How to Find Unexpected Files in a Joomla Installation

Establish what should be present

Start with the exact Joomla version and a list of installed extensions and templates. An unexpected file is one that cannot be explained by Joomla core, a trusted extension package, site media, configuration, or an intentional operational tool. Do not assume every file absent from a Joomla package is malicious because third-party software adds legitimate files.

Compare core areas with a clean Joomla package

Download the matching official Joomla package and compare core directories and files against the installed site. Focus on executable PHP, JavaScript, and configuration-related files. A clean-package comparison can reveal added, missing, or modified files, but preserve site-specific files and extension directories rather than overwriting them during the investigation.

Review timestamps and unusual locations

Look for recently created or modified executable files, PHP in upload/media locations where you do not expect it, strangely named files, hidden files, and scripts placed beside otherwise static assets. Timestamps are clues, not proof: deployments, restores, and attackers can all alter them.

Trace files back to installed extensions

For files under components, modules, plugins, libraries, media, or templates, compare them with a clean package from the extension's trusted vendor. Version metadata alone does not prove file integrity because an attacker can modify code without changing the extension's recorded version.

Treat suspicious files as evidence first

If compromise is possible, copy suspicious files and relevant logs to a protected evidence location before deleting them. Record the path, size, timestamp, and cryptographic hash when your incident process supports it. Avoid opening unknown PHP through the browser or executing it to see what it does.

Search beyond the obvious web root

Persistence can exist in writable directories, cron or scheduled-task scripts, configuration files, alternate document roots, or hosting-account locations outside the Joomla root. If suspicious files reappear after cleanup, investigate server credentials, scheduled jobs, extensions, database content, and other access paths rather than repeatedly deleting the same file.

Restore trust with clean packages

When a Joomla core or extension file is confirmed altered unexpectedly, replace the affected software from trusted official or vendor packages and close the access path that allowed the change. Update vulnerable software, rotate exposed credentials, and monitor logs and filesystem changes after recovery.


Need More Help with Joomla?

Still having trouble? Open a support ticket with QuantaCade Support and we'll be happy to help where we can.

Support priority is given to QuantaCade products, services, and customers. However, we're also happy to assist fellow Joomla users with general Joomla questions and troubleshooting when possible.

QuantaCade is an independent Joomla extension developer and is not official Joomla support. Some issues involving third-party extensions, hosting environments, server configurations, or other systems outside our development control may be beyond what we're able to resolve.

Open a Support Ticket