Introduction
Most Joomla compromises do not come from exotic zero-days. They come from sites running old core versions, abandoned extensions, weak administrator logins, and servers that execute any PHP file an attacker manages to drop into a writable folder. This guide covers each of those, in the order that gives the most protection for the least effort.
The recommendations here were tested on a clean Joomla 6.1.4 install (the current release, 29 September 2026) running on Ubuntu 24.04, Apache 2.4.58, PHP 8.3 and MariaDB. Each one states what was tested and what the result was; the few items that could not be tested are marked as such. Where a common piece of advice turned out to be weak or wrong in testing, that is called out.
Three findings from testing are worth knowing before you start:
- Joomla's shipped
.htaccessblocks some injection patterns, but on a default install the exact core version is still publicly readable at/administrator/manifests/files/joomla.xml. - A root
.htaccessrule that blocks PHP inimages/can be switched off by an attacker who uploads a one-line.htaccess(RewriteEngine On) into that folder. Server-level configuration closes this gap. - Setting
configuration.phpto444does not stop Joomla from rewriting it when the file is owned by the web server user. Ownership matters more than the mode.
