No SSH, no manual cron setup
Set Up Automatic Vulnerability Alerts for Joomla! in 5 Minutes
This is the actual install process, start to finish. For what gets checked and how before installing anything, see how the VEL feed works.
Before you start
Houston needs Joomla 5 or Joomla 6, PHP 8.1 or newer (8.3 or newer for Joomla 6), and a Houston license key from Gumroad to actually run a scan. If your site is still on Joomla 3, Houston is not for it yet: see what Joomla 3 end-of-life actually means and our Joomla! 3 Security Patch instead.
The six steps
- Install the package. Extensions → Manage → Install → Upload Package File, then select the Houston package and install. That is the only manual step in the whole process.
- Let it enable itself. Houston enables its own plugins and creates its own daily scheduled task in System → Scheduled Tasks automatically on install. There is nothing to configure there by hand.
- Activate your license. Enter the Gumroad license key under System → Houston. Without an active license the dashboard is visible, but no scan runs and no findings are generated.
- Run the first scan. Wait for the next scheduled trigger, whether that is a real server cron job, Joomla's own lazy scheduler on ordinary visits, or Web Cron, or open System → Houston and trigger Scan Now for an immediate result.
- Read the dashboard. System → Houston lists every installed extension, whether Joomla has a newer version on record, and any open finding, filterable by type and to third-party extensions only.
- Confirm the alert e-mail arrives. Check spam once after activating. Houston sends through the site's own mailer, so deliverability depends on that domain's SPF, DKIM and DMARC setup, the same as any other transactional e-mail from the site.
What you will see if something is found
A finding shows the extension name, which feed it came from, VEL or the Security Centre, and whatever detail that feed provided. See what a VEL entry can and cannot tell you if a finding looks sparse. Exactly one e-mail goes out for it. It then stays visible on the dashboard without sending another e-mail every day, only when the finding itself is new.