Lyzerslab

What's new in v5.0.0

Global Configuration security audit

Half of every Joomla hardening checklist lives in Global Configuration and is invisible to malware scans. The Configuration Audit card (Pro, Settings > Analysis) reviews 17 of those settings through a security lens — debug output, error verbosity, session handling, cookie flags, forced HTTPS, the FTP layer, webservices, MFA availability, and more.

How to read it

Each row shows the current value, the recommended value, and one of three verdicts: pass (hardened), warn (fix recommended), or verify (check manually — either genuinely ambiguous or a judgment call for your site). There is deliberately no "fail": a misconfiguration is exposure, not a confirmed compromise.

Read-only on purpose

The card never changes anything — every row deep-links to the exact Joomla screen where you change it yourself. One-click fixes stay out until false-positive shapes are known; a wrong click on the session handler would log everyone out.

Joomla 3

Coming to the Joomla 3 edition with v3.0.0.