aceArt · TYPO3 Agency

TYPO3 Maintenance & Security

A TYPO3 website is never "finished". It must be continuously maintained and secured against new vulnerabilities. We take over the maintenance of your TYPO3 installation completely, from controlled updates via LTS lifecycle planning to fast intervention when things do catch fire.

Ongoing maintenance — updates, backups, monitoring

The TYPO3 core, the sitepackage and every installed extension receive regular updates, security-relevant ones included. Skip them and open vulnerabilities pile up over time. We apply updates in a controlled way, test them beforehand on a staging environment and keep a continuous eye on your installation, including automated, regular backups so a clean restore point stands ready in an emergency. Performance stays under observation too: with our free tool SiteSentry we monitor PageSpeed and Core Web Vitals automatically — if a value drops, we know before your visitors notice.

For us, maintenance also includes LTS lifecycle planning. We keep track of when your current TYPO3 version falls out of the free support window and coordinate with you in good time whether a version update or an ELTS extension is the right next step. Details on our page on TYPO3 updates & LTS migration.

TYPO3's official security team & security advisories

Unlike many other CMS, the TYPO3 project runs its own official security team. Reported vulnerabilities are checked centrally, fixed in a coordinated way and published as formal security advisories, with a binding response time of 48 hours for incoming reports.

What that means for your website

  • A central, reliable source: instead of learning about vulnerabilities via scattered forums or third-party plugins, we follow the official TYPO3 security advisories directly
  • Clear severity ratings: every advisory rates the vulnerability by CVSS score, letting us prioritise critical patches cleanly against uncritical ones
  • Coordinated disclosure: patches are generally ready before the vulnerability is described publicly in detail — shortening the window for attacks
  • For extensions too: the security team coordinates not just core but also extension vulnerabilities for extensions from the TYPO3 Extension Repository (TER)

We actively check published advisories against your installation and apply critical security patches promptly — outside regular maintenance windows too, if the situation demands it.

Security — preventing instead of repairing

Most successful attacks exploit known, long-closed vulnerabilities in outdated TYPO3 versions or extensions. The most effective protection is therefore not being attackable in the first place — current versions, a lean, vetted extension stack, restrictive backend user rights and a login area that doesn't lie open to automated brute-force attempts.

What belongs to our security concept

  • A web application firewall and protection against automated brute-force login attempts
  • Regular checking of installed extensions against current security advisories
  • Encrypted connections (SSL/TLS) and cleanly configured HTTP security headers
  • Granular backend user groups instead of sweeping admin rights for everyone
  • Separate, encrypted backups outside the actual hosting environment

Composer-based installations bring an additional advantage here: dependencies are versioned and traceably documented, so when an advisory drops we immediately see whether and where your setup is affected.

TYPO3 compromised? Here's how we proceed

If your installation is already compromised (redirects to foreign domains, unknown backend accounts, unusual server load or simply a bad feeling), one thing counts above all: fast, considered action instead of panic. We take the site offline immediately if needed, secure the current state for analysis and match the symptoms against known security advisories to narrow down the entry point quickly.

With Composer-based installations we rebuild the TYPO3 core and all dependencies from a clean, official source, instead of manually hunting for individual manipulated files. Then we close the exploited gap, renew compromised credentials and set up ongoing maintenance and advisory monitoring, so it doesn't come to this the next time at all.

What a security incident usually shows first

  • Unexpected redirects to foreign domains or spam content on your site
  • New, unknown users in the TYPO3 backend
  • Unusually high server load without an apparent reason
  • A Google warning that your website could be unsafe

Related topics

TYPO3 updates & LTS migration

Ongoing maintenance and LTS lifecycle planning belong together. More on TYPO3 updates & LTS migration.

TYPO3 accessibility

The accessibility statement too should be checked regularly against the actual technical state. More on TYPO3 accessibility.

Ready for your TYPO3 project?

Tell us about your project. We'll get back to you promptly with an honest assessment.

By the way: aceArt is an official Silver Member of the TYPO3 Association.

Contact us
HOMETYPO3-MAINTENANCE-SECURITY