White paper: Joomla! Health Check

Rate this item
(5 votes)

How do you know if your Joomla! website is being run effectively?  Have you had a Joomla! site created but not sure whether the security is up to scratch?  This article aims to give some tips to check against your website, which are drawn from standard security and 'best practice' guidelines.  If you have any other points you think we should add, please leave a comment!

    1. Can you navigate to www.yoursite.co.uk/administrator and get to the Administrator screen?

      Yes? This should be hidden and/or password protected, to stop people accessing your administrator portal without the appropriate credentials. Consider using a plugin such as JSecure to resolve this.

      No? Great, your administrator portal is hidden from public view!

    2. Is there a Super Administrator with the username ‘admin’ and with the ID #62 (go to User Manager to view the user ID)

      Yes? This is the default username and ID number for the site super administrator. If someone knows this information it is much easier to gain access to your website, particularly if you have any other vulnerabilities such as being out of date with your Joomla! installation.  This account should be disabled and an alternative administrator account created - preferably with a hard to guess ID (i.e. not #63, which would be my next guess!) and a unique username.

      No? Great, make sure your default super administrator account with ID of #62 is disabled in User Manager.

    3. Are your website addresses really long and ‘geek speak’? (e.g. www.yoursite.co.uk/index.php?option=com_content&task=view&id=5&Itemid=6)?

      Yes?
      URL’s should be made ‘Search Engine Friendly’ so that they contain keywords and the content of the page/article, so people know what they are looking at, and can tell someone else easily how to reach the page – e.g. www.yoursite.co.uk/About-Us/About-My-Company.  We'll be writing an article on Search Engine Friendly URL's in Joomla! in the near future.

      No? Do your URL’s contain words which are not your keywords, such as www.yoursite.co.uk/content/section/12/162/ ? If so, you may have the default Joomla! Search Engine Friendly URL’s enabled. While this is better than nothing, it isn’t helping your Search Engine Optimisation much, and could be far improved to include keywords relating to the page or article.  Consider whether you may want to use a component to give you further control over your URL's.

    4. Are you running an out of date, unsupported version of Joomla!? If you go to www.yoursite.co.uk/administrator do you see a screen like this:

joomla1.0










Yes?
      If you see this screen, you are using an old and no longer supported version of Joomla! – this version was deprecated almost a year ago! While it is still stable (providing you are running version 1.0.15 which you can find at the bottom of the page when you log in – any lower versions are a serious security risk) it is strongly advised to upgrade to at least Joomla! 1.5, which looks like this:


joomla1.5











  1. Is your Joomla! site using the most up to date version? In Joomla! 1.0.x (first image above) when you log in, it shows at the bottom of the site. In Joomla! 1.5.x (second image above) it shows on the right hand side when logged in. The latest versions are:
    • 1.0.15
    • 1.5.23 (Latest patch released on 4th April 2011)
    Yes? Great, your website is up to date with all the latest patches!

    No? If you are running versions other than those specified above you are potentially at very serious risk of being hacked, as many of the updates are security patches which cover ‘holes’ that are discovered – in much a similar way as Microsoft Updates do.

  2. Does your site have the following features
    • Google Analytics
    • Metadata tools to help with your Search Engine Optimisation
    • Backup systems to take regular updates
    • Anti-spam systems to stop spam coming through your contact/registration forms

    Yes?
    Great to hear, is there anything else you want to add in? With Joomla! the modular extensions system makes it easy to bolt on just about anything - whatever you want to do pretty much can be achieved!

    No? These are basic add-on extensions which can be invaluable to your website!

If you would like any further information about Joomla! sites, please don't hesitate to give us a call on (0845) 003 7235 or email us at This e-mail address is being protected from spambots. You need JavaScript enabled to view it .

You can download this check list as a PDF here.

Ruth Cheesley

Ruth Cheesley

Ruth is the owner and Director of Virya Technologies, having founded the company in 2002 as Essex Virus Removals and later rebranded to Suffolk Computer Services. She is  primarily involved with managing the website design team and liaising with our clients from across the world.

Website: www.viryatechnologies.com E-mail: This e-mail address is being protected from spambots. You need JavaScript enabled to view it
More in this category: « Prev Next »

Add comment


Looking for our open source software?

viryasoftwarelogo

We release and support our open source software at Virya Software

Find us on

facebook    linkedin    twitter     youtube    vimeo    ViryaTechnologiesJoomlaResources    ViryaTechnologiesonTechnorati    rss

Virya Technologies Newsletter

Receive all the latest tips, news and reviews from Virya Technologies.

Come and meet us!

JUN
01

01.06.2012 07:30 - 09:30
Ipswich Connected Business Breakfast

JUN
01

01.06.2012 12:00 - 17:20
Ecademy BlackStar First Friday Working Lunch

JUN
14

14.06.2012 19:30 - 22:00
Joomla! User Group Suffolk Meeting

JUL
06

06.07.2012 07:30 - 09:30
Ipswich Connected Business Breakfast

JUL
06

06.07.2012 12:00 - 17:20
Ecademy BlackStar First Friday Working Lunch

The latest from Virya Technologies

Virya Technologies @yakmoose Are you still looking for #joomla developers? We specialise in Joomla - happy to help! ^RC
ABOUT 8 HOURS AGO
Virya Technologies @tobydecks Do you still need help with #joomla shortcodes? ^RC
ABOUT 8 HOURS AGO
twitter Follow Viryatech on Twitter