Five new tools, and the Joomla 3 numbers nobody wants
Five things shipped in August, and all five are already in your dashboard. A File Manager, so touching a site's disk no longer means going to find its SFTP password first. Impostor Files, a new audit check aimed squarely at backdoors hiding in core folders. The Update Queue, which stops a big batch of updates taking a shared server down with it. A rogue Super Admin check that reads the user table on all your connected Joomla sites. And the Joomla extension vulnerability data we have been building since 2012 is now a public database, with a CVE index beside it.
Impostor Files is the one to look at first. We already had a check that lists all the files on your site that are not part of the CMS distribution. It works, and on the median site it returns 13,653 filenames. That is a haystack, and it looks the same on a clean site as it does on a hacked one. The new check reads only the folders core is responsible for. Joomla 5.4.7 puts exactly one file directly in /administrator/, and that file is index.php. Anything else sitting there arrived some other way, and that is the whole check.
There is one more post this month, and it is an uncomfortable read if you run an agency. We monitor 30,305 live Joomla 3 sites, three years past end of life and eighteen months past the last paid patch anyone could buy. They are flagged as hacked at five times the Joomla 6 rate. What I was not expecting is what has happened since to the sites that did get migrated.
All posts are free to read on the blog
|
|
The last two are the same data in two shapes. There is a page per extension with the affected version ranges we match against, and an index of over 330 CVE records grouped by the year the id was assigned. Both have their own RSS feed, so you can watch either without visiting. Where we found the flaw ourselves, the record links to the write-up we published once the developer had shipped a fix.
|
|
The long read
Joomla 3 didn't fail. Your retainer did.
One caveat belongs in front of the numbers rather than behind them. Every figure here is measured on sites connected to mySites.guru, which someone pays for monthly so that a person is watching, so this is the good end of the ecosystem. 4.90% of the Joomla 3 sites are flagged as hacked, against 0.98% on Joomla 6, and two thirds are still behind 3.10.12, the final release the project made.
Then we ran the same vulnerable-extension analysis across all the branches, and Joomla 4 came back as the worst-maintained one we track. 50.6% of those sites run at least one extension with a known hole in it, against 22.3% of the Joomla 3 sites they migrated away from. That is the version agencies moved to precisely so this would stop being a problem. Migrating is still the only real answer, so read none of this as an argument against it. The migration was a payment though, and the site is a running cost, so when the payments stopped the debt started accruing again the same week.
|
|
Need help with your site?
Phil Taylor – Fixing websites since 2004
|
Found something wrong with your Joomla or WordPress site? If it were simple, you'd have fixed it already. I offer same-day expert help at a flat rate of £120 per incident. No hourly billing surprises.
✓ Hacked or compromised sites
✓ PHP errors and white screens
✓ Upgrades and PHP 8 compatibility
✓ Performance and hosting issues
|
If I can't add value, you don't pay
|