Skip to content

CMS

Joomla audit: extensions, generator tags, and Apache headers

· Configuration notes, not a newsroom.

Joomla fingerprints from generator and /media/jui/. SiteRune treats it as a PHP CMS: cache at the edge, headers at the vhost, stop shipping every extension on the homepage.

Generator is a gift and a leak

A precise Joomla version in the generator tag is a fingerprint we use and a banner attackers use. The security chapter will mention version disclosure when we see it. That is configuration, not a pentest. Update, then stop advertising the patch level in HTML.

What to ship this week

Full-page cache or Cloudflare in front. Security headers in Apache/nginx, not a template override. One SEO extension for titles, canonicals, and sitemap — not three. llms.txt at the origin. Robots that fence /administrator/ without Disallow: /.

Run it on a live URL

The brief will name your CMS and attach the files. Three guest scans, no card.

https://