How to Check Extensions After a Joomla Security Incident

Inventory every installed extension

After containing the site, use Joomla's extension management screens and your deployment records to identify components, modules, plugins, templates, libraries, and packages. Include disabled extensions: code that remains on disk can still matter if another vulnerability or direct file access makes it reachable.

Check each extension against trusted sources

Confirm the vendor, installed version, current supported version, Joomla/PHP compatibility, and whether the package is still maintained. Review the Joomla Vulnerable Extensions List and vendor security notices. Joomla's compromised-site checklist explicitly calls for reviewing vulnerable extensions because outdated or vulnerable third-party code is a common intrusion path.

Treat unexpected extensions as evidence

Investigate extensions you do not recognize, especially newly installed plugins, administrator modules, authentication integrations, or packages with unusual names. Record their files and database entries before removal if incident evidence matters. An attacker may disguise persistence as a normal-looking extension.

Replace executable extension files with clean packages

Do not assume an extension is clean simply because its version number looks current. If the server was compromised, its PHP files may have been modified without changing version metadata. Reinstall trusted extensions and templates from original clean vendor packages, which aligns with Joomla's security recovery guidance.

Remove vulnerable, abandoned, and unnecessary code

If an extension has a known unresolved vulnerability, no supported release, or no business purpose, remove it rather than merely disabling it. Keeping unused code increases the attack surface. Confirm that removal does not leave companion plugins, libraries, scheduled tasks, or files behind.

Review extension configuration and privileged integrations

Inspect API keys, webhooks, upload locations, file-management features, remote update credentials, and administrator permissions associated with extensions. Rotate secrets that may have been exposed. Pay particular attention to extensions implicated by access logs or the original exploit path.

Retest and monitor after cleanup

After reinstalling or removing extensions, update Joomla and all remaining extensions to supported versions, test critical workflows, and review logs for repeated exploit attempts. If suspicious files or behavior return, do not assume the extension review was sufficient; investigate hosting accounts, credentials, scheduled jobs, database content, and other persistence paths.


Need More Help with Joomla?

Still having trouble? Open a support ticket with QuantaCade Support and we'll be happy to help where we can.

Support priority is given to QuantaCade products, services, and customers. However, we're also happy to assist fellow Joomla users with general Joomla questions and troubleshooting when possible.

QuantaCade is an independent Joomla extension developer and is not official Joomla support. Some issues involving third-party extensions, hosting environments, server configurations, or other systems outside our development control may be beyond what we're able to resolve.

Open a Support Ticket