How to Check a Joomla Website for Unexpected Modified Files
Establish a trustworthy comparison point
Unexpected modification only means something when you have a trustworthy baseline. Compare the live Joomla tree with a clean package matching the site's installed Joomla release and with known-good copies of the site's extensions and template. Do not assume an old backup is clean merely because it predates the moment the problem was noticed; a compromise may have existed unnoticed for some time.
Review recently changed files
Use the hosting file manager, SSH, deployment tooling, or a security scanner to sort files by modification time. Joomla's security guidance specifically recommends reviewing recently changed files after a suspected incident. Treat timestamps as leads rather than proof because deployments, restores, cache operations, extension updates, and attackers can all affect file times.
Separate expected writable data from executable code
Cache, logs, media uploads, generated thumbnails, and temporary files legitimately change during normal operation. Core PHP files, template PHP, plugins, and extension code should change primarily during controlled installation, update, or development work. Prioritize unexplained changes to executable files and files loaded on every request.
Compare core files with a clean Joomla package
Obtain the appropriate Joomla package from an official Joomla source and compare core paths against the live installation. A difference can be legitimate when the installed release differs from the package or when local files were intentionally customized, so verify the exact version before replacing anything. Preserve suspicious originals for investigation.
Check extensions and templates separately
A clean Joomla core does not prove the whole site is clean. Compare third-party components, modules, plugins, libraries, templates, and custom code with trusted vendor packages or source-control history. Remove extensions that are obsolete or no longer required rather than leaving vulnerable code installed but unpublished.
Look beyond modified files
Attackers can add new files without modifying existing ones. Search for unfamiliar PHP files, executable files in upload or media directories, unexpected archives, hidden files, altered scheduled jobs, and unauthorized administrator accounts. Review web-server and hosting logs for requests to suspicious paths and unusual POST activity.
Preserve evidence before cleanup
Before deleting or overwriting suspicious files, make a controlled copy of relevant files, logs, timestamps, and configuration for later analysis. If compromise is plausible, take the public site offline and involve the hosting provider. A file-integrity review should lead into a complete incident-response process rather than a piecemeal deletion exercise.
Need More Help with Joomla?
Still having trouble? Open a support ticket with QuantaCade Support and we'll be happy to help where we can.
Support priority is given to QuantaCade products, services, and customers. However, we're also happy to assist fellow Joomla users with general Joomla questions and troubleshooting when possible.
QuantaCade is an independent Joomla extension developer and is not official Joomla support. Some issues involving third-party extensions, hosting environments, server configurations, or other systems outside our development control may be beyond what we're able to resolve.