Joomla's core is solid, the trouble starts with extensions
Joomla has a reputation as a secure system, and rightly so. The team quickly patches the core and releases urgent fixes. The problem is that a site is not just the core. It is also extensions: builders, galleries, forms, stores. And those are the most common route for a break-in.
Where the risk lies
Extensions are written by many different authors, with varying levels of care. Some are developed for years, some abandoned after a year. When a flaw appears in such an add-on and the author no longer updates it, the fix never comes and the site is left exposed.
High-profile flaws in Joomla extensions, such as the dangerous bug in the JCE editor or in the SP Page Builder, show the same pattern: attackers target popular add-ons, because one exploit works on thousands of sites at once.
What to do
- Update extensions as urgently as the core, they are the most common way in.
- Remove add-ons you do not use. Even disabled ones can be vulnerable.
- Only install extensions from trusted sources and check that they are still being developed.
- Look at the official list of vulnerable extensions that Joomla maintains.
Keeping an eye on the health of a dozen extensions is daily, tedious work. As part of our care service we do it for you, get in touch.