How to Determine Whether a Joomla Website Has Been Hacked

Treat symptoms as evidence to investigate, not automatic proof

Defacement, redirects, spam pages, new administrator accounts, unfamiliar files, outbound mail, browser warnings, or unexplained resource usage can indicate compromise, but some have benign causes. Record exactly what happened, when it began, and which URLs or accounts are affected before making changes that could erase useful evidence.

Check Joomla and hosting accounts

Review Joomla users with elevated privileges and compare them with the people who should have access. Also inspect hosting control-panel, SFTP/SSH, database, and deployment accounts. An unauthorized account, unexpected privilege change, or credential use from an unfamiliar source is strong evidence that the investigation must expand beyond Joomla itself.

Compare files with trusted sources

Compare Joomla core files against the correct official package and extensions/templates against trusted vendor copies or source control. Look for unexpected new PHP files as well as modified files. Joomla's security guidance recommends checking changed files and replacing compromised code with clean copies rather than trusting a partially cleaned installation.

Review access, error, and security logs

Examine web-server access and error logs, hosting security logs, authentication records, and any available application logs around the first known symptom. Look for requests to unfamiliar scripts, unusual POST traffic, exploitation patterns, repeated authentication attempts, or access to files that should not have public endpoints.

Check the database and generated output

A compromise can live in content, modules, template settings, user records, scheduled jobs, or extension tables even when core files compare cleanly. Inspect suspicious injected links, scripts, redirects, new users, altered configuration, and unexplained scheduled activity. Preserve database evidence before removing it.

Check systems that can access the site

Joomla's incident checklist recommends scanning computers that have administrative or file-transfer access. Compromised workstations, saved FTP credentials, CI/CD secrets, browser sessions, or hosting accounts can reinfect a cleaned site. Determine whether the entry point was the application, an extension, the server, or a credential.

Respond conservatively when compromise is credible

If evidence indicates compromise, take the site offline or restrict access, preserve evidence, contact the hosting provider, rotate credentials from a clean device, and rebuild affected code from trusted sources. Do not assume deleting the visible payload restores trust. Recovery must address the original access path and any persistence left behind.


Need More Help with Joomla?

Still having trouble? Open a support ticket with QuantaCade Support and we'll be happy to help where we can.

Support priority is given to QuantaCade products, services, and customers. However, we're also happy to assist fellow Joomla users with general Joomla questions and troubleshooting when possible.

QuantaCade is an independent Joomla extension developer and is not official Joomla support. Some issues involving third-party extensions, hosting environments, server configurations, or other systems outside our development control may be beyond what we're able to resolve.

Open a Support Ticket