Security filters for articles
From Joomla! Documentation
If you have a Joomla! Web site where people you do not know, and therefore cannot trust, are able to post articles to your Web site, consider adding an Editing Filter available in Joomla! to help reduce the chance someone could submit data that could harm your Web site.
The safest way to allow people you do not know to submit articles to your Web site is to follow these steps:
1. Do not allow unknown persons more than Author access.
Q. How do I verify the access my Web site allows?
A. In the backend Joomla! Administrator, select Site - Global Configuration to review your User Settings.
- If you do not want others to get an ID to your site, select "No" for Allow User Registration.
- If you are willing to allow people to submit an article, then select "Yes" for Allow User Registration and then select "Author" for New user Registration Type.
- Press Save, when complete.
2. Select the strongest filtering Joomla! offers.
Q. How do I set Joomla! filters for Articles?
A. In the backend Joomla! Administrator, select Content - Article Manager. Then, click the Parameters button.
- Scroll down on the dialog box until you see the "Filtering Options." Select Author.
- Select "No html" for Filter Type.
- Press "Save."
By using those options available in Joomla!, you can better ensure that unknown persons will not send in data that can harm your database.
As usual, the very best way - and only real assurance - is to protect your Web site with backups. Don't go without.
