Skip to main content
Average reading time: 14 minutes, 52 seconds
Total Votes: 1
Please Rate
Decorative image about how to secure a joomla site

6. Extensions, uploads and the Web Services API

Extensions are where most risk lives

Core Joomla is reviewed by a security team; third-party extensions vary widely. Before installing one:

  • Check the Vulnerable Extensions List (VEL) for the extension and the developer. The VEL itself notes it may not be complete, so it is a first check, not a clearance.
  • Prefer extensions with recent releases, a public changelog and support for your Joomla major version.
  • Install only from the developer or the Joomla Extensions Directory, never from "nulled" copies.
  • Uninstall, don't just disable, anything you no longer use. Disabled code is still on disk and may still be reachable.

Keep Media Manager's upload filters on

Content → Media → Options controls uploads. On 6.1.4 the defaults are safe: Restrict Uploads on, Check MIME Types on, and an allow-list of image, audio, video and document extensions with no php, svg or html.

Tested through the Media Manager upload API as a logged-in Super User:

File uploaded

Result

shell.php

Rejected: "This file type is not supported."

shell.phar

Rejected: "This file type is not supported."

shell.php.jpg

Rejected: "This file type is not supported."

fake.jpg containing PHP code

Rejected: "Illegal mime type detected"

notes.txt

Accepted (allowed type)

Do not add svg, html, js or archive types to the allow-list unless you must. Joomla's shipped .htaccess sends Content-Security-Policy: script-src 'none' for .svg files, which limits but does not remove the risk of script in SVGs.

Disable or block the API if you don't use it

Joomla's Web Services API (/api/index.php/v1/...) is on by default, with 18 webservice plugins enabled on the test install. Unauthenticated requests returned 401. Still, every enabled endpoint is attack surface, as the September 2026 ACL fix for webservice edit tasks showed.

  • Disable the Web Services plugins for content you never expose (System → Plugins, filter type webservices). Tested: with the Web Services - Users plugin disabled, /api/index.php/v1/users changed from 401 to 404 Resource not found.
  • If nothing uses the API, block it at the server with rule 3 in section 4. Tested: /api/... returned 403; the site and admin were unaffected.
  • Leave API Authentication - Basic Auth disabled (the default). It accepts a username and password on every request.

Share this article