Find Every Joomla Site
Running a Vulnerable
Extension
mySites.guru checks the extensions installed on each of your Joomla sites against hand-written vulnerability rules, twice a day. When a site matches for the first time, you get an email within seconds.
One free audit of one site · no card · about 2 minutes to connect
344
extension vulnerability rules
204
Joomla extensions covered
420
distinct CVEs
Every rule is public. Browse the database behind it.
Rules written by hand
Each rule is written by hand, either from a vulnerability we found and disclosed ourselves or from the vendor's own advisory. A rule records the extension, the versions it affects and the CVE where one has been issued.
Joomla core is handled separately. Core CVEs are imported every hour from the Joomla Security Centre, so a Joomla version with a known core CVE is flagged as well as the extensions it runs.
Every extension rule is published in the Joomla vulnerability database, with a page per CVE, so you can see exactly what your sites are being checked against.
How your sites are checked
Connect a site once. After that, the checking happens on a schedule and the results show up wherever you already look.
- Twice a day, and on page load
- Each site is checked at every snapshot, which runs twice a day, and again when you open the dashboard.
- Email within seconds
- The alert email goes out within seconds of the snapshot that first finds a match. Desktop push notifications are available too.
- A badge in your sites list
- Affected sites are marked in the sites list, so a vulnerable extension is visible without opening each site.
- The "has vulnerable plugins" filter
- One filter narrows your whole portfolio to the sites that need patching, which is the list you work through.
- The site's Important tab
- The details for each match sit on that site's Important tab, next to the other things that need your attention first.
- Severity where it exists
- Severity is shown where the rule has one, which today is 283 of the 344 extension rules. Where the vendor published no score, we do not invent one.
From alert to patched
Knowing which sites are exposed is half the job. The other half is updating them. Filter to the affected sites, then update the extension across all of them from one screen with bulk Joomla updates. If you want a restore point first, Backup All starts a backup on every filtered site at once.
A vulnerable extension is a common way into a Joomla site. If a site was exposed for a while before you patched it, run the Joomla malware scanner over it to check nothing was left behind.
What our users say
Hover to read their thoughts, or view all reviews
Common questions
Is the Joomla vulnerability scanner free?
Where do the vulnerability rules come from?
How often are my sites checked?
How will I hear about a vulnerable extension?
Does every vulnerability have a severity?
What about WordPress?
More ways mySites.guru protects your sites
Bulk Update Joomla
Patch core and extensions across every site
Uptime Monitoring
Checks every 5 minutes, alerts when a site goes down
Website Backups
Scheduled Akeeba backups for every site
Joomla Malware Scanner
Reads every file on your server for backdoors
Joomla Site Hacked?
Triage, clean it yourself, or hand it over
Manage Multiple Joomla Sites
One dashboard for every Joomla site you run
See which of your extensions are on the list
Start with a free audit of one site. Vulnerability alerts across all your sites are part of every plan.
Get Your Free Site AuditOne free audit of one site · no card · about 2 minutes to connect



















