TYPO3: Hacked or Vulnerable? Immediate help and a checklist
How to check if your TYPO3 website is secure, what to do if you detect a breach or vulnerability, and when to ask for help — a practical step-by-step guide
In a nutshell
Do you suspect a breach?: Don’t panic, but proceed methodically. First, secure the evidence and make a copy, then carry out a diagnosis — not the other way round. Hasty ‘clean-up’ can cover up traces and fail to remove the source of the problem.
Just want to check?: Verify the version of TYPO3 and its extensions, compare them with the latest security advisories, and check the logs and file integrity. You’ll find a specific checklist in the article.
Key principle: A publicly disclosed vulnerability with an available patch is a race against time — attackers’ scanners search for unpatched installations within days.
GDPR: If a personal data breach has occurred, you may be required to report it to the UODO within 72 hours. This is a separate, important obligation.
Sooner or later, every website owner asks themselves this question: is my website secure? Sometimes it’s a routine check, and sometimes it’s a sudden cause for concern — strange posts, slow performance, a warning from the hosting provider, or suspicious redirects. This article will guide you through both scenarios: how to calmly check the security status of your TYPO3 site and what to do if something has already gone wrong.
Please note: this is a practical guide and is not a substitute for an individual analysis. In the event of a serious incident — particularly one involving personal data — it is advisable to seek specialist help as soon as possible.
How to tell when something is wrong
Website hacks rarely make a big splash. More often than not, they’re stealthy — because the attacker wants to remain undetected for as long as possible. Here are some warning signs worth being aware of.
✗ Unfamiliar entries, pages or backend users that nobody on the team has created
✗ Redirects to third-party domains — particularly noticeable for mobile users or those arriving via search engines
✗ A sudden slowdown of the website or an increase in server load for no apparent reason
✗ A warning from your hosting provider, Google Search Console or a browser about malware
✗ Unfamiliar files in system directories, particularly PHP files in locations where they shouldn’t be
✗ Spam being sent from your domain or your domain being blacklisted
✗ Changes to configuration files or user tables that nobody has made
Important: the absence of these symptoms does not mean that the website is secure. Many vulnerabilities can be exploited without leaving any visible traces. Therefore, in addition to responding to warning signs, it is worth regularly and proactively checking the security status of your website.
Checklist: how to check whether TYPO3 is secure
Below is a systematic checklist. You can work through it yourself or commission an audit — in either case, it’s worth knowing exactly what is being checked.
- TYPO3 version
Check that you are using a supported version (v13, v14 or v12 with ELTS). Unsupported versions do not receive patches — this is the single greatest risk.
- Core News
Compare your version with the latest security release (e.g. 14.3.3 / 13.4.31). Every version that is out of date represents a potential, known vulnerability.
- Extensions
List all extensions and versions, and compare them with the latest security advisories. Pay particular attention to the popular ones (tt_address, news, ke_search).
- User permissions
Check the list of backend accounts — make sure they are all recognised and necessary. Delete any unused accounts and restrict any unnecessary permissions (particularly file write permissions).
- Logs
Check the server and TYPO3 logs for unusual requests, login attempts and access to unusual paths.
- File integrity
Compare the system files with a clean version — any unfamiliar or modified PHP files are a cause for concern.
- Configuration and environment
Check the PHP version (to see if it is supported), security settings, access to the installation panel, and whether any sensitive files are exposed.
- Backups
Make sure you have up-to-date, working copies — and that they are stored securely, away from the production server.
What to do if you discover a break-in — step by step
If you have reasonable grounds to suspect a breach, the order in which you take action matters. The most common mistake is to rush into ‘cleaning up’, which obscures the evidence but fails to remove the source — after which the attack returns.
- Secure the evidence
Before you make any changes, make a full backup (files + database + logs). You’ll need it for analysis and in case you need to report an issue.
- Minimise the damage
Depending on the situation: temporarily taking the website offline, disconnecting from the network, changing access passwords (backend, database, FTP, hosting, control panel).
- Identify the source
Identify which vulnerability the attacker exploited — otherwise, cleaning up the system is pointless, as the backdoor remains open. Logs and an analysis of modified files will help here.
- Remove the malicious code and restore the clean files
Most likely from a trusted copy created before the incident, or by reinstalling a clean version of Core and its extensions.
- Fix the vulnerability
Update Core, extensions and PHP. Otherwise, the attack will return.
- Change all credentials
Backend user passwords, API keys, and access details for databases and external services.
- Monitor
Once the site has been restored, monitor the logs and the site’s behaviour — make sure the attack does not recur.
- Consider your legal obligations
If personal data has been leaked, check whether you are required to notify the UODO (within 72 hours) and — in the case of NIS2 entities — whether you are required to report incidents.
In the event of a serious cyber-attack, particularly one involving sensitive data or affecting a regulated organisation, taking action on your own can be risky. In such situations, it is advisable to seek specialist assistance as soon as possible — both to resolve the problem effectively and to document the incident properly.
When to ask for help
Not every situation requires a specialist, but there are certain signs that suggest you shouldn’t try to deal with it on your own.
✓ You suspect a breach but cannot identify the source — cleaning up without doing so is a waste of time
✓ There has been a personal data breach — legal obligations and deadlines are involved
✓ The website is critical to your business (online shop, patient portal, public services) and every hour of downtime costs money
✓ You’re subject to NIS2 and must document your response to the incident
✓ You do not have ongoing technical support and are unsure whether the problem has been fully resolved
Frequently Asked Questions
Very quickly. Automated scanners begin scanning the network for vulnerable systems, often within hours or days of an advisory being published. That is why it is so important to update your system as soon as a patch is released.
Partly. Your hosting provider may have a firewall and basic security measures in place, but it won’t patch vulnerabilities in your TYPO3 installation or extensions — that’s your responsibility (or that of your agency). The application layer is your responsibility.
The update fixes known vulnerabilities, but if a breach has already occurred, the patch alone will not remove any malicious code left behind by the attacker. Therefore, following an incident, you must apply the patch, clean the system and change your credentials.
Security updates — on an ongoing basis, in line with security advisories. A more comprehensive review (extensions, permissions, configuration, backups) — periodically, e.g. quarterly. A fixed-term maintenance contract automates monitoring and reduces response times.
How can we help?
If you suspect a problem or simply want to check your security status — we’re here to help. We offer a TYPO3 security review (versions, extensions, configuration) with a report within 24–48 hours, assistance with post-breach recovery, and ongoing maintenance contracts with a guaranteed response to security advisories and documentation for NIS2 audits.
Telephone: 12 333 44 01. Email: [email protected]. If the matter is urgent — please call.