Framesoft

Publishing

How these three sites are run without Joomla

A short briefing for the data-centre team after the Sourcerer incident. This is the editorial map, not an admin that can run plugins.

No executable content

Sourcerer (CVE-2026-74253) executed {source} blocks found in rendered HTML, including values reflected from URLs, forms, cookies and headers. This site stores copy as TypeScript modules. The contact form strips tags and {source} blocks before writing a JSON file. Nothing a visitor sends is evaluated as code.

Three sites, one deploy

Corporate, FCM and FSP used to be separate Joomla installations — three templates, three plugin lists, three patch cycles. They now share layout, search and publishing. Switch sites in the header.

Static where it should be static

Joomla rendered every page through PHP with cache headers that told browsers not to cache. Product and news pages here are generated from files. They are fast because there is no plugin pipeline on the hot path.

Editing is a pull request, not a Super User session

Change content/news.ts or content/products.ts, review the diff, deploy. That is slower than typing PHP into an article. It is also why yesterday’s class of attack does not apply.

Site map

FCM

Framesoft Contract Management

FSP

Framesoft Structured Products

19 products · 8 articles · contact enquiries land in data/inquiries.json