Skip to main content
mySites.guru
J!Awards 2026mySites.guru is shortlisted for Your Favourite Tool in Your Joomla WorkflowVote by 11 OctoberHow to vote
344 rules, 204 Joomla extensions, 420 CVEs

Find Every Joomla Site
Running a Vulnerable
Extension

mySites.guru checks the extensions installed on each of your Joomla sites against hand-written vulnerability rules, twice a day. When a site matches for the first time, you get an email within seconds.

Get Your Free Site Audit

One free audit of one site · no card · about 2 minutes to connect

344

extension vulnerability rules

204

Joomla extensions covered

420

distinct CVEs

Every rule is public. Browse the database behind it.

Rules written by hand

Each rule is written by hand, either from a vulnerability we found and disclosed ourselves or from the vendor's own advisory. A rule records the extension, the versions it affects and the CVE where one has been issued.

Joomla core is handled separately. Core CVEs are imported every hour from the Joomla Security Centre, so a Joomla version with a known core CVE is flagged as well as the extensions it runs.

Every extension rule is published in the Joomla vulnerability database, with a page per CVE, so you can see exactly what your sites are being checked against.

How your sites are checked

Connect a site once. After that, the checking happens on a schedule and the results show up wherever you already look.

Twice a day, and on page load
Each site is checked at every snapshot, which runs twice a day, and again when you open the dashboard.
Email within seconds
The alert email goes out within seconds of the snapshot that first finds a match. Desktop push notifications are available too.
A badge in your sites list
Affected sites are marked in the sites list, so a vulnerable extension is visible without opening each site.
The "has vulnerable plugins" filter
One filter narrows your whole portfolio to the sites that need patching, which is the list you work through.
The site's Important tab
The details for each match sit on that site's Important tab, next to the other things that need your attention first.
Severity where it exists
Severity is shown where the rule has one, which today is 283 of the 344 extension rules. Where the vendor published no score, we do not invent one.

From alert to patched

Knowing which sites are exposed is half the job. The other half is updating them. Filter to the affected sites, then update the extension across all of them from one screen with bulk Joomla updates. If you want a restore point first, Backup All starts a backup on every filtered site at once.

A vulnerable extension is a common way into a Joomla site. If a site was exposed for a while before you patched it, run the Joomla malware scanner over it to check nothing was left behind.

What our users say

Isaac HartErwin De SaedeleerManuelE.S.FSven KrumbeckDavid McKieMarkus TjoaNick CrossmanTom WebbMichael Sønderup NielsenMikael A - Webbkompass ABDeich8Shaun KehoeLaurent CollonguesThomas C. GassPJWStephan BrendelFrank DelventhalPanagiotisPeter Dowse

Hover to read their thoughts, or view all reviews

Common questions

Is the Joomla vulnerability scanner free?
Ongoing alerts are part of every plan; your free audit shows where the site stands today. The audit covers one site and needs no card. Paid plans start at £5/month for one site or £19.99/month for unlimited sites.
Where do the vulnerability rules come from?
Extension rules are written by hand, from our own security disclosures and from vendor advisories. Each rule names the extension, the affected versions and, where one exists, the CVE. Joomla core CVEs are imported every hour from the Joomla Security Centre. You can browse every extension rule in the Joomla vulnerability database.
How often are my sites checked?
At every snapshot, which runs twice a day, and again when you open the dashboard. When a snapshot finds a match for the first time, the alert email goes out within seconds.
How will I hear about a vulnerable extension?
By email, and by desktop push notification if you turn it on. In the dashboard the site gets a badge in your sites list, the "has vulnerable plugins" filter shows every affected site at once, and the details sit on that site's Important tab.
Does every vulnerability have a severity?
No. Severity is shown where the rule has one: today that is 283 of the 344 extension rules. Some vendors fix a flaw without publishing a score, and we would rather leave the field empty than guess.
What about WordPress?
WordPress plugins and themes are checked as well, from a separate feed. That side is covered on the WordPress vulnerability scanner page.

See which of your extensions are on the list

Start with a free audit of one site. Vulnerability alerts across all your sites are part of every plan.

Get Your Free Site Audit

One free audit of one site · no card · about 2 minutes to connect