Hacked Joomla Site: Cleanup and Recovery
By Glenn Lyvers · Updated · 4 min read
Most hacked-site advice on the internet assumes WordPress, which is unhelpful when your site is Joomla and the folder names do not match anything you are reading. The good news is that the attacks are largely the same — the same spam injections, the same backdoors, the same redirect campaigns — and only the geography differs. Here is the Joomla version.
How Joomla sites get compromised
The dominant route is extensions. Joomla core has a reasonable security record, but the third-party components, modules and plugins around it vary enormously in quality and maintenance. An extension with a known vulnerability, particularly one the developer has abandoned, is the most common way in.
After that: running an unsupported Joomla version, since older major versions stopped receiving security fixes and a great many sites are still on them; weak or reused administrator passwords; and file permissions that are more generous than they need to be. None of that is Joomla-specific in nature — it is the same list as everywhere else, pointed at different files.
Where the malware hides
Start with the directories that matter. The images folder is Joomla's equivalent of the uploads problem — it should contain media and nothing executable, so any PHP file there is wrong by definition. The tmp and cache folders are writable and frequently used to stash payloads. The administrator directory holds the back end and is a favourite for dropped files.
Then the template files, which are Joomla's equivalent of a hacked theme: index.php in your active template is loaded on every page and is a common place to find an injected script. And the database, where injected content sits in articles, in module content, and in extension parameters — the same pattern as WordPress, in differently named tables.
Finding what changed
Sort the whole site by modification time and read the top of the list, which is the single most productive technique on any platform — my guide on timestamp forensics covers it in detail. A cluster of files changed at an hour you were asleep is your starting point.
Then compare against clean copies. Download the exact Joomla version you run and compare core directories file by file; anything present in yours and absent from the official release needs explaining. Do the same for extensions where the vendor makes the original available. And check the user list in the administrator back end for accounts you did not create, particularly ones with super user privileges.
Cleaning it
Preserve evidence first — a full file copy, a database dump, and your logs — as covered in preserving evidence. Then replace core with a clean copy of the same version, reinstall extensions from their original sources rather than repairing them, and delete anything that does not belong, especially executable files in media and temporary directories.
Sweep the database for injected scripts and spam links, delete unrecognized administrator accounts, and check extension parameters for stored payloads. Then rotate everything: database credentials, administrator passwords, FTP and hosting logins, and the secret value in your configuration file.
Securing it afterwards
Update to a supported Joomla version if you are not on one, which is the single highest-value action available and is frequently the actual reason the site was compromised. Remove extensions you do not use, and replace ones whose developers have stopped maintaining them.
Then the platform-agnostic list: two-factor authentication on administrator accounts, which Joomla supports natively; sensible file permissions; PHP execution blocked in directories that only hold media; and a proper backup schedule. My guide on hardening covers the principles, which translate directly.
The fallout is identical
Everything downstream of a hack is platform-independent. If Google flagged you, work through Search Console security issues and reconsideration requests. If browsers or antivirus vendors are blocking you, the blacklist removal links page covers the delisting forms.
And if the site was sending spam, was defaced, or had customer data exposed, the relevant guides apply exactly as written. I work on Joomla sites as well as WordPress ones, so if you would rather hand this over than learn a new directory structure under pressure, my malware removal service covers it.
Related reading: locked out of Joomla administrator. See also every platform I clean.
Common questions
Is Joomla less secure than WordPress?
Not inherently. Both have solid core security teams and both are compromised overwhelmingly through third-party extensions and weak credentials rather than core flaws. The practical difference is that Joomla's smaller ecosystem means fewer eyes on some extensions and more abandoned ones still in use.
Which folders should I check first?
The images directory, which should never contain executable files; the tmp and cache directories, which are writable and commonly used to stash payloads; the administrator directory; and your active template's files, particularly its index.php. Then the database for injected content.
How do I know if my Joomla version is still supported?
Check the version in the administrator control panel against Joomla's published support status. Older major versions have reached end of life and receive no security fixes, so a site still running one is effectively unpatched regardless of how recently it was touched.
Can I use WordPress security plugins on Joomla?
No — they are entirely different platforms and the extensions do not transfer. Joomla has its own security extensions and its own two-factor authentication built into core. The principles carry over exactly; the specific tools do not.
Do I need to reinstall Joomla completely?
Replacing core with a clean copy of the same version is the reliable approach, since it removes modified core files without you having to identify each one. Your database, configuration and media stay in place. Full reinstallation from scratch is rarely necessary unless the site was extensively damaged.
More than malware
Most people meet me in an emergency. It isn’t all I do.
I’ve been building and repairing systems since 1995. Whatever brought you here, there’s a good chance I can help with the rest of it too — and you’ll be dealing with the same person either way.
Hacked, but not WordPress?
Joomla, Drupal, Magento, Shopify, PrestaShop, Laravel, Node, IIS and plain HTML — cleaned the same way, priced the same way.
Take a look →Custom builds & AI systems
Plugins, custom applications, website chatbots and automation — built to do exactly what you need, maintained by the person who wrote them.
Take a look →Servers, speed, SEO & accessibility
Migrations, faster load times, technical SEO and accessibility fixes. Measured improvements, with the numbers to show you.
Take a look →Better web hosting
Fast, secure hosting with SSL and backups included at no extra charge. Clear pricing, no long-term contracts, no surprises.
Take a look →Classes & free tools
Rather learn to handle it yourself? I teach this, and I give away the tools I built for my own cleanups.
Take a look →Something else broken?
Half my work is untangling what someone else started, gave up on, or broke. Describe it in plain words and I’ll tell you honestly.
Take a look →Tell me what’s wrong. I’ll tell you what it takes.
No queue, no call centre, no sales pitch — one person who answers, quotes honestly, and does the work.