload RCE

RSFiles! Fixes an Unauthenticated File Upload RCE

RSFiles! for Joomla (com_rsfiles) up to 1.17.11 had an unauthenticated file upload flaw letting anyone drop a PHP file and run code. Update now.

Unauthenticated SQL Injection in AcyMailing found by mySites.guru

Unauthenticated SQL Injection in AcyMailing found by mySites.guru

mySites.guru found and reported CVE-2026-56292, an unauthenticated SQL injection in AcyMailing for Joomla and WordPress. Update to 10.11.1 now.

JoomShaper Ends Joomla 3 Security Fixes

JoomShaper Ends Joomla 3 Security Fixes

JoomShaper ended Joomla 3 support with no security fixes regardless of severity, then reversed the security half six days later and shipped patches.

Balbooa Forms Fixes an Unauthenticated File Upload RCE

Balbooa Forms Fixes an Unauthenticated File Upload RCE

Balbooa Forms (com_baforms) had an unauthenticated file upload RCE, CVE-2026-56291, fixed in 2.4.1. Three more security releases followed: update to 2.4.3.2.

The Helix3 Defacement Lives in Your Database, Not Your Files

The Helix3 Defacement Lives in Your Database, Not Your Files

The Hacked by AntonKill defacement hits Joomla sites via Helix3, hiding in the database where file scanners never look. Clean it in one click.

Helix Ultimate 2.2.7 Closes an Unauthenticated Menu Write

Helix Ultimate 2.2.7 Closes an Unauthenticated Menu Write

Helix Ultimate 2.2.7 fixes CSRF and permission gaps in com_ajax: an unauthenticated menu write leading to stored XSS, a file delete, and an open redirect.

Helix3 Shipped a Critical Fix as "Security Update"

Helix3 Shipped a Critical Fix as "Security Update"

Helix3 3.1.1 patches an unauthenticated file write and file delete in the Helix3 ajax plugin. JoomShaper announced it but told nobody what it fixes.

PageBuilder CK File Upload RCE - June 2026

PageBuilder CK File Upload RCE - June 2026

PageBuilder CK below 3.6.0 lets anyone upload and run a file on your Joomla site, no login. CVE-2026-56290, CVSS 10.0, exploited in the wild. Update to 3.6.0.

Reinfected? Check Every Crontab, Not Just Yours

Reinfected? Check Every Crontab, Not Just Yours

Your cPanel cron jobs look clean but the site reinfects anyway. The cron rebuilding the malware is hiding in a crontab your account can't see. Here is where.

Hacked Yesterday, Exploited Today: Why One Cleanup Is Never the End

Hacked Yesterday, Exploited Today: Why One Cleanup Is Never the End

The first hack plants a dormant dropper. The real damage comes in the second wave, days or weeks later. Here is why monitoring beats one-shot cleanup.

Avada Builder 3.15.4 Patches an Unauthenticated File Deletion Flaw (CVE-2026-8713)

Avada Builder 3.15.4 Patches an Unauthenticated File Deletion Flaw (CVE-2026-8713)

Avada Builder 3.15.4 fixes a critical unauthenticated file deletion flaw (CVE-2026-8713, CVSS 9.1) that can delete wp-config.php and take over the site.

OVH Flagged Our Plugin as Malware. It Is Not, and Here Is the Proof.

OVH Flagged Our Plugin as Malware. It Is Not, and Here Is the Proof.

OVH's scanner flagged our legitimate bfRestore.php file as malware and cut outgoing connections and email across whole hosting plans. Here is why it is safe.

Zero Day Vulnerability Found in iCagenda Joomla Extension

Zero Day Vulnerability Found in iCagenda Joomla Extension

mySites.guru found and confirmed an unauthenticated upload giving remote code execution on Joomla 6 sites running iCagenda. Fixed same-day in 4.0.8.

SP Page Builder Zero Day Is Being Used to Plant Fake Joomla Admins

SP Page Builder Zero Day Is Being Used to Plant Fake Joomla Admins

An unauthenticated upload in the SP Page Builder Joomla extension gives remote code execution and creates hidden Super User accounts. Fixed in 6.6.2.

Suspect Content vs Hacked Files: Two mySites.guru Tools, One Big Difference

Suspect Content vs Hacked Files: Two mySites.guru Tools, One Big Difference

mySites.guru now has two tools: Suspect content matches a file's content, Hacked files matches its hash. Learn the difference and triage your audit in minutes.

A New mySites.guru Tool to Find, and Fix, the JCE Profiles Hack (June 2026)

A New mySites.guru Tool to Find, and Fix, the JCE Profiles Hack (June 2026)

mySites.guru now has a dedicated check that finds rogue JCE editor profiles and webshells across your Joomla sites, then lets you clean and patch them.

JCE Pro 2.9.99.6 Is a Hardening Release After a Full Audit of Joomla's Most-Installed Editor

JCE Pro 2.9.99.6 Is a Hardening Release After a Full Audit of Joomla's Most-Installed Editor

JCE Pro 2.9.99.6 follows a four-day security audit of the editor, narrowing entry points and hardening input validation. Recommended for every JCE site.

JCE Free/Pro 2.9.99.5 Patches an Unauthenticated File Upload in Joomla's Most-Installed Editor

JCE Free/Pro 2.9.99.5 Patches an Unauthenticated File Upload in Joomla's Most-Installed Editor

JCE Free and JCE Pro 2.9.99.5 patch an unauthenticated editor profile upload that could upload arbitrary files. Update every Joomla site running JCE.

JCE Free/Pro 2.9.99.4 Patches Two Authenticated Vulnerabilities in Joomla's Most Popular Editor

JCE Free/Pro 2.9.99.4 Patches Two Authenticated Vulnerabilities in Joomla's Most Popular Editor

JCE Free and JCE Pro 2.9.99.4 patch an Editor Profile authentication bypass and a directory traversal in filesystem search. Update JCE today.

Avada Builder Patches Two Security Issues in 3.15.3

Avada Builder Patches Two Security Issues in 3.15.3

Avada Builder 3.15.3 patches an unauthenticated SQL injection and a Subscriber-level file read across 1 million WordPress sites. Find affected sites.

Spotting .sorry Ransomware on Your cPanel Hosts

Spotting .sorry Ransomware on Your cPanel Hosts

Sorry ransomware encrypts cPanel-hosted sites via CVE-2026-41940 and appends .sorry to every file. mySites.guru now flags those files in every audit.

Let's Encrypt Is Down. Renewals Are Next

Let's Encrypt Is Down. Renewals Are Next

Let's Encrypt halted certificate issuance at 18:37 UTC on 2026-05-08 after a cross-signed cert problem with its new Generation Y root. Resumed in 2h 28m.

Breeze, Cloudways Cache Plugin, Has a Remote Code Execution Bug

Breeze, Cloudways Cache Plugin, Has a Remote Code Execution Bug

Wordfence blocked 3,936 attacks in 24 hours against Breeze Cache below 2.4.5. CVE-2026-3844 is unauthenticated RCE on 400,000+ WordPress sites.

AcyMailing Vulnerability Also Affects Joomla Sites

AcyMailing Vulnerability Also Affects Joomla Sites

CVE-2026-3614 is listed as a WordPress bug. We diffed the 10.8.1 and 10.8.2 source and the same vulnerable code ships to Joomla sites too.

How to Enable POW Captcha in Joomla 6.1

How to Enable POW Captcha in Joomla 6.1

Joomla 6.1 ships a built-in proof-of-work captcha replacing Google reCAPTCHA. How to enable it on one site or a whole portfolio with mySites.guru.

The WordPress Plugin You Trusted Was Sold to an Attacker

The WordPress Plugin You Trusted Was Sold to an Attacker

A buyer acquired 31 WordPress plugins, planted a backdoor in August 2025, and activated it in April 2026. Here is what happened and how to check your sites.

Smart Slider 3 Pro 3.5.1.35 Was a Malicious Release: Supply Chain Compromise

Smart Slider 3 Pro 3.5.1.35 Was a Malicious Release: Supply Chain Compromise

Smart Slider 3 Pro 3.5.1.35 was a malicious release pushed through the official update channel. RCE backdoor, hidden admin users. Update to 3.5.1.36.

Ninja Forms File Uploads CVE-2026-0740: The AJAX Pattern Strikes Again

Ninja Forms File Uploads CVE-2026-0740: The AJAX Pattern Strikes Again

CVE-2026-0740 is a CVSS 9.8 unauthenticated RCE in the Ninja Forms File Uploads AJAX handler, exploited with over 118,600 attempts blocked by Wordfence.

4 Major WordPress Plugins Patched Security Flaws in March 2026

4 Major WordPress Plugins Patched Security Flaws in March 2026

Elementor, Yoast SEO, WPForms, and Really Simple Security all shipped security patches in March 2026. What was fixed, and how to verify your sites.

AJAX Endpoints Are A Big CMS Security Blind Spot

AJAX Endpoints Are A Big CMS Security Blind Spot

Five AJAX and API vulnerabilities hit Joomla and WordPress in March 2026, all sharing one root cause. Here is what went wrong and how to protect your sites.

Novarain Framework Vulnerability: Check Your Joomla Sites for nrframework

Novarain Framework Vulnerability: Check Your Joomla Sites for nrframework

CVE-2026-21627 (CVSS 9.5) - Tassos/Novarain Framework for Joomla allows unauthenticated file inclusion, deletion, and SQL injection.

Smart Slider 3 Hack Allows Any File to Be Downloaded

Smart Slider 3 Hack Allows Any File to Be Downloaded

CVE-2026-3098 lets any subscriber download wp-config.php from 800,000 WordPress sites running Smart Slider 3. How to check and fix it.

How to Check Your Joomla Database Security with mySites.guru

How to Check Your Joomla Database Security with mySites.guru

Your Joomla database might be running with the default jos_ prefix, a root user, or excessive privileges. Here's how to flag each issue and fix it.

How to Clean Up Dangerous Files Left on Your Joomla Web Server

How to Clean Up Dangerous Files Left on Your Joomla Web Server

ZIP archives, SQL dumps, and PHP error logs left on your Joomla server are security risks waiting to be exploited. Find and remove them before an attacker does.

Snapshot vs Audit: What's the Difference?

Snapshot vs Audit: What's the Difference?

mySites.guru checks your sites two ways: quick snapshots of config and settings, and deep audits that scan every file. Here's when to use each.

How to Verify Your Joomla Site's Email Configuration Actually Works

How to Verify Your Joomla Site's Email Configuration Actually Works

Joomla and WordPress contact forms can silently fail. Check SMTP settings, test mail delivery, and catch email misconfigurations across all your sites.

How to Compare Joomla Templates Across All Your Sites

How to Compare Joomla Templates Across All Your Sites

See which template every Joomla site uses, spot legacy or default templates, and export the full list as CSV from one dashboard.

Is My WordPress Site Hacked? How to Check and What to Do Next

Is My WordPress Site Hacked? How to Check and What to Do Next

Think your WordPress site has been hacked? Here are the signs to look for, how to confirm it, and what to do in the first 24 hours to contain the damage.

How to Enforce Minor Upgrades Only in WordPress

How to Enforce Minor Upgrades Only in WordPress

Stop WordPress from jumping major versions automatically while still getting security patches. How WP_AUTO_UPDATE_CORE works.

WordPress 6.9.2, 6.9.3, and 6.9.4: 10 Security Fixes, a Crash, and Incomplete Patches

WordPress 6.9.2, 6.9.3, and 6.9.4: 10 Security Fixes, a Crash, and Incomplete Patches

WordPress 6.9.2 crashed sites with a white screen, 6.9.3 fixed it, then 6.9.4 completed three missing security patches. What happened and how to recover.

Astroid Framework Vulnerability - What Happened and How to Check Your Joomla Site

Astroid Framework Vulnerability - What Happened and How to Check Your Joomla Site

CVE-2026-21628 (CVSS 10.0) - Astroid Framework for Joomla had a critical auth bypass letting attackers upload backdoors. What happened and what to do.

How to Stop Any Plugin Installs in WordPress Admin

How to Stop Any Plugin Installs in WordPress Admin

Add DISALLOW_FILE_MODS to wp-config.php to block plugin and theme installs in WordPress admin. Code snippet, wp-cli usage, and how to enforce it.

Hidden Files Lurking on Your Web Server

Hidden Files Lurking on Your Web Server

Your web server probably has hidden dot-files you've never seen. Some are harmless, some were left by hackers. Here's how to find them.

mySites.guru supports login with Passkeys

mySites.guru supports login with Passkeys

mySites.guru supports login with passkeys - Face ID, Touch ID, Windows Hello, or any FIDO2 device. Faster than passwords, impossible to phish.

AI-Powered Malware Analysis Now Available in mySites.guru

AI-Powered Malware Analysis Now Available in mySites.guru

Send flagged suspect files to Claude or GPT for instant malware analysis. Crowdsourced cached results shared across all subscribers.

WordPress Plugin Vulnerability Alerting

WordPress Plugin Vulnerability Alerting

mySites.guru cross-references every WordPress plugin on your sites against Wordfence, CVE and custom threat databases, flagging vulnerable plugins instantly.

Check your site's security headers

Check your site's security headers

mySites.guru checks eight HTTP security headers on every snapshot - CSP, HSTS, X-Frame-Options and more - to help you harden against XSS and clickjacking.

End-of-Life Version Support in mySites.guru

End-of-Life Version Support in mySites.guru

mySites.guru monitors end-of-life Joomla and WordPress versions from 1.5 to 6, alerting you when sites run unsupported software that puts them at risk.

Find Hacks and Backdoors in WordPress & Joomla

Find Hacks and Backdoors in WordPress & Joomla

Scan your WordPress and Joomla sites for malware, backdoors, and suspicious files. Hash-based detection and 1,500+ regex patterns.

Quick Snapshot of All Your Sites

Quick Snapshot of All Your Sites

The mySites.guru snapshot runs 140+ best-practice checks - PHP version, CMS config, security headers, SSL and more - twice a day on every connected site.

Real-Time Alerts for File Changes & Logins

Real-Time Alerts for File Changes & Logins

Get real-time email alerts when files change, admins log in, or SSL certificates near expiry across all your Joomla and WordPress sites with mySites.guru.

Remove Fluff Files After Joomla Updates

Remove Fluff Files After Joomla Updates

mySites.guru can automatically delete leftover installation folders, readme files and other fluff left behind after Joomla core updates.

Disable "Send Copy to Submitter" in Joomla

Disable "Send Copy to Submitter" in Joomla

Use mySites.guru to bulk-disable the Joomla Send Copy to Submitter contact form setting across all your sites to stop it being abused for spam.

Clean a Hacked Site with Suspect Content and Hacked Files

Clean a Hacked Site with Suspect Content and Hacked Files

Use mySites.guru's Suspect Content and Hacked Files tools to find, confirm, and clean backdoors on a hacked Joomla or WordPress site, step by step.

Fix Joomla 3 Security Issues in One Click

Fix Joomla 3 Security Issues in One Click

Patch every known Joomla 3 security vulnerability across all your sites with a single toggle in mySites.guru - no manual file edits, no eLTS subscription.

Track SSL Certificate Expirations Easily

Track SSL Certificate Expirations Easily

mySites.guru checks every site's SSL certificate issuer, expiry date and full chain validity on every snapshot, alerting you before they expire.

Best Practice for Joomla & WordPress Sites

Best Practice for Joomla & WordPress Sites

Every mySites.guru snapshot and audit check comes with a detailed Learn More page explaining the best practice recommendation, the risk and how to fix it.

One-Click Admin Login to Any Site

One-Click Admin Login to Any Site

Skip the login page entirely. One click from mySites.guru logs you straight into any Joomla or WordPress admin console - no passwords stored, fully encrypted.

Deep Security Audit for WordPress & Joomla

Deep Security Audit for WordPress & Joomla

Surface-level scanners miss hidden malware. File-level audits check every line of code against 1,500+ patterns to find backdoors other tools miss.

The Joomla 3.10.999 Project

The Joomla 3.10.999 Project

The Joomla 3.10.999 project backported critical security patches to end-of-life Joomla 3 sites. What it was, why it existed, and what to do now.

WordPress Debug Constants Explained

WordPress Debug Constants Explained

WP_DEBUG_LOG writes errors to a publicly accessible file that Google has indexed on thousands of sites. Here's the fix, plus what every debug constant does.

Browse every article