How to Compare Joomla Core Files with a Clean Package
Identify the exact Joomla release first
Determine the installed Joomla version before comparing files. Use an official package for that exact release whenever you are checking integrity. Comparing different releases produces legitimate differences that can look like corruption or compromise and makes the result unreliable.
Obtain the package from an official Joomla source
Use Joomla's official download channel and verify the package using the checksums published for that download when available. Keep the clean package outside the live web root while you extract it. Do not use an old archive from an unknown workstation as your integrity baseline.
Compare core paths without treating site data as core
Compare Joomla core directories and files while accounting for configuration.php, media/uploads, caches, logs, temporary files, and third-party extensions that are specific to the site. Joomla defines paths such as JPATH_ROOT and JPATH_ADMINISTRATOR for its application structure; extensions and site content legitimately add files beyond a stock package.
Use hashes or a recursive comparison
On systems where you have shell access, a recursive diff or cryptographic hash comparison can identify missing, extra, and changed files. Hosting file managers may provide comparison or checksum features as well. Run comparisons read-only first so the investigation does not overwrite evidence or site customizations.
Investigate each difference by ownership
A changed core file can result from corruption, an incomplete update, unsupported manual modification, or compromise. An extra file may belong to an extension or may be suspicious. Trace each difference to Joomla core, a vendor package, or a documented site customization before deciding what to replace.
Do not repair by mixing versions
If core files are missing or corrupted, use a supported Joomla update/reinstall method or a clean package that matches the intended release. Copying individual files from another Joomla version can introduce API mismatches and leave the installation in an inconsistent state.
Verify the site after restoring clean core files
After a supported repair, test the frontend and Administrator, run update checks, review logs, and compare again if necessary. If unexplained changes return, investigate credentials, vulnerable extensions, scheduled jobs, and server-level access. Replacing core files alone does not remove an active compromise.
Need More Help with Joomla?
Still having trouble? Open a support ticket with QuantaCade Support and we'll be happy to help where we can.
Support priority is given to QuantaCade products, services, and customers. However, we're also happy to assist fellow Joomla users with general Joomla questions and troubleshooting when possible.
QuantaCade is an independent Joomla extension developer and is not official Joomla support. Some issues involving third-party extensions, hosting environments, server configurations, or other systems outside our development control may be beyond what we're able to resolve.