TYPO3: Hacked or Vulnerable? Immediate help and a checklist

How to check if your TYPO3 website is secure, what to do if you detect a breach or vulnerability, and when to ask for help — a practical step-by-step guide 

Blog 03.08.2026

In a nutshell

Do you suspect a breach?: Don’t panic, but proceed methodically. First, secure the evidence and make a copy, then carry out a diagnosis — not the other way round. Hasty ‘clean-up’ can cover up traces and fail to remove the source of the problem. 

Just want to check?: Verify the version of TYPO3 and its extensions, compare them with the latest security advisories, and check the logs and file integrity. You’ll find a specific checklist in the article. 

Key principle: A publicly disclosed vulnerability with an available patch is a race against time — attackers’ scanners search for unpatched installations within days. 

GDPR: If a personal data breach has occurred, you may be required to report it to the UODO within 72 hours. This is a separate, important obligation. 

Sooner or later, every website owner asks themselves this question: is my website secure? Sometimes it’s a routine check, and sometimes it’s a sudden cause for concern — strange posts, slow performance, a warning from the hosting provider, or suspicious redirects. This article will guide you through both scenarios: how to calmly check the security status of your TYPO3 site and what to do if something has already gone wrong. 

Please note: this is a practical guide and is not a substitute for an individual analysis. In the event of a serious incident — particularly one involving personal data — it is advisable to seek specialist help as soon as possible. 

How to tell when something is wrong

Website hacks rarely make a big splash. More often than not, they’re stealthy — because the attacker wants to remain undetected for as long as possible. Here are some warning signs worth being aware of. 

Unfamiliar entries, pages or backend users that nobody on the team has created 

Redirects to third-party domains — particularly noticeable for mobile users or those arriving via search engines 

A sudden slowdown of the website or an increase in server load for no apparent reason 

A warning from your hosting provider, Google Search Console or a browser about malware 

Unfamiliar files in system directories, particularly PHP files in locations where they shouldn’t be 

Spam being sent from your domain or your domain being blacklisted 

Changes to configuration files or user tables that nobody has made 

Important: the absence of these symptoms does not mean that the website is secure. Many vulnerabilities can be exploited without leaving any visible traces. Therefore, in addition to responding to warning signs, it is worth regularly and proactively checking the security status of your website. 

Checklist: how to check whether TYPO3 is secure

Below is a systematic checklist. You can work through it yourself or commission an audit — in either case, it’s worth knowing exactly what is being checked. 

  • TYPO3 version

    Check that you are using a supported version (v13, v14 or v12 with ELTS). Unsupported versions do not receive patches — this is the single greatest risk. 

  • Core News

    Compare your version with the latest security release (e.g. 14.3.3 / 13.4.31). Every version that is out of date represents a potential, known vulnerability. 

  • Extensions

    List all extensions and versions, and compare them with the latest security advisories. Pay particular attention to the popular ones (tt_address, news, ke_search). 

  • User permissions

    Check the list of backend accounts — make sure they are all recognised and necessary. Delete any unused accounts and restrict any unnecessary permissions (particularly file write permissions). 

  • Logs

    Check the server and TYPO3 logs for unusual requests, login attempts and access to unusual paths. 

  • File integrity

    Compare the system files with a clean version — any unfamiliar or modified PHP files are a cause for concern. 

  • Configuration and environment

    Check the PHP version (to see if it is supported), security settings, access to the installation panel, and whether any sensitive files are exposed. 

  • Backups

    Make sure you have up-to-date, working copies — and that they are stored securely, away from the production server. 

What to do if you discover a break-in — step by step

If you have reasonable grounds to suspect a breach, the order in which you take action matters. The most common mistake is to rush into ‘cleaning up’, which obscures the evidence but fails to remove the source — after which the attack returns. 

  • Secure the evidence

    Before you make any changes, make a full backup (files + database + logs). You’ll need it for analysis and in case you need to report an issue. 

  • Minimise the damage

    Depending on the situation: temporarily taking the website offline, disconnecting from the network, changing access passwords (backend, database, FTP, hosting, control panel). 

  • Identify the source

    Identify which vulnerability the attacker exploited — otherwise, cleaning up the system is pointless, as the backdoor remains open. Logs and an analysis of modified files will help here. 

  • Remove the malicious code and restore the clean files

    Most likely from a trusted copy created before the incident, or by reinstalling a clean version of Core and its extensions. 

  • Fix the vulnerability

    Update Core, extensions and PHP. Otherwise, the attack will return.

  • Change all credentials

    Backend user passwords, API keys, and access details for databases and external services. 

  • Monitor

    Once the site has been restored, monitor the logs and the site’s behaviour — make sure the attack does not recur.

  • Consider your legal obligations

    If personal data has been leaked, check whether you are required to notify the UODO (within 72 hours) and — in the case of NIS2 entities — whether you are required to report incidents. 

In the event of a serious cyber-attack, particularly one involving sensitive data or affecting a regulated organisation, taking action on your own can be risky. In such situations, it is advisable to seek specialist assistance as soon as possible — both to resolve the problem effectively and to document the incident properly. 

When to ask for help

Not every situation requires a specialist, but there are certain signs that suggest you shouldn’t try to deal with it on your own. 

You suspect a breach but cannot identify the source — cleaning up without doing so is a waste of time 

There has been a personal data breach — legal obligations and deadlines are involved 

The website is critical to your business (online shop, patient portal, public services) and every hour of downtime costs money 

You’re subject to NIS2 and must document your response to the incident 

You do not have ongoing technical support and are unsure whether the problem has been fully resolved

Frequently Asked Questions

Very quickly. Automated scanners begin scanning the network for vulnerable systems, often within hours or days of an advisory being published. That is why it is so important to update your system as soon as a patch is released. 

Partly. Your hosting provider may have a firewall and basic security measures in place, but it won’t patch vulnerabilities in your TYPO3 installation or extensions — that’s your responsibility (or that of your agency). The application layer is your responsibility. 

The update fixes known vulnerabilities, but if a breach has already occurred, the patch alone will not remove any malicious code left behind by the attacker. Therefore, following an incident, you must apply the patch, clean the system and change your credentials.

Security updates — on an ongoing basis, in line with security advisories. A more comprehensive review (extensions, permissions, configuration, backups) — periodically, e.g. quarterly. A fixed-term maintenance contract automates monitoring and reduces response times.

How can we help?

If you suspect a problem or simply want to check your security status — we’re here to help. We offer a TYPO3 security review (versions, extensions, configuration) with a report within 24–48 hours, assistance with post-breach recovery, and ongoing maintenance contracts with a guaranteed response to security advisories and documentation for NIS2 audits. 

Telephone: 12 333 44 01. Email: [email protected]. If the matter is urgent — please call. 

About the author
Krzysztof Napora
Krzysztof Napora
Krzysztof Napora