How to secure a Joomla site
Team Host.it 4 min read
Content
https://youtu.be/fBCEd7o2FOA
Updates Regularly checking the version of Joomla installed to avoid using an old and outdated version is the most important action to take to ensure the security of your website.
To check for any updates, simply access the Control Panel and view the messages of availability of new updates for both the extensions and the Joomla core.
Checking known vulnerabilities Joomla uses mailing lists to keep users updated in case of security vulnerabilities present in the core or extensions. Subscribing to these lists to receive notifications can be a good way to keep tabs on security fix releases.
Secure administrative password The most effective best practice for creating a secure password is that of length: use a long password with many character variations to avoid so-called "brute-force" attacks (i.e. the use of scripts by hackers to guess the most used character combinations in passwords).
Backup All Host hosting profiles provide a daily automatic backup service with a retention of up to 90 days. This is already a great way to keep your website data safe.
If you want to add greater security to the backup service included in your hosting profile, we recommend using personal backups with the most used extension for Joomla sites, namely Akeeba Backup.
Permissions on files and folders In all CMS, including Joomla, it is possible to set different levels of access to files and folders. Access permissions prevent unauthorized changes and it is therefore very important to set them correctly. An online Joomla site with inappropriate permissions is easily attacked.
There is an extension for Joomla, Admin Tools, which allows you to check and correct file permissions to ensure a higher level of security for your website.
PHP versions The discussion of updated versions applies not only to the Joomla core, but also and above all to the language in which this CMS is written (as well as many other software and apps on the web), namely PHP.
Check the version of PHP you are using with Joomla by going to "System > System Information" and check that this is the latest available also in terms of vulnerabilities.
The PHP version release cycle is available online.
Control and removal of inactive users If your Joomla site has been active for some time, you will almost certainly have accumulated a series of Super Users (users with maximum site administration privileges). If these users are no longer used, it is a good idea to do a good cleaning, to prevent the accounts from being used by hackers to take over the management of your site.
To check for inactive Super Users you can go to "User Management", filter by User Groups and check how many and which Administrators and Super Users are present, eliminating those that are no longer used or are no longer needed.
Another very important practice is to rename the "admin" user with a more personalized username. Changing this username to something other than "admin" will certainly make it more difficult for a hacker to try to guess this data for a possible brute-force attack on your Joomla site.
Unused extensions Always check all the extensions you have installed on your Joomla site over time. Do you still use them all? If the answer is no, proceed to uninstall the ones you no longer use, especially since these extensions could contain security flaws that would put your entire website at risk.
Just remember to proceed like this:
First disable the extension you want to uninstall to check the impact this could have on the site;
Make a backup copy BEFORE uninstalling;
Disable caching mechanisms from the site;
and finally, uninstall the extension.
Removing old files and installations Inside your Joomla installation check that you do not have additional files that are no longer necessary such as:
publicly available site backup files;
old versions of the site in some subfolders.
If these types of files are present, proceed with deleting them.
Backend protection Here are the two most common ways to prevent users from accessing the backend:
protect the "administrator" folder with a password;
add a secret parameter to the backend URL.
2-factor authentication By using a 2-factor authentication system (for example by entering a numeric token at each login) you reduce the possibility for hackers to identify the password to access your Joomla site.
Hosting Optimized for Joomla Most of the tips listed here in this article are actions that you, Joomla users, must do directly for your website. At Host we take care of verifying that your sites are secure and updated to avoid potential attacks. Our Customer Service notifies you in the event of a hacked site and tries to identify, together with you, the best practices to implement to improve the security of your Joomla installation.
DISCOVER HOSTINGS OPTIMIZED FOR JOOMLA
Joomla hosting
Joomla hosting in Italy
Plans with backups, SSL certificates and tools for developers and agencies.
Related articles
From the blog
From the archive