Every check we run on your sites
Connect a site and these run against it automatically: the quick configuration and header checks twice a day, the deeper file scans with the full audit, which most sites schedule weekly. This is the whole list: what each check looks at, why it matters, and where we can fix it for you without you touching the site.
Download the whole list as a printable checklist (PDF)
- 329 checks, every one of them on this page
- 67 fixable across every connected site in one click
- 48 with a full write-up
| Group | What it covers | WordPress | Joomla | Any PHP site | Checks |
|---|---|---|---|---|---|
| Hacked site detection | Signatures and behaviours that only appear on a compromised site: rogue admin accounts, planted editor profiles, malicious cron jobs and injected template code. | 13 | 15 | 6 | 34 |
| Joomla configuration | Settings in Joomla Global Configuration that decide how much a mistake or a break-in can cost you. | 0 | 54 | 0 | 54 |
| WordPress configuration | The wp-config.php constants and admin settings that harden a WordPress install, and the ones that quietly leave it open. | 41 | 0 | 0 | 41 |
| Security headers | The HTTP response headers a browser uses to decide what your pages are allowed to do. | 6 | 6 | 8 | 20 |
| Database integrity | How the database is named, who connects to it, and what else it can reach. | 5 | 7 | 0 | 12 |
| User accounts and access | Who can log in, how they prove it, and how many accounts nobody has used in years. | 14 | 20 | 0 | 34 |
| Hosting environment | What the server underneath the site is actually running. | 8 | 9 | 9 | 26 |
| Files | Files that should not be there, files that changed, and files that are missing. | 18 | 22 | 15 | 55 |
| Folders | Folder permissions, writable paths, and directories left behind by an install. | 4 | 6 | 3 | 13 |
| Extensions and plugins | The third-party code with the same privileges as the CMS itself. | 1 | 10 | 0 | 11 |
| Discussion settings | Comment handling, and the settings that decide how much spam you moderate. | 5 | 0 | 0 | 5 |
| Writing settings | Post revisions, autosaves and the content the database keeps forever by default. | 6 | 0 | 0 | 6 |
| Appearance | The active theme, and whether it is the one you think it is. | 1 | 0 | 0 | 1 |
| Search engine visibility | What your robots.txt allows search engines and AI answer engines to fetch, and the single stray line that can take a site out of Google altogether. | 8 | 9 | 0 | 17 |
| All groups | 14 groups | 130 | 158 | 41 | 329 |
Hacked site detection
34 checksSignatures and behaviours that only appear on a compromised site: rogue admin accounts, planted editor profiles, malicious cron jobs and injected template code.
WordPress 13 checks
- Check Suspect Patterns Matched Content In Files
- Hacked Files (100% Certain)
- Check Files That Can Send An Email (or Mass Emails!)
- Check Files That Can Attempt To Upload Files
- Check Files That Are Not Core Files
- Check Core WordPress Folders For Impostor Files
- Check For Malicious Cron Jobs
- Check For Malicious WP-Cron Events
- Suspect WP Options
- Must-Use Plugins and Drop-ins
- Rogue and Hidden Administrators
- Impostor Plugin Identities
- Processes Running Deleted Code
Joomla 15 checks
- Check for JCE Rogue Profiles & Backdoors
- Check Suspect Patterns Matched Content In Files
- Hacked Files (100% Certain)
- Rogue Super Admin Accounts
- Check Files That Can Send An Email (or Mass Emails!)
- Check Files That Can Attempt To Upload Files
- Helix3 Custom Code Hack
- Check Files That Are Not Core Files
- SP Page Builder Rogue Icon-Font Assets
- Check Core Folders For Impostor Files
- Helix Ultimate Mega Menu Hack
- Unpatched JoomShaper Security Holes
- Check For Malicious Cron Jobs
- Check For Malicious Scheduled Tasks
- Processes Running Deleted Code
Any PHP site 6 checks
- Check Suspect Patterns Matched Content In Files
- Hacked Files (100% Certain)
- Check Files That Can Send An Email (or Mass Emails!)
- Check Files That Can Attempt To Upload Files
- Check For Malicious Cron Jobs
- Processes Running Deleted Code
Joomla configuration
54 checksSettings in Joomla Global Configuration that decide how much a mistake or a break-in can cost you.
Joomla 54 checks
- Joomla CMS Version Must Be Up-to-date
- Changes To Core Joomla Files Should Be Avoided
- Disable Joomla 5.4+ Automatic Core Upgrades
- Remove FTP Configuration From Global Config
- Site Should Not Be Set To Offline
- Your Favicon Should Be Changed From Default Joomla Icon
- Joomla Global Email Configuration Should Work
- Use A Joomla Core Or Akeeba Admin Tools .htaccess File
- Check Files That May Need Joomla 5 Compatibility Plugin (Beta)
- Joomla Cache Configuration Should Be Enabled
- Log And Tmp Folders Should Use Default Locations
- Joomla SEF Configuration Should Be Enabled
- Disable Mail To Friend To Prevent Spam
- Debug Mode Should Be Disabled
- Avoid Setting $live_site Unless Absolutely Necessary
- Admin Group Should Use Default Blacklist Text Filter
- Disable Plain Text Password Emails
- Disable Flash File Uploads
Joomla, continued
- Error Reporting Should Be Set To None In Production
- Disable Template Module Position Preview
- Avoid Setting Cookie Domain/Path Unless Necessary
- Enable Session Garbage Collection Plugin
- Enable Google Recaptcha To Prevent Form Spam
- Protect /administrator/ With .htaccess Password
- Keep configuration.php Inside The Webroot
- Avoid Using Default Joomla Templates
- Session Lifetime Should Use The Default Value
- Enable Gzip Compression
- Enable IP Logging For User Actions
- Publish A Privacy Policy Using Joomla Privacy Tools
- Enable Joomla System Log Rotation
- Set Public, Guest And Registered Groups To 'No HTML'
- $root_user Should Not Be Defined In configuration.php
- Debug Language Should Not Be Enabled In Production
- Action And Hide Post Install Messages
- Disable Send Copy To Submitter To Prevent Spam
Joomla, continued
- Use Default Update Channel To Prevent Accidental Series Jump
- Fix Known Joomla 3 End Of Life Security Issues
- Disable Joomla Core Update Notification Emails
- Disable Log Everything To Prevent Huge Log Files
- Disable Log Deprecated To Prevent Huge Log Files
- Use A Valid SSL Certificate To Secure Traffic
- Investigate Locked Scheduled Tasks
- Enable Joomla module versioning for safe rollback of module edits
- Enable Proof-of-Work Captcha To Prevent Form Spam
- Unblock mySites.guru IP in Akeeba Admin Tools
- Language update sites point to the wrong Joomla version
- Force SSL Should Be Set To Entire Site
- Force Multi-Factor Authentication For Super Users
- Article Options Ignored (Joomla 5.4.7 & 6.1.2)
- Template Manager Broken (Joomla 5.4.8 & 6.1.3)
- Don't Share Site & Admin Sessions
- Site Time & Timezone Configuration
- Ensure Joomla Configuration Secret String Is Set and Secure
WordPress configuration
41 checksThe wp-config.php constants and admin settings that harden a WordPress install, and the ones that quietly leave it open.
WordPress 41 checks
- Changes To Core WordPress Files Should Be Avoided
- WordPress Version Must Be Up-to-date
- Use A Valid SSL Certificate To Secure Traffic
- WordPress Address Should Normally Equal Site Address
- Password Protect WP-Admin
- WordPress Email Configuration Should Work
- Disable XML-RPC in WordPress
- Allow Search Engines To Index This Site
- Avoid Using Default Distributed Salt Values
- Remove Default Tagline "Just Another WordPress Site"
- Remove The Default "Sample Page"
- Remove The Default "Hello World!" Post
- Config Constant: Disable WP_DEBUG In Production
- Config Constant: Disable WP_DEBUG_LOG In Production
WordPress, continued
- Config Constant: Disable WP_DEBUG_DISPLAY In Production
- Config Constant: Disable File Editing Through Admin Console with DISALLOW_FILE_EDIT
- Config Constant: Enable FORCE_SSL_ADMIN to secure admin connections
- Config Constant: Enable FORCE_SSL_LOGIN to secure login connections (@Deprecated)
- Config Constant: Prohibit Database Repair with WP_ALLOW_REPAIR constant
- Config Constant: Disallow Unfiltered Content with DISALLOW_UNFILTERED_HTML
- Config Constant: Disable unfiltered file uploads with ALLOW_UNFILTERED_UPLOADS
- Config Constant: Enable Auto Upgrades with AUTOMATIC_UPDATER_DISABLED constant
- Config Constant: Enable Minor Upgrades only with WP_AUTO_UPDATE_CORE constant
- Config Constant: Disable Plugin Installs with DISALLOW_FILE_MODS constant
- Config Constant: Disable Script debugging with SCRIPT_DEBUG constant
- Config Constant: Disable save queries debug with SAVEQUERIES constant
- Config Constant: Enable WP_POST_REVISIONS to limit number of revisions saved to 10
- Config Constant: Set AUTOSAVE_INTERVAL to 30 seconds to prevent data loss
WordPress, continued
- Disable Emojis
- Remove jQuery Migrate Script
- Remove WordPress Admin Footer Banner
- Remove WordPress & Plugin Generator Tags And Version Numbers
- Remove post shortlink head tags
- Remove WordPress Logo Menu top left of Admin Console
- Disable WordPress Application Passwords for APIs
- Disable Links In User Comments To Prevent Spam
- Disable the "Howdy," greeting
- Remove Plugin Admin Nag Screens
- Disable Frontend Menu Bar When Logged In
- Config Constant: Disable WP_AI_SUPPORT to turn off WordPress AI features
- Site Time & Timezone Configuration
Security headers
20 checksThe HTTP response headers a browser uses to decide what your pages are allowed to do.
WordPress 6 checks
- Permissions-Policy Controls Which Features Can Be Used In The Browser
- Remove Deprecated Feature-Policy Header
- Referrer-Policy Sets How Much Info Is Leaked When Linking Off Site
- Strict-Transport-Security (HSTS) Enforces The Use Of HTTPS
- X-Content-Type-Options Stops Browsers MIME Sniffing The Content Type
- X-Frame-Options Controls Whether Your Site Can Be Framed
Joomla 6 checks
- Permissions-Policy Controls Which Features Can Be Used In The Browser
- Remove Deprecated Feature-Policy Header
- Referrer-Policy Sets How Much Info Is Leaked When Linking Off Site
- Strict-Transport-Security (HSTS) Enforces The Use Of HTTPS
- X-Content-Type-Options Stops Browsers MIME Sniffing The Content Type
- X-Frame-Options Controls Whether Your Site Can Be Framed
Any PHP site 8 checks
- Content-Security-Policy Header Blocks Attacks
- Expect-CT Tells Browsers To Expect Certificate Transparency
- Permissions-Policy Controls Which Features Can Be Used In The Browser
- Remove Deprecated Feature-Policy Header
- Referrer-Policy Sets How Much Info Is Leaked When Linking Off Site
- Strict-Transport-Security (HSTS) Enforces The Use Of HTTPS
- X-Content-Type-Options Stops Browsers MIME Sniffing The Content Type
- X-Frame-Options Controls Whether Your Site Can Be Framed
Database integrity
12 checksHow the database is named, who connects to it, and what else it can reach.
WordPress 5 checks
- Default Database Prefix Should Not Be Set As wp_
- Database User Should Not Be "root"
- DB User Should Only Have Access To One Database
- The mySites.guru Activity Log Table Should Not Grow Unchecked
- Pending Database Migrations
Joomla 7 checks
- Default Database Prefix Should Not Be Set As jos_
- Database User Should Not Be "root"
- DB User Should Only Have Access To One Database
- Backup Tables Should Be Removed From Database
- Joomla Core Database Schema Should Match Installed Joomla Version
- Expire Old User Action Log Entries
- Action Log Tables Should Not Grow Unchecked
User accounts and access
34 checksWho can log in, how they prove it, and how many accounts nobody has used in years.
WordPress 14 checks
- "Anyone can register" should be disabled unless required
- New User Default Role Should Not Be Administrator
- Limit The Number Of Administrators To One
- Avoid Using "admin" As A Username
- Users With Application Or API Passwords
- Inactive Users (180+ Days)
- Unactivated Users
- Blocked Users
- Avoid MD5 Hashed Passwords (May Indicate Hacked Site)
- Privacy: Keep Pending Export Requests At Zero
- Privacy: Keep Pending Remove Requests At Zero
- Privacy: Remove Completed Export Requests
- Privacy: Remove Completed Remove Requests
- Users With No Role
Joomla 20 checks
- Super Admin Should Not Have Username "admin"
- Avoid MD5 Hashed Passwords (May Indicate Hacked Site)
- Enable Two-Factor Authentication Plugins
- Disable User Registration Unless Required
- Default Group For New Users Should Not Be Admin Or Super Admin
- Limit The Number Of Super Admins To One
- Use Two-Factor Authentication On All Super User Accounts
- Check For Joomla.user.helper.XXXX Usernames (2016 Hack Indicator)
- Remove "Never Logged In" Accounts
- Inactive Users (180+ Days)
- Unactivated Users
- Blocked Users
- Privacy: Review Overdue Privacy Requests
- Privacy: Review Pending Export Requests
- Privacy: Review Pending Remove Requests
- Privacy: Process Confirmed Export Requests
- Privacy: Process Confirmed Remove Requests
- Privacy: Remove Completed Export Requests
- Privacy: Remove Completed Remove Requests
- Users In No User Group
Hosting environment
26 checksWhat the server underneath the site is actually running.
WordPress 8 checks
- PHP Version Should Be Latest Supported Series
- PHP Safe Mode Should Be Off
- PHP Display Errors Configuration Should Be Off
- PHP Register Globals Should Be Off
- PHP File Uploads Should Be Enabled
- PHP Magic Quotes Should Be Off
- PHP Session Path Should Be Writable
- PHP Disabled Functions Should Be Minimised
Joomla 9 checks
- PHP Version Should Be Latest Supported Series
- PHP Safe Mode Should Be Off
- PHP Display Errors Configuration Should Be Off
- PHP Register Globals Should Be Off
- PHP File Uploads Should Be Enabled
- PHP Magic Quotes Should Be Off
- PHP Session Path Should Be Writable
- PHP Disabled Functions Should Be Minimised
- PHP Extension fileinfo Must Be Installed For Media Manager
Any PHP site 9 checks
- PHP Version Should Be Latest Supported Series
- PHP Safe Mode Should Be Off
- PHP Display Errors Configuration Should Be Off
- PHP Register Globals Should Be Off
- PHP File Uploads Should Be Enabled
- PHP Magic Quotes Should Be Off
- PHP Session Path Should Be Writable
- PHP Disabled Functions Should Be Minimised
- Site Time & Timezone Configuration
Files
55 checksFiles that should not be there, files that changed, and files that are missing.
WordPress 18 checks
- Files That Could Not Be Audited, Review Manually
- Files Modified In Last Three Days
- Multiple .htaccess Files Located In Webspace
- File Permissions Of 777 Should Be Avoided
- PHP error_log Files Should Be Reviewed And Deleted
- Zend/ionCube Encrypted Files Should Be Avoided
- Locate And Review Hidden Files ("dot Files", .DS_Store Etc)
- Investigate And Remove /wp-content/debug.log
- Locate And Review Archive Files (Zip, Tar.gz, Etc)
- Locate And Review Files Over 2Mb Size
- Review Renamed Files (.old, .bak, .orig)
- PHP Files Should Not Be In These Certain Folders
- Locate And Review Any SQL Files That Are Publicly Available
- "php.ini" and ".user.ini" Override Files Located In Webspace
- Identify Files With No Content (Zero Bytes In Size)
- Files Modified Between Audits
- Identify Missing Core WordPress Files
- Locate And Review Double Extension Files (name.php.xxx)
Joomla 22 checks
- Files That Could Not Be Audited, Review Manually
- Remove Unneeded Joomla Core "fluff"
- Uploaded Tmp Files/Folders Should Be Removed
- Akeeba Kickstart Should Not Be Left In Webspace
- Files Modified In Last Three Days
- Forum Post Assistant Should Not Be Left In Webspace
- Multiple .htaccess Files Located In Webspace
- File Permissions Of 777 Should Be Avoided
- PHP error_log Files Should Be Reviewed And Deleted
- Zend/ionCube Encrypted Files Should Be Avoided
- Locate And Review Hidden Files ("dot Files", .DS_Store Etc)
- Locate And Review Archive Files (Zip, Tar.gz, Etc)
- Locate And Review Files Over 2Mb Size
- Review Renamed Files (.old, .bak, .orig)
- PHP Files Should Not Be In These Certain Folders
- Locate And Review Any SQL Files That Are Publicly Available
- Locate And Review Any admintool_breaches.log Files
- "php.ini" and ".user.ini" Override Files Located In Webspace
- Identify Files With No Content (Zero Bytes In Size)
- Files Modified Between Audits
- Identify Missing Core Joomla Files
- Locate And Review Double Extension Files (name.php.xxx)
Any PHP site 15 checks
- Files That Could Not Be Audited, Review Manually
- Files Modified In Last Three Days
- Multiple .htaccess Files Located In Webspace
- File Permissions Of 777 Should Be Avoided
- PHP error_log Files Should Be Reviewed And Deleted
- Zend/ionCube Encrypted Files Should Be Avoided
- Locate And Review Hidden Files ("dot Files", .DS_Store Etc)
- Locate And Review Archive Files (Zip, Tar.gz, Etc)
- Locate And Review Files Over 2Mb Size
- Review Renamed Files (.old, .bak, .orig)
- PHP Files Should Not Be In These Certain Folders
- Locate And Review Any SQL Files That Are Publicly Available
- "php.ini" and ".user.ini" Override Files Located In Webspace
- Identify Files With No Content (Zero Bytes In Size)
- Files Modified Between Audits
Folders
13 checksFolder permissions, writable paths, and directories left behind by an install.
WordPress 4 checks
- Folder Permissions That Should Be Avoided
- Paths With Hidden Folders In Them
- One Webspace Should Contain One Website Installation
- Fix File & Folder Permissions
Joomla 6 checks
- Folder Permissions That Should Be Avoided
- Installation Folders Should Be Deleted
- Paths With Hidden Folders In Them
- "tmp/logs" Folders Should Be Writable
- One Webspace Should Contain One Website Installation
- Fix File & Folder Permissions
Any PHP site 3 checks
- Folder Permissions That Should Be Avoided
- Paths With Hidden Folders In Them
- Fix File & Folder Permissions
Extensions and plugins
11 checksThe third-party code with the same privileges as the CMS itself.
WordPress 1 check
- Delete Files For Deactivated Plugins
Joomla 10 checks
- Privacy: Publish Privacy Consent Plugin
- User Action Log Plugins Should Be Enabled
- Disable Joomla Guided Tours In Production
- Enable Image Thumbnails To Speed Up Media Manager In Joomla 4.3+
- "Behaviour - Backward Compatibility 6" Plugin (plg_behaviour_compat6, J5 Classes) - Warning! LEARN before disabling!
- "Behaviour - Backward Compatibility" Plugin (plg_behaviour_compat, J4 Classes) - Warning! LEARN before disabling!
- Disable Sample Data In Production
- Joomla Redirect Plugin Should Be Enabled If You Use Redirects
- Stop The Redirect Plugin Recording Every 404 URL
- Recorded 404 URLs Should Not Pile Up
Discussion settings
5 checksComment handling, and the settings that decide how much spam you moderate.
WordPress 5 checks
- Disable Comments On New Articles
- Require Comment Author Name And Email
- Require Registration And Login To Comment
- Keep Comments Requiring Moderation At Zero
- Keep Trashed Comments At Zero
Writing settings
6 checksPost revisions, autosaves and the content the database keeps forever by default.
WordPress 6 checks
- Default Post Category Should Not Be Uncategorised
- Remove Post Via Email Settings Unless Required
- Remove Old Post Revisions From The Database
- Remove Auto-Save Revisions From The Database
- Remove Trashed Posts And Pages From The Database
- Remove Draft Posts And Pages From The Database
Appearance
1 checkThe active theme, and whether it is the one you think it is.
WordPress 1 check
- Avoid Using Default WordPress Themes
Search engine visibility
17 checksWhat your robots.txt allows search engines and AI answer engines to fetch, and the single stray line that can take a site out of Google altogether.
WordPress 8 checks
- Your robots.txt Should Not Block Every Crawler
- Your robots.txt Should Not Block Search Engines
- Your robots.txt Should Not Block AI Answer Engines
- Your robots.txt Should Be Reachable
- Your robots.txt Must Sit At The Domain Root
- Your robots.txt Should Point Crawlers At Your Sitemap
- Your AI Training And Answer Engine Policy
- Your robots.txt May Be Managed Somewhere Else
Joomla 9 checks
- Your robots.txt Should Not Block Every Crawler
- Your robots.txt Should Not Block Search Engines
- Your robots.txt Should Not Block AI Answer Engines
- Your robots.txt Should Be Reachable
- Your robots.txt Must Sit At The Domain Root
- Your robots.txt Should Point Crawlers At Your Sitemap
- Your AI Training And Answer Engine Policy
- Your robots.txt May Be Managed At The Edge
- Robots.txt Should Not Block Media & Template Folders
Connect a site and every one of these runs on it.
Free on one WordPress, Joomla or any PHP site, no card. Read the report, then fix what it finds: 67 of these checks can be put right across every connected site with one click.