# mySites.guru > Manage, monitor, and secure all your WordPress and Joomla sites from one dashboard. Security audits, bulk updates, backups, uptime monitoring, and 240+ tools. Trusted by 90,000+ sites since 2012. ## Key Pages - [Features](https://mysites.guru/features/): All-in-one WordPress & Joomla management — malware scanning, bulk updates, backups, uptime monitoring, single sign-on & unlimited team access. - [Pricing](https://mysites.guru/pricing/): £19.99/month for unlimited sites and team members. Single site plan at £5/month. No per-site fees, all features included. - [Free Site Audit](https://mysites.guru/free-audit/): Run a free security audit on any WordPress or Joomla site. Scans every file for malware, backdoors, and vulnerabilities. - [Screenshots](https://mysites.guru/screenshots/): Visual tour of the mySites.guru dashboard showing all 18 key views. - [Reviews](https://mysites.guru/reviews/): Verified customer reviews and independent WP Mayor review (4.6/5 stars). - [FAQ](https://mysites.guru/faq/): Common questions about setup, security, pricing, and multi-site management. ## Solutions - [WordPress Hacked?](https://mysites.guru/wordpress-hacked/): Free security scan for compromised WordPress sites. Checks every file for malware, backdoors, and injected code. - [Joomla Hacked?](https://mysites.guru/joomla-hacked/): Triage a compromised Joomla site, clean it yourself with the suspect content and hacked files tools, or hand it over for a flat fee. Built on 14 years of Joomla-specific threat data. - [Joomla Malware Scanner](https://mysites.guru/joomla-malware-scanner/): Free file-level malware and backdoor scanning for Joomla. Reads every file on your server, not just your rendered pages. - [JCE Hack Tool](https://mysites.guru/jce-hack/): Find and remove the JCE Profiles hack, including rogue editor profiles and the webshells dropped through them. - [WordPress Malware Scanner](https://mysites.guru/wordpress-malware-scanner/): Deep file-level malware scanning for WordPress. Scans every file against 14 years of threat data. - [WordPress Vulnerability Scanner](https://mysites.guru/wordpress-vulnerability-scanner/): Automatic CVE alerts for every WordPress plugin and theme. One-click security patches. - [Bulk Update WordPress](https://mysites.guru/bulk-update-wordpress/): Update plugins, themes, and core across all your WordPress sites at once. - [Manage Multiple WordPress Sites](https://mysites.guru/manage-multiple-wordpress-sites/): One dashboard for all your WordPress and Joomla sites. ## Guides - [WordPress & Joomla Security Guide](https://mysites.guru/guides/wordpress-joomla-security-guide/): Comprehensive guide to securing WordPress and Joomla sites - malware scanning, vulnerability management, hardening, and incident response. - [Managing CMS Updates at Scale](https://mysites.guru/guides/managing-cms-updates-at-scale/): How to handle WordPress and Joomla core, plugin, and theme updates across dozens or hundreds of sites safely. - [Agency Multi-Site Management](https://mysites.guru/guides/agency-multi-site-management/): Running a web agency with many client sites - team workflows, client reporting, bulk operations, and scaling operations. - [Site Monitoring & Alerting Guide](https://mysites.guru/guides/site-monitoring-alerting-guide/): Uptime monitoring, SSL tracking, disk space alerts, and file change detection across all your sites from one dashboard. - [The Joomla Agency Handbook](https://mysites.guru/guides/joomla-agency-handbook/): Managing Joomla sites at agency scale - updates, security, extensions, migrations, and Joomla-specific workflows. ## Blog Posts - [iCagenda 4.0.12 fixes an unauthenticated SQL injection](https://mysites.guru/blog/icagenda-calendar-module-sql-injection/): CVE-2026-67365 is an unauthenticated SQL injection in the iCagenda Calendar module for Joomla, scored 9.2 Critical. Fixed in 4.0.12. - [Sourcerer 14.0.0 fixes PHP execution from unverified content](https://mysites.guru/blog/sourcerer-14-unverified-content-php-execution/): Sourcerer, the Joomla extension, ran PHP from page content it could not trace to a verified source. CVE-2026-74253 scores 10.0 critical. Update to 14.0.0. - [Why PHP 8.5.7 Shows Amber When PHP 8.4.24 Shows Green](https://mysites.guru/blog/php-supported-versions-amber-green/): PHP 8.5.7 shows amber while 8.4.24 shows green because the badge checks whether you are on the newest patch in your branch, not which branch you picked. - [Phoca Cart 5.2.4, 6.1.7 and 4.0.13 fix a front-end SQL injection](https://mysites.guru/blog/phoca-cart-sql-injection-product-filter/): Phoca Cart 5.2.4, 6.1.7 and 4.0.13 patch an unauthenticated SQL injection in the Joomla extension's product filter. Joomla 5 sites running Phoca Cart 6.x are not offered it. - [Unauthenticated Remote Code Execution in SP Page Builder found by mySites.guru](https://mysites.guru/blog/sp-page-builder-pre-auth-rce-file-inclusion-disclosure/): mySites.guru found a pre-authentication remote code execution flaw in SP Page Builder for Joomla, in the same 6.7.1 release that fixed our earlier reports. Update to 6.8.0 now. - [Cotton Cloud Patched the Login, Then the Data](https://mysites.guru/blog/cotton-cloud-incomplete-security-fix/): Two access control flaws in Cotton Cloud for Joomla. The first fix closed the door and left the room unlocked. CVE-2026-67283 and CVE-2026-67284 are fixed in 2.0.3. - [Twenty Rules for Joomla Extension Developers Handling a Security Report](https://mysites.guru/blog/joomla-extension-security-disclosure-standard/): A new Joomla Manual page sets out 20 rules for how extension developers should handle a security report. Republished here in full under the JEDL. - [The Fabrik Fiasco: Announced, Restricted, Relabelled](https://mysites.guru/blog/fabrik-unauthenticated-rce-calc-element/): Two CVSS 10.0 RCEs in the Fabrik Joomla extension. Its 4.7.0 fix was announced as stable, restricted to a test group, then relabelled a release candidate. - [Joomla 6.1.2 and 5.4.7 Silently Ignore Every Article Option](https://mysites.guru/blog/joomla-6-1-2-5-4-7-article-options-ignored/): Joomla 6.1.2 and 5.4.7 silently ignore every per-article Option on the front end. The root cause, how to find affected articles, and the official hotfix. - [Another 23 Critical Security Vulnerabilities in Gridbox for Joomla](https://mysites.guru/blog/gridbox-23-critical-vulnerabilities/): Balbooa asked us to audit Gridbox. We found 23 vulnerabilities, including a pre-auth RCE in one request. Several are being actively exploited in the wild, and the complete fix is now out in Gridbox 2.20.2. Update every Gridbox site immediately. - [JCE 2.9.99.10 Fixes Another Security Issue](https://mysites.guru/blog/jce-2-9-99-10-security-update/): JCE 2.9.99.10 patches a file rename flaw that let a privileged user create a hidden file in the folder they were browsing. The release also hardens far more than its changelog lists. - [Pre-Authentication SQL Injection and Mail Relay in SP Page Builder found by mySites.guru](https://mysites.guru/blog/sp-page-builder-sql-injection-mail-relay-disclosure/): mySites.guru found four vulnerabilities in SP Page Builder for Joomla: a pre-auth SQL injection, an unauthenticated mail relay, and two more. Fixed in 6.7.1. A fifth flaw survived that release and was only fixed on 12 August in 6.8.0. - [Exposed Customer Invoices, Order Forgery and SQL Injection in EasyStore for Joomla found by mySites.guru](https://mysites.guru/blog/easystore-security-disclosure/): Before EasyStore 2.0.2, any logged-in customer could read every other customer's invoice by editing one URL. mySites.guru found this and two unauthenticated flaws. Update now. - [Regular Labs Patched Its Whole Joomla Extension Catalogue at Once](https://mysites.guru/blog/regular-labs-joomla-extension-security-release/): Regular Labs shipped a security-hardening update across its entire Joomla extension range on 22 July 2026: SSRF, command injection, stored XSS and more. No CVEs. Update every Regular Labs extension now. - [PageBuilder CK RCE fixed - again - correctly this time](https://mysites.guru/blog/pagebuilderck-file-upload-rce-incomplete-fix/): PageBuilder CK's 3.6.0 fix for its file-upload RCE (CVE-2026-56290) only added a login check, so any Editor could still run code up to 3.6.2. Fixed in 3.6.3, and two further security releases followed. Be on 3.6.5. - [Events Booking for Joomla exposes personal and financial data from invoices](https://mysites.guru/blog/events-booking-invoice-idor/): An unauthenticated flaw in Events Booking for Joomla let anyone download any registrant's invoice, with their name, address, email and payment. Fixed in 5.8.2. - [One VEL for Every Joomla and WordPress Site](https://mysites.guru/blog/vulnerable-extension-list-joomla-wordpress/): The Joomla VEL (Vulnerable Extension List) only covers Joomla and never checks your sites. mySites.guru tracks Joomla and WordPress extension vulnerabilities and flags yours. - [Your .htaccess Won't Stop a Joomla Hack](https://mysites.guru/blog/your-htaccess-wont-stop-a-joomla-hack/): A hardened .htaccess feels safe, but Joomla attacks ride straight through index.php. Here is why the file protects far less than most site owners think. - [Membership Pro 4.6.2: A Quiet Fix for Anonymous File Uploads](https://mysites.guru/blog/membership-pro-unauthenticated-file-upload/): Membership Pro 4.6.2 quietly fixes the same anonymous upload flaw we reported in Events Booking. Now CVE-2026-62415, rated critical. What to do about it. - [Gridbox for Joomla: One Cookie and You Are a Super User](https://mysites.guru/blog/gridbox-critical-authentication-bypass/): A critical unauthenticated authentication bypass in Gridbox for Joomla let anyone become a Super User by setting a single cookie. Fixed in 2.20.1. Update now. - [Events Booking for Joomla: Anyone Could Upload Files to Your Server](https://mysites.guru/blog/events-booking-unauthenticated-upload-user-enumeration/): mySites.guru found two unauthenticated flaws in Events Booking for Joomla: anonymous file upload enabled by default, and a leak of every user's name and email. Fixed across 5.8.0 and 5.8.1. - [DJ-Classifieds Unauthenticated File Upload](https://mysites.guru/blog/dj-classifieds-unauthenticated-file-upload/): DJ-Classifieds below 3.11.2 let anyone upload files to your Joomla site with no login, and it was being used in the wild. Update to 3.11.2 now. - [jDownloads 4.1 Shipped an Unauthenticated Upload Endpoint, Now Fixed in 4.1.6](https://mysites.guru/blog/jdownloads-4-1-unauthenticated-upload-flaw/): jDownloads 4.1.0 to 4.1.5 shipped a leftover test script that let anyone upload files to your Joomla site with no login. Update to 4.1.6, which removes it. - [We Are Not the Only Ones Auditing Joomla Extensions](https://mysites.guru/blog/we-are-not-the-only-ones-auditing-joomla-extensions/): Two Joomla extension flaws just went public via the Joomla CNA: an unauthenticated SQL injection in JoomCCK and a stored XSS in ChronoForms. Neither was ours. Update now. - [Unauthenticated SQL Injection in Quix Page Builder found by mySites.guru](https://mysites.guru/blog/quix-sql-injection-disclosure/): mySites.guru found and reported CVE-2026-58078, an unauthenticated SQL injection in Quix Page Builder for Joomla. An anonymous request to a front-end element endpoint could read the whole site database. Fixed in Quix 6.2.1; update to 6.2.2 now. - [JoomShaper Patched the Joomla 3 It Said It Never Would](https://mysites.guru/blog/joomshaper-reverses-joomla-3-decision/): Six days after ruling out Joomla 3 security patches regardless of severity, JoomShaper shipped them for Helix Ultimate, Helix3 and SP Page Builder. What is in them. - [Unauthenticated SQL Injection in EDocman found by mySites.guru](https://mysites.guru/blog/edocman-sql-injection-disclosure/): mySites.guru found an unauthenticated SQL injection in EDocman for Joomla that let anyone read the whole database. Fixed in 3.9.0 - update now. - [The One-Click Way to Patch JoomShaper Extensions on Joomla 3](https://mysites.guru/blog/patch-abandoned-joomshaper-joomla-3-extensions/): mySites.guru backports JoomShaper's security fixes into SP Page Builder, Helix3 and Helix Ultimate on Joomla 3, in place and across every site in your account, from one toggle. - [SiteGround's Captcha Is Blocking mySites.guru - again](https://mysites.guru/blog/siteground-captcha-blocking-mysites-guru/): SiteGround's Anti-Bot AI serves mySites.guru's worker a 202 captcha challenge instead of your site. Here's how to spot it and get our IP whitelisted. - [Nineteen and Counting: Joomla Extension Vulnerabilities We Found and Disclosed in a Month](https://mysites.guru/blog/a-month-of-joomla-security-disclosures/): In just over a month mySites.guru found and responsibly disclosed nineteen security issues in popular Joomla extensions, most of them critical. Here is the full roundup and what to do about it. - [Unauthenticated SQL Injection in DPCalendar found by mySites.guru](https://mysites.guru/blog/dpcalendar-sql-injection-disclosure/): mySites.guru found and reported an unauthenticated SQL injection in DPCalendar for Joomla. An anonymous request to the public events feed could read the whole site database. Fixed in 10.11.2 and 8.19.4, update now. - [Joomla Update Error 999: a Dead Extension Redirecting to LinkedIn](https://mysites.guru/blog/invalid-status-code-999-joomla-update-error/): The Joomla 'Invalid status code 999' update error is not a bug. It is an abandoned extension whose update site redirects to LinkedIn. Here is the fix. - [What Are the .myjoomla.configuration.php.md5 Files?](https://mysites.guru/blog/myjoomla-configuration-php-md5-files/): Found .myjoomla.configuration.php.md5 files in your Joomla webspace? They are not malware. They are mySites.guru file-integrity lock files. Here's what they do. - [Phoca Download 6.1.3 Fixes an Authenticated Upload RCE](https://mysites.guru/blog/phoca-download-authenticated-file-upload-rce/): Phoca Download for Joomla (com_phocadownload) up to 6.1.2 let a logged-in member upload a PHP file and run code on the server. Fixed in 6.1.3, update now. - [RSFiles! Fixes an Unauthenticated File Upload RCE](https://mysites.guru/blog/rsfiles-unauthenticated-file-upload-rce/): RSFiles! for Joomla (com_rsfiles) up to 1.17.11 had an unauthenticated file upload flaw that let anyone drop a PHP file and run code. Fixed in 1.17.12, update now. - [Unauthenticated SQL Injection in AcyMailing found by mySites.guru](https://mysites.guru/blog/acymailing-sql-injection-disclosure/): mySites.guru found and reported CVE-2026-56292, an unauthenticated SQL injection in AcyMailing for Joomla and WordPress. Update to 10.11.1 now. - [JoomShaper Ends Joomla 3 Security Fixes](https://mysites.guru/blog/joomshaper-drops-joomla-3-support/): JoomShaper ended Joomla 3 support with no security fixes regardless of severity, then reversed the security half six days later and shipped patches. What to do about it. - [Balbooa Forms Fixes an Unauthenticated File Upload RCE](https://mysites.guru/blog/balbooa-forms-unauthenticated-file-upload-flaw/): Balbooa Forms (com_baforms) had an unauthenticated file upload RCE, CVE-2026-56291, fixed in 2.4.1. Three more security releases followed: update to 2.4.3.2. - [The Helix3 Defacement Lives in Your Database, Not Your Files](https://mysites.guru/blog/helix3-antonkill-defacement-wave/): The Hacked by AntonKill defacement hits Joomla sites through the Helix3 framework, and the payload hides in the database where file scanners never look. Clean it in one click and find every affected site. - [Helix Ultimate 2.2.7 Closes an Unauthenticated Menu Write](https://mysites.guru/blog/helix-ultimate-security-update/): Helix Ultimate 2.2.7 quietly fixes CSRF and permission gaps in its com_ajax handler, an unauthenticated menu write that leads to stored XSS, an in-folder file delete, and an open redirect. Here is what changed and why to update today. - [Helix3 Shipped a Critical Fix as "Security Update"](https://mysites.guru/blog/helix3-security-update-changelog-failure/): Helix3 3.1.1 patches an unauthenticated file write and arbitrary file delete in the Helix3 ajax plugin. JoomShaper announced it, but told nobody what it fixes. Here is the detail, and why you should update now. - [PageBuilder CK File Upload RCE - June 2026](https://mysites.guru/blog/pagebuilderck-unauthenticated-file-upload-rce/): PageBuilder CK below 3.6.0 lets anyone upload and run a file on your Joomla site, no login. CVE-2026-56290, CVSS 10.0, exploited in the wild. Update to 3.6.0. - [Reinfected? Check Every Crontab, Not Just Yours](https://mysites.guru/blog/reinfected-check-every-crontab-not-just-yours/): Your cPanel cron jobs look clean but the site reinfects anyway. The cron rebuilding the malware is hiding in a crontab your account can't see. Here is where. - [Hacked Yesterday, Exploited Today: Why One Cleanup Is Never the End](https://mysites.guru/blog/hacked-yesterday-exploited-today/): The first hack plants a dormant dropper. The real damage comes in the second wave, days or weeks later. Here is why monitoring beats one-shot cleanup. - [Avada Builder 3.15.4 Patches an Unauthenticated File Deletion Flaw (CVE-2026-8713)](https://mysites.guru/blog/avada-builder-cve-2026-8713/): Avada Builder 3.15.4 fixes a critical unauthenticated arbitrary file deletion flaw (CVE-2026-8713, CVSS 9.1) that can delete wp-config.php and hand an attacker the whole site. Here's how to find every site you manage still running an unpatched version. - [Delete 9,000 Hacker .htaccess Files in One Click](https://mysites.guru/blog/delete-malicious-htaccess-files-bulk/): Hackers drop malicious .htaccess files in every folder of your site. mySites.guru deletes all the stray ones in a single click and leaves the legitimate files untouched. - [OVH Flagged Our Plugin as Malware. It Is Not, and Here Is the Proof.](https://mysites.guru/blog/ovh-flagged-our-plugin-as-malware/): OVH's scanner flagged our legitimate bfRestore.php file as malware and cut outgoing connections and email across whole hosting plans. Here is why it is safe. - [Zero Day Vulnerability Found in iCagenda Joomla Extension](https://mysites.guru/blog/icagenda-zero-day-file-upload-rce/): We found and confirmed an unauthenticated file upload that gave attackers full remote code execution on Joomla 6 sites running iCagenda. It was already being exploited. The developer shipped 4.0.8 the same day. - [SP Page Builder Zero Day Is Being Used to Plant Fake Joomla Admins](https://mysites.guru/blog/sp-page-builder-zero-day-uploadcustomicon-rce/): An unauthenticated file upload in SP Page Builder gives attackers remote code execution on Joomla sites and is being used to create hidden Super User accounts. It is fixed in 6.6.2. Update now and check for rogue admins. - [Joomla Update Not Possible Because the Offered Update Has Expired](https://mysites.guru/blog/joomla-update-not-possible-offered-update-has-expired/): Joomla shows "Update not possible because the offered update has expired"? It is usually not your site. Here is the real cause, how to tell which one you have, and the fix. - [Suspect Content vs Hacked Files: Two mySites.guru Tools, One Big Difference](https://mysites.guru/blog/suspect-content-vs-hacked-files/): mySites.guru now has two tools: Suspect content matches a file's content, Hacked files matches its hash. Learn the difference and triage your audit in minutes. - [A New mySites.guru Tool to Find, and Fix, the JCE Profiles Hack (June 2026)](https://mysites.guru/blog/finding-every-site-running-a-vulnerable-jce/): mySites.guru now has a dedicated check that finds rogue JCE editor profiles and webshells across your Joomla sites, then lets you clean and patch them from one screen. - [JCE Pro 2.9.99.6 Is a Hardening Release After a Full Audit of Joomla's Most-Installed Editor](https://mysites.guru/blog/jce-pro-2-9-99-6-security-update/): JCE Pro 2.9.99.6 follows a four-day security audit of the editor, narrowing entry points and hardening input validation. Strongly recommended for every Joomla site running JCE. - [How to Access Your mySites.guru Account Using our Secure API](https://mysites.guru/blog/mysites-guru-api/): The mySites.guru Agency API runs audits, backups and updates across every WordPress and Joomla site you manage, from your own scripts, over OAuth2 with PKCE. - [Manage Every Site From Claude Desktop or other AI tools](https://mysites.guru/blog/manage-every-site-from-claude-desktop/): Connect your mySites.guru account to Claude or any MCP client and run audits, backups and updates across all your WordPress and Joomla sites by typing what you want. - [JCE Free/Pro 2.9.99.5 Patches an Unauthenticated File Upload in Joomla's Most-Installed Editor](https://mysites.guru/blog/jce-pro-2-9-99-5-security-update/): JCE Free and JCE Pro 2.9.99.5 patch an unauthenticated editor profile upload that could be used to upload arbitrary files to the server. Update every Joomla site running JCE now. - [JCE Free/Pro 2.9.99.4 Patches Two Authenticated Vulnerabilities in Joomla's Most Popular Editor](https://mysites.guru/blog/jce-pro-2-9-99-4-security-update/): JCE Free and JCE Pro 2.9.99.4 patch an Editor Profile authentication bypass and a directory traversal in filesystem search. Update every Joomla site running JCE today. - [Joomla 5.4.6 and 6.1.1 Patch TEN Security Issues](https://mysites.guru/blog/joomla-5-4-6-and-6-1-1-patch-ten-security-issues/): Joomla 5.4.6 and 6.1.1 close ten security issues including an MFA bypass and a com_users privilege escalation. Here is the patch order for an agency running 30+ sites. - [WP_AI_SUPPORT: Disable WordPress 7 AI Across Every Site](https://mysites.guru/blog/disable-wordpress-ai-features-wp-ai-support/): WordPress 7.0 ships with built-in AI features enabled by default. Disable WP_AI_SUPPORT across every WordPress site you manage in one click with mySites.guru. - [mySites.guru is fully compatible with WordPress 7.0](https://mysites.guru/blog/mysites-guru-fully-compatible-with-wordpress-7/): WordPress 7.0 "Armstrong" shipped on 20 May 2026. mySites.guru works perfectly with it. Backup, update, and control auto-updates across every site. - [Avada Builder Patches Two Security Issues in 3.15.3](https://mysites.guru/blog/avada-builder-cve-2026-4782-4798/): Avada Builder 3.15.3 patches an unauthenticated SQL injection and a Subscriber-level arbitrary file read across 1 million WordPress sites. Here's how to find every affected site you manage. - [Spotting .sorry Ransomware on Your cPanel Hosts](https://mysites.guru/blog/sorry-ransomware-cpanel-detection/): Sorry ransomware encrypts cPanel-hosted sites via CVE-2026-41940 and appends .sorry to every file. mySites.guru now flags those files automatically in every audit. - [Let's Encrypt Is Down. Renewals Are Next](https://mysites.guru/blog/lets-encrypt-issuance-halted-2026-05-08/): Let's Encrypt halted all certificate issuance at 18:37 UTC on 2026-05-08 after a cross-signed cert problem with their new Generation Y root. Issuance resumed via the Generation X root after roughly 2h 28m. The postmortem (2026-05-13) identifies missing Extended Key Usage (EKU) fields on the cross-certified subordinate CAs, with revocation and reissuance of the X2/YR-by-X1 and YE-by-X2 cross-signs. - [How to Enable Joomla Extension Auto-Updates Safely](https://mysites.guru/blog/how-to-enable-joomla-extension-auto-updates/): How to enable auto-updates for Joomla extensions across one site or hundreds, with backup and rollback steps that keep client sites safe if an update breaks. - [Breeze, Cloudways Cache Plugin, Has a Remote Code Execution Bug](https://mysites.guru/blog/breeze-cache-cve-2026-3844-active-exploitation/): Wordfence blocked 3,936 attacks in 24 hours against Breeze Cache below 2.4.5. CVE-2026-3844 is unauthenticated RCE on 400,000+ WordPress sites. Audit your portfolio. - [A Login for Your Accountant, Not Your Sites](https://mysites.guru/blog/accountant-portal-invoice-access/): Invite your bookkeeper or accountant to mySites.guru with read-only access to invoices only. No site access, no tools, no team data. One captive page, nothing else. - [AcyMailing Vulnerability Also Affects Joomla Sites](https://mysites.guru/blog/acymailing-cve-2026-3614-joomla/): CVE-2026-3614 is listed as a WordPress bug. We diffed the 10.8.1 and 10.8.2 source and the same vulnerable code ships to Joomla sites too. - [How to Enable POW Captcha in Joomla 6.1](https://mysites.guru/blog/how-to-enable-pow-captcha-in-joomla-6-1/): Joomla 6.1 ships a built-in proof-of-work captcha that replaces Google reCAPTCHA. Here is how to enable it across one site or an entire portfolio, with mySites.guru or by hand. - [How to Turn On Module Versioning in Joomla 6.1](https://mysites.guru/blog/joomla-6-1-module-versioning/): Joomla 6.1 finally brings version history to modules. Here's how to enable save_history manually, and how mySites.guru flips it on across every site in one click. - [Joomla 6.1.0 Released - What's New](https://mysites.guru/blog/joomla-6-1-release-whats-new/): Joomla 6.1 lands with a visual workflow editor, built-in POW captcha, media custom fields for audio and video, and a Cassiopeia child template with color controls. - [The WordPress Plugin You Trusted Was Sold to an Attacker](https://mysites.guru/blog/essential-plugin-wordpress-backdoor/): A buyer acquired 31 WordPress plugins, planted a backdoor in August 2025, and activated it in April 2026. Here is what happened and how to check your sites. - [Smart Slider 3 Pro 3.5.1.35 Was a Malicious Release: Supply Chain Compromise](https://mysites.guru/blog/smart-slider-3-pro-supply-chain-compromise/): Smart Slider 3 Pro 3.5.1.35 was a malicious release pushed through the official update channel. RCE backdoor, hidden admin users. Update to 3.5.1.36. - [Ninja Forms File Uploads CVE-2026-0740: The AJAX Pattern Strikes Again](https://mysites.guru/blog/ninja-forms-file-uploads-cve-2026-0740/): CVE-2026-0740 is a CVSS 9.8 unauthenticated RCE in the Ninja Forms File Uploads AJAX handler, now actively exploited with over 118,600 attempts blocked by Wordfence. Here is how the flaw works, why the first patch failed, the IoCs to hunt, and how to find vulnerable sites fast. - [4 Major WordPress Plugins Patched Security Flaws in March 2026](https://mysites.guru/blog/four-wordpress-plugins-security-patches-march-2026/): Elementor, Yoast SEO, WPForms, and Really Simple Security all shipped security patches in March 2026. Here's what was fixed, who's affected, and how to verify your sites. - [AJAX Endpoints Are A Big CMS Security Blind Spot](https://mysites.guru/blog/ajax-endpoints-cms-security-blind-spot/): Five AJAX and API vulnerabilities hit Joomla and WordPress in March 2026, all sharing one root cause. Here is what went wrong and how to protect your sites. - [Joomla's Compat Plugin Is a Crutch, Not a Fix](https://mysites.guru/blog/joomla-compat-plugin-is-a-crutch/): Joomla's backward compatibility plugins keep broken extensions alive. Here's why that's technical debt, how to test without them, and how to recover if your site crashes. - [Novarain Framework Vulnerability: Check Your Joomla Sites for nrframework](https://mysites.guru/blog/novarain-framework-joomla-vulnerability/): CVE-2026-21627 (CVSS 9.5) - Tassos/Novarain Framework for Joomla allows unauthenticated file inclusion, deletion, and SQL injection. - [WordPress 7 Technical Requirements Check: Is Your Hosting Ready?](https://mysites.guru/blog/wordpress-7-technical-requirements-check/): WordPress 7 requires PHP 7.4+ and MySQL 8.0+. Run a free hosting check across your entire portfolio to find which sites meet the technical requirements. - [Smart Slider 3 Hack Allows Any File to Be Downloaded](https://mysites.guru/blog/smart-slider-3-arbitrary-file-read-vulnerability/): CVE-2026-3098 lets any subscriber download wp-config.php from 800,000 WordPress sites running Smart Slider 3. How to check and fix it. - [Detect Locked Joomla Scheduled Tasks Before They Cause Problems](https://mysites.guru/blog/detect-locked-joomla-scheduled-tasks/): Joomla's Task Scheduler can leave tasks stuck in a locked state after crashes or timeouts. mySites.guru detects and unlocks them across all your sites. - [How to Check Your Sites for WordPress 7.0 Compatibility](https://mysites.guru/blog/wordpress-7-requirements/): WordPress 7.0 requires PHP 7.4+ and MySQL 8.0+, dropping PHP 7.2/7.3. Sites on older versions won't auto-update. Check your whole portfolio in seconds. - [How to Check Your Joomla Database Security with mySites.guru](https://mysites.guru/blog/how-to-check-joomla-database-security/): Your Joomla database might be running with the default jos_ prefix, a root user, or excessive privileges. Here's how to flag each issue and fix it. - [Joomla TinyMCE Editor Broken in Firefox 148 - How to Fix It](https://mysites.guru/blog/joomla-tinymce-firefox-148-fix/): Firefox 148 broke the TinyMCE editor in Joomla 4, 5, and 6. The editor flickers and reloads endlessly. Joomla 5.4.4 and 6.0.4 fix it permanently. - [How to Clean Up Dangerous Files Left on Your Joomla Web Server](https://mysites.guru/blog/how-to-clean-up-dangerous-files-joomla-server/): ZIP archives, SQL dumps, and PHP error logs left on your Joomla server are security risks waiting to be exploited. Find and remove them before an attacker does. - [How to Remove the Sample Page and Hello World Post in WordPress with One Click](https://mysites.guru/blog/remove-sample-page-hello-world-wordpress-one-click/): Every WordPress install ships with a Sample Page and Hello World post. Learn why they hurt SEO and how mySites.guru removes them across all your sites. - [Snapshot vs Audit: What's the Difference?](https://mysites.guru/blog/snapshot-vs-audit-whats-the-difference/): mySites.guru checks your sites two ways: quick snapshots of config and settings, and deep audits that scan every file. Here's when to use each. - [How to Check if Your Joomla Site's robots.txt is Hurting Your SEO](https://mysites.guru/blog/how-to-check-joomla-robots-txt-seo/): Joomla's default robots.txt blocks media and template folders from search engines, killing your image SEO. Here's how to fix it. - [How to Verify Your Joomla Site's Email Configuration Actually Works](https://mysites.guru/blog/how-to-verify-joomla-email-configuration-works/): Joomla and WordPress contact forms can silently fail. Check SMTP settings, test mail delivery, and catch email misconfigurations across all your sites. - [How to Compare Joomla Templates Across All Your Sites](https://mysites.guru/blog/how-to-compare-joomla-templates-across-sites/): See which template every Joomla site uses, spot legacy or default templates, and export the full list as CSV from one dashboard. - [Is My WordPress Site Hacked? How to Check and What to Do Next](https://mysites.guru/blog/is-my-wordpress-site-hacked/): Think your WordPress site has been hacked? Here are the signs to look for, how to confirm it, and what to do in the first 24 hours to contain the damage. - [How to Enforce Minor Upgrades Only in WordPress](https://mysites.guru/blog/enforce-minor-upgrades-only-wordpress/): Stop WordPress from jumping major versions automatically while still getting security patches. How WP_AUTO_UPDATE_CORE works. - [How to Disable Automated Joomla Core Upgrades in Joomla 5.4+ and 6.0](https://mysites.guru/blog/how-to-disable-joomla-automated-upgrades/): Joomla 5.4 and 6.0 auto-update your site without asking. How to disable Joomla automatic updates, why agencies should, and the TUF security model behind them. - [Build a Morning Routine for Checking All Your Joomla Sites in 5 Minutes](https://mysites.guru/blog/how-to-build-morning-routine-checking-joomla-sites/): A practical morning workflow for agency owners to check uptime, backups, updates, and alerts across hundreds of Joomla sites in under 5 minutes. - [WordPress 6.9.2, 6.9.3, and 6.9.4: 10 Security Fixes, a Crash, and Incomplete Patches](https://mysites.guru/blog/wordpress-6-9-2-security-release-crashes-websites/): WordPress 6.9.2 crashed sites with a white screen, 6.9.3 fixed it, then 6.9.4 completed three missing security patches. What happened and how to recover. - [How to Disable the WordPress Admin Menu Bar on the Frontend When Logged In](https://mysites.guru/blog/disable-wordpress-admin-bar-frontend/): Remove the WordPress admin toolbar from your frontend with a per-user toggle, functions.php filter, or one click across all your sites. Code included. - [How to Prevent Accidental Joomla Version Jumps with Update Channel Management](https://mysites.guru/blog/how-to-prevent-accidental-joomla-version-jumps/): One wrong Joomla update channel setting can jump your site from Joomla 4 to 5 or 5 to 6. Here is how mySites.guru detects and prevents this. - [How to Find and Disable the Guided Tours Plugin on Your Joomla Sites](https://mysites.guru/blog/how-to-find-disable-guided-tours-plugin-joomla/): Joomla Guided Tours wastes resources on live sites. Why you should disable it in production and how mySites.guru handles it automatically. - [How to Stop Automatic Updates in WordPress with One Click](https://mysites.guru/blog/stop-automatic-updates-wordpress-one-click/): WordPress auto-updates can break plugins, themes, and layouts without warning. Control updates across all your sites from one dashboard with mySites.guru. - [Astroid Framework Vulnerability - What Happened and How to Check Your Joomla Site](https://mysites.guru/blog/astroid-framework-security-vulnerability/): CVE-2026-21628 (CVSS 10.0) - Astroid Framework for Joomla had a critical auth bypass letting attackers upload backdoors. What happened and what to do. - [Why you're getting downtime alerts (and why they matter)](https://mysites.guru/blog/uptime-monitoring-explained/): How uptime monitoring works, what triggers downtime alerts when your site seems fine, and how to monitor hundreds of sites from a single dashboard. - [How to Remove the WordPress Logo from the Admin Bar with One Click](https://mysites.guru/blog/remove-wordpress-logo-admin-bar-one-click/): The WordPress admin bar logo links to WordPress.org and identifies your CMS. Remove it in one click with mySites.guru for a white-label admin. - [How to Stop Any Plugin Installs in WordPress Admin](https://mysites.guru/blog/stop-plugin-installs-wordpress-admin/): Add DISALLOW_FILE_MODS to wp-config.php to block plugin and theme installs in WordPress admin. Code snippet, wp-cli usage, and how to enforce it. - [Hidden Files Lurking on Your Web Server](https://mysites.guru/blog/the-hidden-files-lurking-on-your-site-that-you-dont-know-about/): Your web server probably has hidden dot-files you've never seen. Some are harmless, some were left by hackers. Here's how to find them. - [mySites.guru Raycast Extension for Mac](https://mysites.guru/blog/mysites-guru-raycast-extension-for-mac/): Free Raycast extension for mySites.guru on macOS. Search your managed sites, open management pages, and copy URLs without leaving the keyboard. - [mySites.guru supports login with Passkeys](https://mysites.guru/blog/passkeys-for-secure-login-to-mysites/): mySites.guru supports login with passkeys - Face ID, Touch ID, Windows Hello, or any FIDO2 device. Faster than passwords, impossible to phish. - [AI-Powered Malware Analysis Now Available in mySites.guru](https://mysites.guru/blog/ai-powered-malware-analysis-now-available-in-mysites-guru/): Send flagged suspect files to Claude or GPT for instant malware analysis. Crowdsourced cached results shared across all subscribers. - [Joomla 6 Technical Requirements (2026)](https://mysites.guru/blog/joomla-6-technical-requirements/): Joomla 6 requires PHP 8.3+, MySQL 8.0.13+, or MariaDB 10.4+. Check if your server is ready in 30 seconds with our free bulk compatibility scanner. - [What Users Really Think of mySites.guru](https://mysites.guru/blog/mysites-guru-reviews/): What agencies and site owners actually say about managing their Joomla and WordPress sites with mySites.guru. Named reviewers only, no anonymous testimonials. - [WordPress Plugin Vulnerability Alerting](https://mysites.guru/blog/wordpress-plugin-vulnerability-alerting/): mySites.guru cross-references every WordPress plugin on your sites against Wordfence, CVE and custom threat databases, flagging vulnerable plugins instantly. - [Web Server disk space monitoring](https://mysites.guru/blog/about-the-disk-space-warnings-in-mysites-guru/): mySites.guru monitors your server's real disk partition usage twice daily and alerts you before it fills up - even if your hosting quota looks fine. - [Add unlimited Joomla and WordPress sites to mySites.guru](https://mysites.guru/blog/add-unlimited-joomla-and-wordpress-sites-to-mysites-guru/): Step-by-step guide to connecting your first Joomla or WordPress site to mySites.guru - supports unlimited sites for one flat monthly fee. - [Automatic Updates for Any Joomla Extension](https://mysites.guru/blog/automatic-updates-for-any-joomla-extension/): Enable automatic updates for any Joomla extension that uses a Joomla update site - set per-site or across all connected sites with two clicks. - [Backup 1000s of Sites from One Dashboard](https://mysites.guru/blog/backup-1000s-of-joomla-and-wordpress-sites-with-ease-with-mysites-guru/): Schedule and manage Akeeba Backup across thousands of Joomla and WordPress sites from a single mySites.guru dashboard. - [Backup All Your Sites With One Click](https://mysites.guru/blog/backup-all-your-joomla-wp-sites-easily-with-one-button-in-mysites-guru/): The one-click Backup All Sites button is back in mySites.guru, now with a per-site default backup profile to power the bulk backup queue. - [Check your site's security headers](https://mysites.guru/blog/check-your-websites-security-headers-with-mysites-guru/): mySites.guru checks eight HTTP security headers on every snapshot - CSP, HSTS, X-Frame-Options and more - to help you harden against XSS and clickjacking. - [White-Label Client Reports for Your Sites](https://mysites.guru/blog/create-custom-client-white-label-reports-for-your-joomla-and-wordpress-sites/): Build unlimited branded report templates in mySites.guru. Assign them to scheduled reports and send white-label updates directly to clients. - [End-of-Life Version Support in mySites.guru](https://mysites.guru/blog/end-of-life-supported-versions/): mySites.guru monitors end-of-life Joomla and WordPress versions from 1.5 to 6, alerting you when sites run unsupported software that puts them at risk. - [Find Hacks and Backdoors in WordPress & Joomla](https://mysites.guru/blog/find-hacked-files-and-backdoors-in-joomla-and-wordpress/): Scan your WordPress and Joomla sites for malware, backdoors, and suspicious files. Hash-based detection and 1,500+ regex patterns. - [Quick Snapshot of All Your Sites](https://mysites.guru/blog/get-a-quick-snapshot-of-your-joomla-and-wordpress-sites-with-mysites-guru/): The mySites.guru snapshot runs 140+ best-practice checks - PHP version, CMS config, security headers, SSL and more - twice a day on every connected site. - [Get Expert Help for Your Sites Instantly](https://mysites.guru/blog/get-expert-help-for-your-joomla-and-wordpress-problems-immediately/): mySites.guru subscribers get direct access to Phil Taylor for fast expert help with any Joomla or WordPress problem - set fees, no ticket queues. - [Real-Time Alerts for File Changes & Logins](https://mysites.guru/blog/get-real-time-alerting-of-modified-files-admin-logins-and-much-more-with-mysites-guru/): Get real-time email alerts when files change, admins log in, or SSL certificates near expiry across all your Joomla and WordPress sites with mySites.guru. - [Audit local sites or sites behind firewalls with mySites.guru](https://mysites.guru/blog/how-to-audit-your-local-sites-with-mysites-guru-or-behind-firewalls/): How to connect local development sites or sites behind corporate firewalls to mySites.guru using tunnelling tools like Ngrok, Expose, and Cloudflare Tunnel. - [Remove Fluff Files After Joomla Updates](https://mysites.guru/blog/how-to-automatically-remove-fluff-files-after-joomla-updates/): mySites.guru can automatically delete leftover installation folders, readme files and other fluff left behind after Joomla core updates. - [Disable "Send Copy to Submitter" in Joomla](https://mysites.guru/blog/how-to-disable-send-copy-to-submitter-in-joomla-to-prevent-spam-with-mysites-guru/): Use mySites.guru to bulk-disable the Joomla Send Copy to Submitter contact form setting across all your sites to stop it being abused for spam. - [Clean a Hacked Site with Suspect Content and Hacked Files](https://mysites.guru/blog/how-to-fix-a-hacked-joomla-or-wordpress-site-with-mysites-guru/): Use mySites.guru's Suspect Content and Hacked Files tools to find, confirm, and clean backdoors on a hacked Joomla or WordPress site, step by step. - [Fix Joomla 3 Security Issues in One Click](https://mysites.guru/blog/how-to-fix-joomla-3-security-issues-with-a-single-click/): Patch every known Joomla 3 security vulnerability across all your sites with a single toggle in mySites.guru - no manual file edits, no eLTS subscription. - [How to get mySites.guru for free - for a whole month!](https://mysites.guru/blog/how-to-get-mysites-guru-for-free-for-a-whole-month/): Apply the FIRSTMONTHFREE code to the unlimited-sites mySites.guru plan and cancel before your first renewal to use the full service free for a whole month. - [How to Hide Joomla Post Installation Messages](https://mysites.guru/blog/how-to-hide-joomla-post-installation-messages-on-1000-sites-with-one-click-with-mysites-guru/): Dismiss Joomla post-installation messages on every connected site at once using the mySites.guru bulk action - no need to log into each site individually. - [How to impersonate your mySites.guru team members](https://mysites.guru/blog/how-to-impersonate-your-mysites-guru-team-members/): Account owners can impersonate any team member inside mySites.guru to review their view and permissions without needing to share passwords. - [Install Extensions to Multiple Joomla Sites](https://mysites.guru/blog/how-to-install-an-extension-to-multiple-joomla-sites-at-once/): Push a Joomla extension install to hundreds of sites simultaneously from the mySites.guru dashboard, with full success and failure notifications per site. - [Manage and Monitor Any PHP App with mySites.guru](https://mysites.guru/blog/how-to-manage-and-monitor-any-php-application-with-mysites-guru/): The mySites app works with any PHP-based web application, not just WordPress and Joomla. Connect any PHP site to get security audits, snapshots, and alerts. - [Manage Multiple WordPress Sites Like a Pro](https://mysites.guru/blog/how-to-manage-multiple-wordpress-sites-like-a-pro/): Practical tips for managing multiple WordPress sites efficiently, covering centralised dashboards, backup strategies, security hardening and team workflows. - [Upgrade 100s of Sites from One Dashboard](https://mysites.guru/blog/how-to-mass-upgrade-joomla-and-wordpress-sites-from-one-dashboard/): Run core and extension updates across hundreds of Joomla and WordPress sites from the mySites.guru dashboard. - [Test Site Performance With Lighthouse](https://mysites.guru/blog/how-to-test-your-site-performance-with-lighthouse-audits-in-mysites-guru/): Run Google Lighthouse performance audits against any of your connected Joomla or WordPress sites directly from within the mySites.guru dashboard. - [Auto-Upgrade 1000s of Plugins & Extensions](https://mysites.guru/blog/how-to-update-joomla-joomla-extensions-wordpress-and-wordpress-plugins-from-mysites-guru/): Update Joomla extensions, WordPress plugins, and CMS cores across all your sites from one mySites.guru dashboard. Select all, click upgrade, done. - [Install Extensions to 1000+ Sites at Once](https://mysites.guru/blog/install-a-joomla-extension-or-wordpress-plugin-to-1000-sites-with-ease-using-mysites-guru/): Install any Joomla extension or WordPress plugin across 1,000 sites in one go using the mySites.guru bulk install tool - no SSH or FTP needed. - [Integrate mySites.guru to Alfred Workflow on Mac](https://mysites.guru/blog/integrate-mysites-guru-to-alfred-workflow-on-mac/): How to integrate mySites.guru with Alfred on macOS so you can jump straight to any connected site's management page from your keyboard. - [Track SSL Certificate Expirations Easily](https://mysites.guru/blog/keep-an-eye-on-your-joomla-and-wordpress-ssl-certificate-expirations-with-mysites-guru/): mySites.guru checks every site's SSL certificate issuer, expiry date and full chain validity on every snapshot, alerting you before they expire. - [Best Practice for Joomla & WordPress Sites](https://mysites.guru/blog/learn-the-best-practice-for-joomla-and-wordpress-sites-with-mysites-guru/): Every mySites.guru snapshot and audit check comes with a detailed Learn More page explaining the best practice recommendation, the risk and how to fix it. - [Manage all your Joomla Sites Extensions with mySites.guru](https://mysites.guru/blog/manage-all-your-joomla-sites-extensions-with-mysites-guru/): View, search and update every Joomla extension across all your connected sites from a single page in mySites.guru. - [Manage Multiple Sites With Your Whole Team](https://mysites.guru/blog/manage-multiple-joomla-and-wordpress-sites-with-your-whole-team/): Add unlimited team members to your mySites.guru account with per-site and per-feature permissions. No per-seat fees. - [Manage Multiple WordPress Sites](https://mysites.guru/blog/manage-multiple-wordpress-sites/): Centralise updates, backups, security audits and one-click logins across all your WordPress sites. One dashboard, unlimited sites, £19.99/month. - [Manage Your Joomla 4 Sites with mySites.guru](https://mysites.guru/blog/manage-your-joomla-4-sites-with-mysites-guru/): mySites.guru fully supports Joomla 4 with the same audit, backup, update, and monitoring toolset available for every Joomla version since 1.5. - [Migrating to Modern Joomla When Using mySites.guru](https://mysites.guru/blog/migrating-to-joomla-4-when-using-mysites-guru/): How to keep your sites connected to mySites.guru when migrating from Joomla 3 to Joomla 4, 5, or 6. Step-by-step connector swap process. - [Monitor site uptime with mySites.guru](https://mysites.guru/blog/monitor-your-sites-uptime-with-mysites-guru/): mySites.guru runs its own uptime monitoring engine with per-minute checks and instant downtime alerts at no extra cost. - [mySites.guru is the new name for rebranded myJoomla.com](https://mysites.guru/blog/myjoomla-com-is-now-mysites-guru/): myJoomla.com has been rebranded as mySites.guru to reflect full support for Joomla, WordPress and any PHP-based website in one platform. - [90,000+ Sites Trust mySites.guru](https://mysites.guru/blog/mysites-guru-connected-to-74000-joomla-and-wordpress-sites/): Over 90,000 Joomla, WordPress, and PHP sites are connected to mySites.guru - all managed from a single dashboard invested into daily by its founder. - [One-Click Admin Login to Any Site](https://mysites.guru/blog/one-click-login-to-any-joomla-or-wordpress-admin-console-with-mysites-guru/): Skip the login page entirely. One click from mySites.guru logs you straight into any Joomla or WordPress admin console - no passwords stored, fully encrypted. - [The mySites.guru Command Palette Navigation](https://mysites.guru/blog/our-command-palette-navigation-with-cmdk/): Press Cmd+K anywhere in mySites.guru to open the command palette and instantly navigate to any site, tool or account setting without touching the mouse. - [Schedule Audits, Updates & Backups](https://mysites.guru/blog/schedule-your-security-audits-updates-backups-for-your-site-with-mysites-guru/): Configure time-based and action-based schedules for security audits, snapshots, updates and Akeeba backups across all your mySites.guru connected sites. - [Deep Security Audit for WordPress & Joomla](https://mysites.guru/blog/security-audit-tools/): Surface-level scanners miss hidden malware. File-level audits check every line of code against 1,500+ patterns to find backdoors other tools miss. - [The Agency Dashboard for All Your Sites](https://mysites.guru/blog/site-information-all-in-one-place-with-mysites-guru/): The mySites.guru main dashboard surfaces SSL status, update counts, audit alerts, uptime and more for every connected Joomla or WordPress site at a glance. - [Site Management Is More Than Just Updates](https://mysites.guru/blog/site-management-is-about-more-than-just-upgrades-backups-and-uptime-monitoring/): Real site management means security audits, best practice checks, and hack detection - not just bulk updates, backups, and uptime pings. - [Tools for Managing Multiple Sites](https://mysites.guru/blog/snapshot-all-your-sites-with-one-click-at-mysites-guru-the-joomla-and-wordpress-control-panel/): The mySites.guru Snapshot All button refreshes version data, security checks and best practice results across every connected site in one click. - [The Best Multi-Site Management Dashboard](https://mysites.guru/blog/the-best-dashboard-for-unlimited-joomla-and-wordpress-sites/): Manage unlimited WordPress, Joomla and PHP sites from one secure dashboard. Security audits, backups, uptime monitoring and more for GBP 19.99/month. - [The Joomla 3.10.999 Project](https://mysites.guru/blog/the-joomla-3-10-999-project/): The Joomla 3.10.999 project backported critical security patches to end-of-life Joomla 3 sites. What it was, why it existed, and what to do now. - [Anonymize Data Before Taking Screenshots](https://mysites.guru/blog/tip-how-to-anonymize-data-before-taking-a-screenshot-of-your-mysites-guru-account/): Append ?anon=1 to any mySites.guru URL to instantly replace site names, URLs, and user data with randomised values so you can share screenshots safely. - [Top 50 Joomla Extensions in 2026](https://mysites.guru/blog/top-50-joomla-extensions/): Real-time ranking of the top 50 most-installed Joomla extensions, pulled live from the mySites.guru database of 90,000+ connected sites. - [WordPress Debug Constants Explained](https://mysites.guru/blog/understanding-wordpress-debug-constants/): WP_DEBUG_LOG writes errors to a publicly accessible file that Google has indexed on thousands of sites. Here's the fix, plus what every debug constant does. - [Universal User Management Across Sites](https://mysites.guru/blog/universal-user-management-for-joomla-and-wordpress-sites/): Search, edit, and reset passwords for users across all your Joomla and WordPress sites from one page. Manage roles, revoke access, and save hours. - [Unlimited Backup Schedules With Cron Syntax](https://mysites.guru/blog/unlimited-backup-schedules/): Create unlimited backup schedules in mySites.guru using cron syntax. Assign different Akeeba Backup profiles per schedule. - [mySites.guru No Longer Provides UptimeRobot Status Pages](https://mysites.guru/blog/uptimerobot-public-status-pages-free-for-all-mysites-guru-subscribers/): mySites.guru replaced UptimeRobot with its own uptime monitoring engine after UptimeRobot raised fees by 352%. Here's what changed. - [White-Label Activity Reports for Clients](https://mysites.guru/blog/whitelabeled-client-activity-reports-for-joomla-and-wordpress-sites/): Send automated, branded site activity reports to your clients on any schedule. Covers updates, backups, audits, uptime and more - included in every plan. - [WP Mayor's Five-Star Review of mySites.guru for WordPress](https://mysites.guru/blog/wp-mayor-review-of-mysites-guru/): WP Mayor gave mySites.guru a five-star rating after a month of hands-on testing. Here's what reviewer Kevin Wood found. - [Emails from AuditMailerTest@myjoomla.io](https://mysites.guru/blog/emails-from-auditmailertest-myjoomla-io/): Explains why you may receive test emails from AuditMailerTest@myjoomla.io and what they mean for your mySites.guru audit notifications.