Joomla core integrity
Joomla core file integrity checks, even without official checksums
WordPress has official checksums. Joomla doesn’t, which is why almost no tool really verifies Joomla core files. We build them from the official packages.
The problem
Without a reference, an altered file looks normal.
Joomla doesn’t publish a list of file fingerprints. Without a trusted reference there’s no way to tell whether libraries/src/Factory.php is the original or a modified copy.
Files left over from earlier versions make it harder still: after years of updates a Joomla site has plenty of them, almost all harmless.
How it works
We build the reference ourselves.
- 1
Official packages
We download the official Full Package of every Joomla version and fingerprint its files.
- 2
Comparison on the site
The agent compares every core file with the fingerprints of the installed version.
- 3
Sensible severity
Modified PHP in the core is critical; files left from earlier versions are recognised by their content and don’t raise alarms.
In detail
Made for Joomla.
- Joomla 3.9, 3.10, 4, 5 and 6
- Modified, missing and unexpected files in core folders
- Files left from earlier versions recognised and kept apart from threats
- Diff against the official package for every flagged file
- Custom changes can be approved, for example in overrides
- In our tests: zero false positives across 9,625 files of a clean install
FAQ
Frequently asked questions
Does Joomla publish official file checksums?
No, Joomla doesn’t publish a list of file fingerprints. We build them from the official Full Package of every version.
Does it work on Joomla 3?
Yes, with a dedicated plugin for Joomla 3.9 and 3.10 that runs even on PHP 7.1.
What about files from old versions?
We recognise them by comparing their content with earlier releases: they are listed separately and don’t trigger critical alerts.
Related features
Goes well with
Try it on your clients’ sites.
During the beta we welcome agencies in small groups and set up the first sites together.