Tuesday, 01 February 2011 16:05

White paper: Joomla! Health Check

How do you know if your Joomla! website is being run effectively?  Have you had a Joomla! site created but not sure whether the security is up to scratch?  This article aims to give some tips to check against your website, which are drawn from standard security and 'best practice' guidelines.  If you have any other points you think we should add, please leave a comment!

    1. Can you navigate to www.yoursite.co.uk/administrator and get to the Administrator screen?

      Yes? This should be hidden and/or password protected, to stop people accessing your administrator portal without the appropriate credentials. Consider using a plugin such as JSecure to resolve this.

      No? Great, your administrator portal is hidden from public view!

    2. Is there a Super Administrator with the username ‘admin’ and with the ID #62 (go to User Manager to view the user ID)

      Yes? This is the default username and ID number for the site super administrator. If someone knows this information it is much easier to gain access to your website, particularly if you have any other vulnerabilities such as being out of date with your Joomla! installation.  This account should be disabled and an alternative administrator account created - preferably with a hard to guess ID (i.e. not #63, which would be my next guess!) and a unique username.

      No? Great, make sure your default super administrator account with ID of #62 is disabled in User Manager.

    3. Are your website addresses really long and ‘geek speak’? (e.g. www.yoursite.co.uk/index.php?option=com_content&task=view&id=5&Itemid=6)?

      Yes?
      URL’s should be made ‘Search Engine Friendly’ so that they contain keywords and the content of the page/article, so people know what they are looking at, and can tell someone else easily how to reach the page – e.g. www.yoursite.co.uk/About-Us/About-My-Company.  We'll be writing an article on Search Engine Friendly URL's in Joomla! in the near future.

      No? Do your URL’s contain words which are not your keywords, such as www.yoursite.co.uk/content/section/12/162/ ? If so, you may have the default Joomla! Search Engine Friendly URL’s enabled. While this is better than nothing, it isn’t helping your Search Engine Optimisation much, and could be far improved to include keywords relating to the page or article.  Consider whether you may want to use a component to give you further control over your URL's.

    4. Are you running an out of date, unsupported version of Joomla!? If you go to www.yoursite.co.uk/administrator do you see a screen like this:

joomla1.0










Yes?

      If you see this screen, you are using an old and no longer supported version of Joomla! – this version was deprecated almost a year ago! While it is still stable (providing you are running version 1.0.15 which you can find at the bottom of the page when you log in – any lower versions are a serious security risk) it is strongly advised to upgrade to at least Joomla! 1.5, which looks like this:



joomla1.5











  1. Is your Joomla! site using the most up to date version? In Joomla! 1.0.x (first image above) when you log in, it shows at the bottom of the site. In Joomla! 1.5.x (second image above) it shows on the right hand side when logged in. The latest versions are:
    • 1.0.15
    • 1.5.23 (Latest patch released on 4th April 2011)
    Yes? Great, your website is up to date with all the latest patches!

    No? If you are running versions other than those specified above you are potentially at very serious risk of being hacked, as many of the updates are security patches which cover ‘holes’ that are discovered – in much a similar way as Microsoft Updates do.

  2. Does your site have the following features
    • Google Analytics
    • Metadata tools to help with your Search Engine Optimisation
    • Backup systems to take regular updates
    • Anti-spam systems to stop spam coming through your contact/registration forms

    Yes?
    Great to hear, is there anything else you want to add in? With Joomla! the modular extensions system makes it easy to bolt on just about anything - whatever you want to do pretty much can be achieved!

    No? These are basic add-on extensions which can be invaluable to your website!

If you would like any further information about Joomla! sites, please don't hesitate to give us a call on (0845) 003 7235 or email us at This email address is being protected from spambots. You need JavaScript enabled to view it. .

You can download this check list as a PDF here.

Last modified on Monday, 25 June 2012 22:44
Ruth Cheesley

Ruth è il proprietario e direttore delle Virya Technologies, dopo aver fondato l'azienda nel 2002 come Essex Virus Removals e poi ridenominati in Suffolk Computer Services. Lei è principalmente coinvolto con la gestione del team di progettazione di siti web e di contatto con i nostri clienti di tutto il mondo.

Website: www.viryatechnologies.com

Leave your comments

0 Character restriction
Your text should be more than 10 characters
terms and condition.
  • No comments found

Training Courses

Google+ for Business - Ipswich
17-06-2013 2:00 pm
Basepoint Business Centre, Ipswich

Looking for our open source software?

viryasoftwarelogo

We release and support our open source software at Virya Software

Forthcoming events

MAY
30

30.05.2013 - 03.06.2013J and Beyond

JUN
6

06.06.2013 - 07.06.2013Great British Business Show @ Excel, London

Latest tweets

Virya Technologies We are in the process of dealing with a script causing high load on our Prajna server, meaning some sites are... http://t.co/StXS2dz3QX
Sunday, 19 May 2013 17:55
Virya Technologies We have been advised that the earlier connectivity problems at our data centre have been resolved. Sorry for any inconvenience.
Friday, 17 May 2013 12:59
Virya Technologies @heartinternet are reporting problems with dedicated & vps servers - some sites we host may be slow to respond. http://t.co/xD4nGZJ6Rq
Friday, 17 May 2013 12:23
Follow ViryaTech on Twitter