Get Started

Critical Security Notice

Before scanning a compromised Joomla site, close the original entry point first.

  1. Update SP Page Builder to 6.6.2 or later.
  2. Update or remove JCE if it is installed.
  3. Take a full backup and run the first scan on staging when possible.

In June 2026, a critical unauthenticated RCE was disclosed in SP Page Builder versions below 6.6.2. The flaw allowed attackers to upload PHP webshells without any login, read configuration.php, create rogue Super User accounts, and inject Stored XSS payloads into Helix Ultimate mega-menu items -- often within minutes of finding a vulnerable site.