Running Joomla 5 or 6?
Houston.
Vulnerability Scanner for Joomla!
Reads your installed extensions and Joomla's own core version, matches them every day against Joomla's own free VEL feed and official Security Centre feed — no API key, no central Artd-run database — and e-mails you only when a genuinely new finding appears.
License only gates update notifications for Houston itself
2
official Joomla data sources checked daily
0
central database, no API key for either feed
1 click
install — scan task sets itself up
1 new finding(s) · ALERT SENT
Why this matters
WordPress has had automated, inventory-based vulnerability checking (MainWP, WPScan, Wordfence, Patchstack) for years. Joomla doesn’t have an equivalent — existing Joomla security tools do file-integrity scanning or malware signatures, not CVE matching against what you actually have installed.
Extensions get vulnerabilities too
Not just the Joomla core. A site with a dozen third-party extensions has a dozen more things that can silently go out of date and stay vulnerable.
Manual checking doesn’t scale
Checking each installed extension against the VEL list by hand works for one site. It doesn’t for an agency managing dozens.
A daily status e-mail gets ignored
Tools that report every day train you to skim past them. Houston only e-mails when something is actually new.
What’s included
Two data sources, matched against your actual installation, every day.
Extensions
Joomla’s own VEL feed
Reads Joomla’s free, key-less Vulnerable Extensions List directly and matches it against every component, plugin, module and template actually installed on your site — by exact name, not a loose text match, and by version range where the feed provides one.
Core
Joomla’s own Security Centre feed
Checks your installed Joomla core version against Joomla’s own official security advisories feed — the same source Joomla’s own security team publishes to, no separate CVE database required.
Dashboard
One screen, everything installed
System → Houston lists every installed extension, whether Joomla itself has a newer version on record, and any open finding — filterable to components, plugins, modules, templates, or third-party-only (hiding Joomla’s own bundled extensions).
Alerting
Only when it’s new
A finding is only e-mailed the first time it’s seen. Already-known findings stay visible on the dashboard without sending another e-mail every single day.
How it works
Installs as a normal Joomla extension. No SSH or manual cron setup required.
-
Install
Extensions → Install → upload the package file. That’s the only step.
-
It sets itself up
Enables itself and creates its own daily scheduled task — nothing to configure in System → Scheduled Tasks.
-
It runs
Triggered by a real server cron job, Joomla’s own lazy scheduler on ordinary site visits, or Web Cron — whichever this site already has.
-
You get an e-mail
Only when a genuinely new finding appears. Check System → Houston any time for the full picture.
Honest about the data
What Houston can and can’t promise, stated plainly — the same way we document every fix in the Joomla! 3 patch.
VEL’s own data isn’t always complete
Joomla’s VEL feed sometimes lists a vulnerable extension without a CVE number, version range, or severity rating attached — even for confirmed, critical issues. Houston still surfaces the finding, but shows it honestly as “severity unclear” rather than guessing a rating the source data doesn’t support.
It doesn’t scan for malware
Houston matches inventory against known-vulnerability data. It does not read your files for backdoors or webshells, and it is not a firewall. Pair it with a file-integrity tool if you need that too.
The alert e-mail is only as good as your mail setup
Houston sends through Joomla’s own mailer. Whether it lands in your inbox or your spam folder depends on your own domain’s SPF/DKIM/DMARC setup, the same as any other transactional e-mail from your site — check spam once after activating.
Frequently asked questions
Does Houston replace a malware scanner like Watchful or a firewall?
No. Houston does not scan files for malware and does not block attacks. It matches your installed extensions and Joomla core version against known-vulnerability data (Joomla’s VEL feed and Joomla’s own Security Centre feed) and tells you when a match appears. File-integrity/malware scanning and firewalling are a different job, done by different tools.
Which Joomla versions does Houston support?
Joomla 5 and Joomla 6. It requires PHP 8.1 or newer (Joomla 5’s own minimum; Joomla 6 requires PHP 8.3+). It is not compatible with Joomla 3 or 4 installations — if you’re still on Joomla 3, see our Joomla! 3 Security Patch instead.
Is this a subscription?
The scan and dashboard keep working with or without a license. A license unlocks update notifications for Houston itself, billed per year per site.
Does Houston send my site’s data anywhere?
No central Artd-run database exists for this product. Houston reads two of Joomla’s own public feeds directly from your server (no API key needed for either) and keeps the results in your own database. The only outbound call beyond that is the license check against Gumroad, made only when you activate a license key.
Get Houston
Scan and dashboard work with or without a license. A license unlocks update notifications for Houston itself.
Houston — Vulnerability Scanner for Joomla!
See current pricing on the order page.
Get Houston- Daily extension & core vulnerability scan
- Admin dashboard: every extension, update status, open findings
- E-mail alert on genuinely new findings only
- Works with Joomla! 5 and 6
- No central vulnerability database, no API key
Deliberately not included
- Malware/file-integrity scanning — use a dedicated tool such as Watchful alongside Houston
- Automatic patching — Houston tells you what’s outdated or vulnerable, updating remains your call
- Coverage for Joomla 3 or 4 — Joomla 5/6 only