Joomla Penetration Testing
Joomla’s risk sits in what your team added and changed: extensions, administrator access and permissions. We test the Joomla site you deployed, not a default install. CREST-certified testers, fixed price from £2,060 for a 2-day single-site scope, quoted within 24 hours.
- Unlimited retesting
- Unlimited pre-retesting
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
Every group’s permission for every action in Joomla is set to Allowed, Denied or Inherited, and the Calculated Setting column shows what that combination actually adds up to once global, component and category permissions are combined.
Why Joomla security comes down to extensions and permissions
Joomla builds access from user groups that nest inside each other, plus a separate system of Access Levels that controls what a logged-in or anonymous visitor can see. Joomla’s own ACL documentation splits this into two questions: which parts of the site a user can reach, and which actions they can perform once there. In System, Global Configuration, Permissions, every action for every group is set to Allowed, Denied or Inherited, and Joomla shows the outcome in a Calculated Setting column once every layer, global, component and category, has been combined. We test what a group’s calculated permission actually is once every layer is combined, not what a single screen appears to say on its own.
Every component, module and plugin on a Joomla site comes from a third-party developer of variable quality, and each one runs with the same access to the database and file system as the core. Joomla’s own security guidance directs installers to the Vulnerable Extensions List before installing anything, naming poorly written or abandoned third-party code, not the core, as the source of most reported Joomla vulnerabilities. We check every installed extension against that list and review its permission and file-handling behaviour directly, and we look for files, folders and database tables an old uninstalled extension left behind, since Joomla’s own checklist warns these can stay reachable by direct URL after removal.
Joomla 4 added a Web Services API that exposes the same content and configuration through JSON endpoints alongside the traditional site and administrator interfaces. Joomla’s own API documentation states that every endpoint requires authentication unless it is explicitly designated public, and that the default API application requires a Super User account. Authentication runs through a Bearer token built from an HMAC of your site’s secret value in configuration.php, issued by an API authentication plugin rather than a full OAuth implementation. We test which endpoints are reachable without a token, what a token scoped to a lower-privileged account can still read or change, and whether the API surface enforces the same ACL your front end and admin panel do.
SCOPE
What we pen test on a Joomla site
Third-Party Extensions: Components, Modules and Plugins
Every component, module and plugin on your Joomla site comes from a developer outside the Joomla project, and each one runs with the same access to the database and file system as the core. We review each installed extension’s permission and file-handling behaviour, and check its name and version against Joomla’s own Vulnerable Extensions List before testing what it actually does on your site.
Orphaned Files From Uninstalled Extensions
Uninstalling an extension does not always remove everything it created. Joomla’s own setup checklist warns that leftover files, folders and database tables can remain reachable by a direct URL long after the extension is gone, so we check for exactly that: old component, module and plugin paths still serving content nobody remembers installing.
Administrator Directory, Super User Accounts and Login Hardening
The /administrator path is the single door into every permission Joomla has, and a Super User account bypasses every explicit check below it. We test how that path is exposed, how many accounts sit in the Super User group, and whether multi-factor authentication and lockout controls are enforced on every one of them.
Global Configuration: Group Actions and Calculated Permissions
In System, Global Configuration, Permissions, every action for every user group is set to Allowed, Denied or Inherited, and a Calculated Setting column shows what that combination resolves to once parent groups are taken into account. We test the calculated outcome for every group in scope, not what one slider appears to show before it is saved.
Component and Category-Level Permission Overrides
Permissions set in a component’s own Options screen, such as Content, Article Manager, can grant or withhold actions like Create, Edit, Edit Own, Publish and Delete for a specific group at that level, narrower than whatever Global Configuration set. We test these overrides at category and component level, including whether an Edit Own permission actually stops a user reaching records they do not own.
Viewing Access Levels and Front-End Visibility
Access Levels are a separate system from ACL actions: they decide which menu items, modules and content a visitor can see, based on the groups assigned to that level and any of their child groups. We test what a Public-level page actually exposes to an unauthenticated visitor, and check for content or menu items left on a permissive Access Level by mistake.
Web Services API Token Generation and Scope
Joomla’s built-in Web Services API authenticates with a Bearer token, and the token itself is built from an HMAC of your site’s secret value in configuration.php, generated through an API authentication plugin rather than a full OAuth implementation. We test what a token issued to a lower-privileged account can still read or change, and how the plugin handles a token that should have been revoked.
Public and Super-User-Only API Endpoints
Joomla’s own API documentation states that every endpoint requires authentication unless it is explicitly designated public, and that the default API application requires a Super User account. We map every endpoint your integration actually exposes against that rule, checking for a route left reachable without a token or a permission check that only exists on the equivalent front-end page.
Media Manager Uploads and File-Type Enforcement
The Media Manager is the standard route for a logged-in user to put a file on your server, and what it accepts depends on the file-type and MIME-type settings configured for your site. We test what the upload form and the underlying API endpoint actually accept once a filename or content-type is manipulated, not just what the interface offers in its picker.
Deployment Configuration: configuration.php, Debug Mode and the Installation Folder
configuration.php holds the database credentials and the secret value your Web Services API tokens are built from, and Joomla’s own checklist calls for it to sit outside the public web root wherever your hosting allows it. We check whether debug mode and verbose error reporting are switched off in production, and whether the installation folder was actually removed after setup rather than left reachable.
OUR PROCESS
Joomla Penetration Testing: From Scope to Attestation
Scope and Access
We agree the environments, administrator and API accounts we need, and which extensions and Super User accounts are in scope before testing begins.
Extension and Permission Mapping
We map every installed extension, user group and Access Level against Joomla’s Global Configuration permissions before manual testing starts.
Manual Testing
A CREST-certified tester manually exploits weaknesses in extensions, ACL configuration, administrator access and the Web Services API, chaining findings where they compound.
Attestation and Retest
You get a technical report with CVSS scores and reproduction steps, a walkthrough call, a free retest once fixes are deployed, and an attestation letter for auditors.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a CREST Joomla pen test quote in 24 hours
A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.
- CREST and IASME accredited. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one business day with a fixed-price quote from a named CREST assessor.
- You approve the scope and we book a start date, usually within 24 hours.
- Live findings land in your client portal as we test, with a free retest of every fix.
Get your fixed pen test quote in 24 hours
Quote request received
We will reply within one business day with your fixed-price quote from a named CREST assessor.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one business day. Your data stays with us. No newsletter signup.
COMPLIANCE READY
Reports Mapped to Every Framework
Findings are written so your team can reference the report against each framework without translation work.
ISO 27001:2022
Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.
SOC 2 Type I & II
CC6 logical access, CC7 system operations, CC8 change management evidence.
PCI DSS
Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.
FCA SYSC
SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.
UK GDPR
Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.
Cyber Essentials Plus
Direct certification through our IASME body status, single-vendor delivery.
PRICING
Transparent Joomla Penetration Testing Pricing
Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.
2 to 3 testing days
Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.
Get a fixed quote3 to 5 testing days
Multi-role SaaS, business application with payment integration. Around 8 to 12 working days from kickoff to report.
Get a fixed quote5 to 7 testing days
Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.
Get a fixed quoteSECTORS
Sectors We Test Joomla For
Sector-specific scoping for regulated UK organisations.
Fintech & FCA-Regulated
FCA SYSC, Open Banking FAPI 1.0, PSD2 SCA, payment-flow scrutiny, KYC/AML testing.
Fintech sector pageSaaS Companies
SOC 2 Type I & II evidence, multi-tenant boundaries, role escalation, customer-tenant isolation.
SaaS sector pageLaw Firms
SRA Cyber Standard, privileged data, conveyancing fraud defence, partner-tier procurement.
Law firm sector pageHealthcare
NHS DTAC, DSP Toolkit v6, UK GDPR Article 32, EHR systems, telehealth platforms.
Healthcare sector pageInsurance
FCA / PRA Operational Resilience, cyber underwriting, claims data, broker portals.
Insurance sector pagePublic Sector
CCS / G-Cloud framework, NCSC-aligned, citizen-facing services, PSN-compliance scrutiny.
Public sector pageWHY EJN LABS
What You Get From Joomla Penetration Testing
Six concrete differentiators competitors don’t all match.
CREST-Certified Testers, Verifiable
Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.
24-Hour Startup, Where Required
From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.
Live Findings, Not 4-Week PDFs
Critical issues reported during testing through your client portal. Your team remediates while testing continues.
Audit-Ready Reports
Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).
Free Retests, Standard
Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.
UK-Based CREST Testers
Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.
FAQ
Frequently Asked
What access do you need to test our Joomla site?
We need administrator credentials for at least one account in each relevant user group, including a Super User account to review Global Configuration permissions and installed extensions. If the Web Services API is enabled, we also need a token or account for each permission tier it exposes.
Will testing touch our live data?
We test whichever environment you give us access to. If that is production, we agree exclusions upfront, such as bulk deletes and outbound emails, and we do not run destructive tests against real customer records without that agreement in writing.
How long does a Joomla penetration test take?
A single Joomla site sits in our 2-day single-site scope, with a report typically landing around 5 working days after kickoff. Sites with a large number of extensions, custom user groups or a public-facing Web Services API move into a wider scope with more testing days.
Do you test self-hosted Joomla as well as managed hosting?
Yes. We test Joomla running on your own server or in a container the same way as Joomla on managed hosting. The server-configuration checks adjust to whichever platform you use, but the extension, ACL and administrator testing is the same either way.
Is the /administrator area included in the test by default?
Yes. If administrator access sits behind a VPN, IP allowlist or network our test team cannot reach without extra setup, tell us during scoping so we can arrange access or agree to exclude it.
What is out of scope for a single-site Joomla test?
Infrastructure-level issues in the underlying server, network or cloud configuration are out of scope for this test and covered by our cloud penetration testing service instead. The Joomla core codebase itself is also out of scope, since that is the Joomla project’s own responsibility to secure.
Do you need our source code?
No. Testing is black-box against the running site by default. A grey-box option, where we review extension code, Global Configuration permissions and configuration.php settings alongside testing, is available if you want faster or deeper coverage of specific findings.
Does Joomla have a customer penetration-testing policy we need to follow?
No. Joomla is open source software you install and control yourself rather than a hosted multi-tenant service, so there is no vendor notification process to follow before testing it. The Joomla Security Strike Team (JSST) handles vulnerability reports for the Joomla core codebase itself, not customer testing authorisation, and if your site runs on shared or managed hosting, that provider’s own penetration-testing policy still applies and we check it during scoping.
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get a fixed price for your Joomla site
Joomla’s risk sits in what your team added and changed: extensions, administrator access and permissions. We test the Joomla site you deployed, not a default install. CREST-certified testers, fixed price from £2,060 for a 2-day single-site scope, quoted within 24 hours.



