Keeping a Joomla site secure is an ongoing responsibility, not a one-time setup step. This section covers general good practice for hardening your site, plus one specific tool built into Joomla for adding an extra layer of browser-level security.

  • Best Practices – Sixteen recommended practices for hardening a Joomla site, from strong passwords and multi-factor authentication to keeping core, extensions, and templates up to date.
  • HTTP Headers – Using the HTTP Headers plugin to configure security headers such as X-Frame-Options, HSTS, and Content Security Policy from the backend, without editing server configuration files directly.