Free Joomla tool · no sign-up

Which Joomla version is that site running?

Enter any address. In a few seconds you get the Joomla version, whether that version still receives security updates, the PHP version, the template, SSL and security headers.

It works on any site — yours, a client's, one you have been asked to quote on. No account, no email required to see the result.

  • Result on screen in a few seconds
  • Nothing to install, nothing to sign up for
  • Read-only: it requests pages your own browser could request

Free Joomla Health Check

Enter your site's address and I'll check it in seconds — no signup required for the basics.

We only request pages your browser can already see. No login, no scanning, nothing changed on your site.

  • Joomla version & end-of-life status
  • PHP version
  • SSL certificate status
  • Security header score
What you get

Four things, in plain language

Enough to tell you whether a site is a problem waiting to happen, without asking you to read a security report.

Joomla version and support status

The exact version where the site exposes it, and a straight answer on whether that branch still gets security patches. Joomla 3 and 4 no longer do.

PHP version

Read from the server's own response headers, when the host discloses it. Old PHP is the thing that turns a working site into a blank page after a hosting upgrade.

SSL and security headers

Whether HTTPS verifies, how long the certificate has left, and which of the six common security response headers are actually set.

Template and visible extensions

The template in use and any third-party extensions the page's own markup already names — often the first sign that something abandoned is still running.

Being straight with you

What this tool does not do

Plenty of “free scanners” are really vulnerability probes wearing a friendly hat. This one is not, and here is exactly where the line is.

It never logs in

No credentials are asked for, guessed or used. Everything comes from pages served publicly to any visitor.

It does not probe for holes

No vulnerability scanning, no walking through hundreds of paths looking for what is installed. Six requests per check, hard limit.

It respects robots.txt

If a site tells crawlers to stay out of a folder, this stays out too — which is why some results show an approximate version rather than an exact one.

It says who it is

Every request carries a user agent naming this tool and linking back here, so any site owner can see who asked and why.

Your address stays yours

You only give an email if you want the detailed report. No newsletter, no resale, deleted on request.

Results are not a security audit

This is a surface check. A clean result means nothing obvious is wrong from outside, not that a site is secure.

Questions

About this tool

Is it OK to check a site I don't own?

Yes. Everything this tool reads is served publicly to anyone who visits the site — the same information your browser receives when you open the page. It does not log in, test for vulnerabilities, or send anything but ordinary GET requests, and it identifies itself in every one of them.

Why does the version sometimes say “approx.”?

The exact version normally comes from a file under /administrator/. Most Joomla sites tell crawlers to stay out of that folder in robots.txt, and this tool honours that. When it cannot read the exact number it falls back to identifying the major version from the page's own markup, which is enough to tell you whether the branch is supported.

Why does PHP show as “not disclosed”?

Many hosts strip the X-Powered-By header, which is good practice. When it is not there, the PHP version simply cannot be read from outside — that is a point in the site's favour, not a failed check.

Do you store what I check?

The result is stored so that re-checking the same domain within a day does not hit that server again. Your IP is never stored, only a one-way hash of it used to stop the tool being hammered. If you ask for the detailed report, your email is stored with it until you ask me to delete it.

The result says my site is fine. Am I safe?

It means nothing obvious is wrong from the outside. A surface check cannot see a compromised file, a weak admin password, or an extension with a vulnerability that has not been published. Treat a green result as “no alarm bells”, not as a clean bill of health.

Came out red?

An unsupported Joomla version is not an emergency today, and it is not something to leave alone either. I upgrade Joomla 3 and 4 sites to Joomla 6 without losing the design, the content or the Google positions — and keep them patched afterwards.

About

Saint Art Designs is a freelance Joomla web developer specializing in modern, responsive, and secure websites.

Why Hire Me?

With over two decades of experience in Joomla development, I deliver high-quality, stable, and scalable websites.

Each project is approached with precision, clear communication, and a focus on long-term value.

Get a Quote

Online Profiles

Freelancer
Upwork
Linkedin
Facebook
Google Review

Contact Info