Skip to main content
mySites.guru
New features added last monthRelease RadarFile ManagerImpostor FilesUpdate QueueRogue AdminsMCP & APIJoomla VELCVE Index

Every check we run on your sites

Connect a site and these run against it automatically: the quick configuration and header checks twice a day, the deeper file scans with the full audit, which most sites schedule weekly. This is the whole list: what each check looks at, why it matters, and where we can fix it for you without you touching the site.

Download the whole list as a printable checklist (PDF)

One row per group. A check that exists for more than one platform is a separate check on each, so the platform columns add up to the total.
GroupWhat it coversWordPressJoomlaAny PHP siteChecks
Hacked site detectionSignatures and behaviours that only appear on a compromised site: rogue admin accounts, planted editor profiles, malicious cron jobs and injected template code.1315634
Joomla configurationSettings in Joomla Global Configuration that decide how much a mistake or a break-in can cost you.054054
WordPress configurationThe wp-config.php constants and admin settings that harden a WordPress install, and the ones that quietly leave it open.410041
Security headersThe HTTP response headers a browser uses to decide what your pages are allowed to do.66820
Database integrityHow the database is named, who connects to it, and what else it can reach.57012
User accounts and accessWho can log in, how they prove it, and how many accounts nobody has used in years.1420034
Hosting environmentWhat the server underneath the site is actually running.89926
FilesFiles that should not be there, files that changed, and files that are missing.18221555
FoldersFolder permissions, writable paths, and directories left behind by an install.46313
Extensions and pluginsThe third-party code with the same privileges as the CMS itself.110011
Discussion settingsComment handling, and the settings that decide how much spam you moderate.5005
Writing settingsPost revisions, autosaves and the content the database keeps forever by default.6006
AppearanceThe active theme, and whether it is the one you think it is.1001
Search engine visibilityWhat your robots.txt allows search engines and AI answer engines to fetch, and the single stray line that can take a site out of Google altogether.89017
All groups14 groups13015841329

Signatures and behaviours that only appear on a compromised site: rogue admin accounts, planted editor profiles, malicious cron jobs and injected template code.

WordPress 13 checks

Joomla 15 checks

Any PHP site 6 checks

  • Check Suspect Patterns Matched Content In Files
  • Hacked Files (100% Certain)
  • Check Files That Can Send An Email (or Mass Emails!)
  • Check Files That Can Attempt To Upload Files
  • Check For Malicious Cron Jobs
  • Processes Running Deleted Code

Settings in Joomla Global Configuration that decide how much a mistake or a break-in can cost you.

Joomla 54 checks

  • Joomla CMS Version Must Be Up-to-date
  • Changes To Core Joomla Files Should Be Avoided
  • Disable Joomla 5.4+ Automatic Core Upgrades
  • Remove FTP Configuration From Global Config
  • Site Should Not Be Set To Offline
  • Your Favicon Should Be Changed From Default Joomla Icon
  • Joomla Global Email Configuration Should Work
  • Use A Joomla Core Or Akeeba Admin Tools .htaccess File
  • Check Files That May Need Joomla 5 Compatibility Plugin (Beta)
  • Joomla Cache Configuration Should Be Enabled
  • Log And Tmp Folders Should Use Default Locations
  • Joomla SEF Configuration Should Be Enabled
  • Disable Mail To Friend To Prevent Spam
  • Debug Mode Should Be Disabled
  • Avoid Setting $live_site Unless Absolutely Necessary
  • Admin Group Should Use Default Blacklist Text Filter
  • Disable Plain Text Password Emails
  • Disable Flash File Uploads

Joomla, continued

  • Error Reporting Should Be Set To None In Production
  • Disable Template Module Position Preview
  • Avoid Setting Cookie Domain/Path Unless Necessary
  • Enable Session Garbage Collection Plugin
  • Enable Google Recaptcha To Prevent Form Spam
  • Protect /administrator/ With .htaccess Password
  • Keep configuration.php Inside The Webroot
  • Avoid Using Default Joomla Templates
  • Session Lifetime Should Use The Default Value
  • Enable Gzip Compression
  • Enable IP Logging For User Actions
  • Publish A Privacy Policy Using Joomla Privacy Tools
  • Enable Joomla System Log Rotation
  • Set Public, Guest And Registered Groups To 'No HTML'
  • $root_user Should Not Be Defined In configuration.php
  • Debug Language Should Not Be Enabled In Production
  • Action And Hide Post Install Messages
  • Disable Send Copy To Submitter To Prevent Spam

Joomla, continued

  • Use Default Update Channel To Prevent Accidental Series Jump
  • Fix Known Joomla 3 End Of Life Security Issues
  • Disable Joomla Core Update Notification Emails
  • Disable Log Everything To Prevent Huge Log Files
  • Disable Log Deprecated To Prevent Huge Log Files
  • Use A Valid SSL Certificate To Secure Traffic
  • Investigate Locked Scheduled Tasks
  • Enable Joomla module versioning for safe rollback of module edits
  • Enable Proof-of-Work Captcha To Prevent Form Spam
  • Unblock mySites.guru IP in Akeeba Admin Tools
  • Language update sites point to the wrong Joomla version
  • Force SSL Should Be Set To Entire Site
  • Force Multi-Factor Authentication For Super Users
  • Article Options Ignored (Joomla 5.4.7 & 6.1.2)
  • Template Manager Broken (Joomla 5.4.8 & 6.1.3)
  • Don't Share Site & Admin Sessions
  • Site Time & Timezone Configuration
  • Ensure Joomla Configuration Secret String Is Set and Secure

The wp-config.php constants and admin settings that harden a WordPress install, and the ones that quietly leave it open.

WordPress 41 checks

  • Changes To Core WordPress Files Should Be Avoided
  • WordPress Version Must Be Up-to-date
  • Use A Valid SSL Certificate To Secure Traffic
  • WordPress Address Should Normally Equal Site Address
  • Password Protect WP-Admin
  • WordPress Email Configuration Should Work
  • Disable XML-RPC in WordPress
  • Allow Search Engines To Index This Site
  • Avoid Using Default Distributed Salt Values
  • Remove Default Tagline "Just Another WordPress Site"
  • Remove The Default "Sample Page"
  • Remove The Default "Hello World!" Post
  • Config Constant: Disable WP_DEBUG In Production
  • Config Constant: Disable WP_DEBUG_LOG In Production

WordPress, continued

  • Config Constant: Disable WP_DEBUG_DISPLAY In Production
  • Config Constant: Disable File Editing Through Admin Console with DISALLOW_FILE_EDIT
  • Config Constant: Enable FORCE_SSL_ADMIN to secure admin connections
  • Config Constant: Enable FORCE_SSL_LOGIN to secure login connections (@Deprecated)
  • Config Constant: Prohibit Database Repair with WP_ALLOW_REPAIR constant
  • Config Constant: Disallow Unfiltered Content with DISALLOW_UNFILTERED_HTML
  • Config Constant: Disable unfiltered file uploads with ALLOW_UNFILTERED_UPLOADS
  • Config Constant: Enable Auto Upgrades with AUTOMATIC_UPDATER_DISABLED constant
  • Config Constant: Enable Minor Upgrades only with WP_AUTO_UPDATE_CORE constant
  • Config Constant: Disable Plugin Installs with DISALLOW_FILE_MODS constant
  • Config Constant: Disable Script debugging with SCRIPT_DEBUG constant
  • Config Constant: Disable save queries debug with SAVEQUERIES constant
  • Config Constant: Enable WP_POST_REVISIONS to limit number of revisions saved to 10
  • Config Constant: Set AUTOSAVE_INTERVAL to 30 seconds to prevent data loss

WordPress, continued

  • Disable Emojis
  • Remove jQuery Migrate Script
  • Remove WordPress Admin Footer Banner
  • Remove WordPress & Plugin Generator Tags And Version Numbers
  • Remove post shortlink head tags
  • Remove WordPress Logo Menu top left of Admin Console
  • Disable WordPress Application Passwords for APIs
  • Disable Links In User Comments To Prevent Spam
  • Disable the "Howdy," greeting
  • Remove Plugin Admin Nag Screens
  • Disable Frontend Menu Bar When Logged In
  • Config Constant: Disable WP_AI_SUPPORT to turn off WordPress AI features
  • Site Time & Timezone Configuration

The HTTP response headers a browser uses to decide what your pages are allowed to do.

WordPress 6 checks

  • Permissions-Policy Controls Which Features Can Be Used In The Browser
  • Remove Deprecated Feature-Policy Header
  • Referrer-Policy Sets How Much Info Is Leaked When Linking Off Site
  • Strict-Transport-Security (HSTS) Enforces The Use Of HTTPS
  • X-Content-Type-Options Stops Browsers MIME Sniffing The Content Type
  • X-Frame-Options Controls Whether Your Site Can Be Framed

Joomla 6 checks

Any PHP site 8 checks

  • Content-Security-Policy Header Blocks Attacks
  • Expect-CT Tells Browsers To Expect Certificate Transparency
  • Permissions-Policy Controls Which Features Can Be Used In The Browser
  • Remove Deprecated Feature-Policy Header
  • Referrer-Policy Sets How Much Info Is Leaked When Linking Off Site
  • Strict-Transport-Security (HSTS) Enforces The Use Of HTTPS
  • X-Content-Type-Options Stops Browsers MIME Sniffing The Content Type
  • X-Frame-Options Controls Whether Your Site Can Be Framed

How the database is named, who connects to it, and what else it can reach.

WordPress 5 checks

  • Default Database Prefix Should Not Be Set As wp_
  • Database User Should Not Be "root"
  • DB User Should Only Have Access To One Database
  • The mySites.guru Activity Log Table Should Not Grow Unchecked
  • Pending Database Migrations

Joomla 7 checks

Who can log in, how they prove it, and how many accounts nobody has used in years.

WordPress 14 checks

  • "Anyone can register" should be disabled unless required
  • New User Default Role Should Not Be Administrator
  • Limit The Number Of Administrators To One
  • Avoid Using "admin" As A Username
  • Users With Application Or API Passwords
  • Inactive Users (180+ Days)
  • Unactivated Users
  • Blocked Users
  • Avoid MD5 Hashed Passwords (May Indicate Hacked Site)
  • Privacy: Keep Pending Export Requests At Zero
  • Privacy: Keep Pending Remove Requests At Zero
  • Privacy: Remove Completed Export Requests
  • Privacy: Remove Completed Remove Requests
  • Users With No Role

Joomla 20 checks

What the server underneath the site is actually running.

WordPress 8 checks

  • PHP Version Should Be Latest Supported Series
  • PHP Safe Mode Should Be Off
  • PHP Display Errors Configuration Should Be Off
  • PHP Register Globals Should Be Off
  • PHP File Uploads Should Be Enabled
  • PHP Magic Quotes Should Be Off
  • PHP Session Path Should Be Writable
  • PHP Disabled Functions Should Be Minimised

Joomla 9 checks

  • PHP Version Should Be Latest Supported Series
  • PHP Safe Mode Should Be Off
  • PHP Display Errors Configuration Should Be Off
  • PHP Register Globals Should Be Off
  • PHP File Uploads Should Be Enabled
  • PHP Magic Quotes Should Be Off
  • PHP Session Path Should Be Writable
  • PHP Disabled Functions Should Be Minimised
  • PHP Extension fileinfo Must Be Installed For Media Manager

Any PHP site 9 checks

  • PHP Version Should Be Latest Supported Series
  • PHP Safe Mode Should Be Off
  • PHP Display Errors Configuration Should Be Off
  • PHP Register Globals Should Be Off
  • PHP File Uploads Should Be Enabled
  • PHP Magic Quotes Should Be Off
  • PHP Session Path Should Be Writable
  • PHP Disabled Functions Should Be Minimised
  • Site Time & Timezone Configuration

Files

55 checks

Files that should not be there, files that changed, and files that are missing.

WordPress 18 checks

  • Files That Could Not Be Audited, Review Manually
  • Files Modified In Last Three Days
  • Multiple .htaccess Files Located In Webspace
  • File Permissions Of 777 Should Be Avoided
  • PHP error_log Files Should Be Reviewed And Deleted
  • Zend/ionCube Encrypted Files Should Be Avoided
  • Locate And Review Hidden Files ("dot Files", .DS_Store Etc)
  • Investigate And Remove /wp-content/debug.log
  • Locate And Review Archive Files (Zip, Tar.gz, Etc)
  • Locate And Review Files Over 2Mb Size
  • Review Renamed Files (.old, .bak, .orig)
  • PHP Files Should Not Be In These Certain Folders
  • Locate And Review Any SQL Files That Are Publicly Available
  • "php.ini" and ".user.ini" Override Files Located In Webspace
  • Identify Files With No Content (Zero Bytes In Size)
  • Files Modified Between Audits
  • Identify Missing Core WordPress Files
  • Locate And Review Double Extension Files (name.php.xxx)

Joomla 22 checks

  • Files That Could Not Be Audited, Review Manually
  • Remove Unneeded Joomla Core "fluff"
  • Uploaded Tmp Files/Folders Should Be Removed
  • Akeeba Kickstart Should Not Be Left In Webspace
  • Files Modified In Last Three Days
  • Forum Post Assistant Should Not Be Left In Webspace
  • Multiple .htaccess Files Located In Webspace
  • File Permissions Of 777 Should Be Avoided
  • PHP error_log Files Should Be Reviewed And Deleted
  • Zend/ionCube Encrypted Files Should Be Avoided
  • Locate And Review Hidden Files ("dot Files", .DS_Store Etc)
  • Locate And Review Archive Files (Zip, Tar.gz, Etc)
  • Locate And Review Files Over 2Mb Size
  • Review Renamed Files (.old, .bak, .orig)
  • PHP Files Should Not Be In These Certain Folders
  • Locate And Review Any SQL Files That Are Publicly Available
  • Locate And Review Any admintool_breaches.log Files
  • "php.ini" and ".user.ini" Override Files Located In Webspace
  • Identify Files With No Content (Zero Bytes In Size)
  • Files Modified Between Audits
  • Identify Missing Core Joomla Files
  • Locate And Review Double Extension Files (name.php.xxx)

Any PHP site 15 checks

  • Files That Could Not Be Audited, Review Manually
  • Files Modified In Last Three Days
  • Multiple .htaccess Files Located In Webspace
  • File Permissions Of 777 Should Be Avoided
  • PHP error_log Files Should Be Reviewed And Deleted
  • Zend/ionCube Encrypted Files Should Be Avoided
  • Locate And Review Hidden Files ("dot Files", .DS_Store Etc)
  • Locate And Review Archive Files (Zip, Tar.gz, Etc)
  • Locate And Review Files Over 2Mb Size
  • Review Renamed Files (.old, .bak, .orig)
  • PHP Files Should Not Be In These Certain Folders
  • Locate And Review Any SQL Files That Are Publicly Available
  • "php.ini" and ".user.ini" Override Files Located In Webspace
  • Identify Files With No Content (Zero Bytes In Size)
  • Files Modified Between Audits

Folders

13 checks

Folder permissions, writable paths, and directories left behind by an install.

WordPress 4 checks

  • Folder Permissions That Should Be Avoided
  • Paths With Hidden Folders In Them
  • One Webspace Should Contain One Website Installation
  • Fix File & Folder Permissions

Joomla 6 checks

  • Folder Permissions That Should Be Avoided
  • Installation Folders Should Be Deleted
  • Paths With Hidden Folders In Them
  • "tmp/logs" Folders Should Be Writable
  • One Webspace Should Contain One Website Installation
  • Fix File & Folder Permissions

Any PHP site 3 checks

  • Folder Permissions That Should Be Avoided
  • Paths With Hidden Folders In Them
  • Fix File & Folder Permissions

The third-party code with the same privileges as the CMS itself.

WordPress 1 check

  • Delete Files For Deactivated Plugins

Joomla 10 checks

  • Privacy: Publish Privacy Consent Plugin
  • User Action Log Plugins Should Be Enabled
  • Disable Joomla Guided Tours In Production
  • Enable Image Thumbnails To Speed Up Media Manager In Joomla 4.3+
  • "Behaviour - Backward Compatibility 6" Plugin (plg_behaviour_compat6, J5 Classes) - Warning! LEARN before disabling!
  • "Behaviour - Backward Compatibility" Plugin (plg_behaviour_compat, J4 Classes) - Warning! LEARN before disabling!
  • Disable Sample Data In Production
  • Joomla Redirect Plugin Should Be Enabled If You Use Redirects
  • Stop The Redirect Plugin Recording Every 404 URL
  • Recorded 404 URLs Should Not Pile Up

Comment handling, and the settings that decide how much spam you moderate.

WordPress 5 checks

  • Disable Comments On New Articles
  • Require Comment Author Name And Email
  • Require Registration And Login To Comment
  • Keep Comments Requiring Moderation At Zero
  • Keep Trashed Comments At Zero

Post revisions, autosaves and the content the database keeps forever by default.

WordPress 6 checks

  • Default Post Category Should Not Be Uncategorised
  • Remove Post Via Email Settings Unless Required
  • Remove Old Post Revisions From The Database
  • Remove Auto-Save Revisions From The Database
  • Remove Trashed Posts And Pages From The Database
  • Remove Draft Posts And Pages From The Database

Appearance

1 check

The active theme, and whether it is the one you think it is.

WordPress 1 check

  • Avoid Using Default WordPress Themes

What your robots.txt allows search engines and AI answer engines to fetch, and the single stray line that can take a site out of Google altogether.

WordPress 8 checks

  • Your robots.txt Should Not Block Every Crawler
  • Your robots.txt Should Not Block Search Engines
  • Your robots.txt Should Not Block AI Answer Engines
  • Your robots.txt Should Be Reachable
  • Your robots.txt Must Sit At The Domain Root
  • Your robots.txt Should Point Crawlers At Your Sitemap
  • Your AI Training And Answer Engine Policy
  • Your robots.txt May Be Managed Somewhere Else

Joomla 9 checks

  • Your robots.txt Should Not Block Every Crawler
  • Your robots.txt Should Not Block Search Engines
  • Your robots.txt Should Not Block AI Answer Engines
  • Your robots.txt Should Be Reachable
  • Your robots.txt Must Sit At The Domain Root
  • Your robots.txt Should Point Crawlers At Your Sitemap
  • Your AI Training And Answer Engine Policy
  • Your robots.txt May Be Managed At The Edge
  • Robots.txt Should Not Block Media & Template Folders

Connect a site and every one of these runs on it.

Free on one WordPress, Joomla or any PHP site, no card. Read the report, then fix what it finds: 67 of these checks can be put right across every connected site with one click.

Run a free audit