0845 4747 450

Joomla Hosting

Joomla! is an extremely powerful open source content management system (CMS). The core application is mature, very stable and inherently secure – as long as no poorly coded and vulnerable third party extension applications are installed, Joomla updates are installed on release and you choose a Joomla hosting company who have their web hosting servers securely configured.

Here are a few recommendations that Rochen, the web hosting company that host all the official Joomla websites suggest to ensure your Joomla website is not only secure, but also performs to its maximum potential.

Secure Joomla Hosting

  1. Your Joomla hosting company should run PHP in CGI mode with su_php.  This means that PHP does not run under the global Apache web server user, but under your own individual user account.  This means you don’t need to set insecure CHMOD 777 (read, write, execute permissions for all users).  Installation of plugins is much more straight forward and secure.
  2. All Joomla files should be CHMOD to 644 and all directories to 755 – no files should ever be set to 777 – especially the configuration.php file.
  3. The Joomla FTP layer is only required if your host does not run PHP under the account user.  If you have a good Joomla hosting company then you should not need to enable FTP in your global site settings.  You should also remove your FTP login details if they have already been stored.
  4. Change the default administrator username to something other than ‘admin’ – I normally change the username and set the user level to registered user. This makes the site even harder to compromise.
  5. Don’t install every component, plugin and module ever written for Joomla – if you don’t have a use for an extension or you no longer use one, remove them. The more joomla extensions you install the more you have to keep updated to avoid vulnerability issues. Make sure you remove the actual files too by FTP.
  6. Make sure your Joomla hosting company are keeping their servers regularly updated and removing end of life applications (like PHP4). Server modules like mod_security for Apache and open_basedir under PHP helps to minimise cross site scripting (XSS) issues.
  7. Passwords – as always make sure you use secure passwords for your administrator user, FTP, control panel and database connection.
  8. Password protect your administrator folder using .htaccess. This will ensure that even if someone were to get hold of your admin user password, they would not be able to get far enough into the site to actually use it.
  9. Most importantly, keep your Joomla installation updated to the latest version. It is a great idea to subscribe to the Joomla Security Mailing List. You should also subscribe to the security mailing lists of any third party vendors whose extensions you have installed.

Joomla Web Hosting

You can be sure that at least your Joomla hosting company is fulfilling their side of the deal by going straight to a well respected host. There is no greater testimonial of the standard of Joomla hosting offered by Rochen than that all the official Joomla websites are hosted on their servers. Dorey Media prefer our clients to host with Rochen where possible.

Like this? Tweet it to your followers!

Member of Nominet UK Microsoft Partner Microsoft Bing Google Adwords Yahoo!

Contact Dorey Media

  • UK Lo-Call: 0845 47 47 450
  • Telephone: +44 (0)203 287 5450
  • Mobile: +44 (0)7779 66 66 31
  • Facsimile: +44 (0)7092 808080
  • Email:
  • Skype: DoreyMedia
You are here: Joomla Hosting