Houston - Vulnerability Scanner
Introduction
Houston checks your installed extensions and the Joomla core every day against Joomla's own official vulnerability feeds, and e-mails you only when a genuinely new finding appears.
Daily vulnerability scanning for your installed extensions and the Joomla core, using Joomla's own official vulnerability feeds. Alerts you only when something new is actually found.
What it does
Houston reads every installed extension (components, plugins, modules, templates) directly from your site, so there is no manual inventory to maintain. It matches them against Joomla's own free VEL feed (Vulnerable Extensions List) and Joomla's official Security Centre feed for the core: no third-party database, and no external API key needed for the matching itself.
It sends an e-mail only on a genuinely new finding. There is no recurring status report and no repeat alert for something you already know about. Installation is unattended: Houston enables itself and sets up its own daily scheduled task automatically, with nothing to configure by hand in Joomla's Task Scheduler.
The dashboard lists every installed extension, whether Joomla has a newer version on record, and any open finding, filterable by type and status.
How it works
Houston runs entirely on your own server. There is no central database operated by the vendor, and no site content or configuration is transmitted anywhere. The only outbound requests are the call to Joomla's own public vulnerability feeds, a best-effort CVSS lookup against NVD or CVE.org using just the CVE id (never the site's identity), and, when a license key has been entered, a license-verification call to the vendor's payment provider.
Scope and limitations
Joomla's VEL feed is the best available source, but it is not always complete. Houston surfaces findings exactly as the feed reports them, without adding information the feed does not provide. Houston performs inventory-based vulnerability matching only. It does not scan files for malware and does not perform file-integrity checking.
Requirements
Joomla 5 or 6 (Joomla 4 likely works, untested)
PHP 8.1+ (8.1 for Joomla 5, 8.3 for Joomla 6)
Licensing note
The extension code is free and GPL-licensed. A paid license key is required for vulnerability matching to run. Without a key, the dashboard still lists installed extensions and available Joomla-reported updates, but no vulnerability matching happens and no e-mail alerts go out.
Server Requirements
Joomla 5.0 or Joomla 6.0 (Joomla 4 likely compatible, untested). PHP 8.1 or higher (PHP 8.3 required on Joomla 6). No PHP extensions beyond what a standard Joomla 5/6 install already requires (cURL, standard database driver)
Houston - Vulnerability Scanner
- Version:
- 1.02
- Developer:
- Artd Webdesign GmbH
- Last updated:
-
Sep 02 2026
15 hours ago - Date added:
- Sep 01 2026
- License:
- GPLv2 or later
- Type:
- Paid download
- Includes:
- c p
- Compatibility:
- J5 J5 (b/c plugin) J6 J6 (b/c plugin)
Share