- Change the default database prefix (jos_)
- Use a SEF component
- Use the correct CHMOD for each folder and file.
- Password protect your administrative area.
- Use a .htaccess file to secure your Joomla.
- Passwords – Use a unique strong password.
- Install the jSecure Authentication plugin.
- Always Update all third party extensions to the latest versions.
- Remove any unused third party extensions.
- Disable or remove unused user accounts.
- If possible use less number of extenisons.
- Always use the highest rated third party extension.
- Always take back ups dont rely on Hosting provider.
- Recommended to use OWASP Joomla Vulnerability Scanner for security vulnerabilities and exploitable plug-ins https://vel.joomla.org/