Support

Admin Tools

#43345 File scanner results - same files always reported as modified

Posted in ‘Admin Tools for Joomla!’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
6.1.3
PHP version
8.3.33
Admin Tools version
7.9.2

Latest post by marcmarc on Saturday, 19 September 2026 02:50 CDT

marcmarc
Hi, I've 8 joomla 6.1.3 websites in production. I run a filescan everyday and there is no surprise with 5 of these websites. For 3 of them, I have the same results every day. The same files are reported as modified again and again. The path of these files is /administrator/components/com_admintools/tmpl I've attached a csv export of the last scan for one of these website. Any idea? Thanks

moira

Looking at the CSV you attached, every path is listed twice: once inside a folder with a capitalised name (e.g. AdminPassword, AutoBannedAddresses, NginXConfMaker) and once inside the equivalent all-lowercase folder (adminpassword, autobannedaddresses, nginxconfmaker). The currently installed Admin Tools 7.9.2 only ships the lowercase folders, so having both present at the same time on these 3 sites means there’s a leftover, incorrectly-cased duplicate of each folder sitting alongside the real one.

That duplication is itself the problem, independent of the scanner. Joomla (and every reputable extension, ours included) is built on the assumption that a site’s files can be moved to a case-insensitive filesystem — Windows NTFS, Apple’s APFS, etc. — without anything breaking. Having two folders that differ only by letter case (AdminPassword vs adminpassword) violates that assumption: on a case-insensitive filesystem the two would collapse into one anyway, and whichever file “wins” would depend on write order rather than anything predictable. This is why you’re seeing them reported as “modified” on every single scan: our database looks up each file’s previous checksum by path, and that lookup is case-insensitive, so the record for one casing keeps getting overwritten by the other, and vice versa, on every run.

All of these entries have a threat score of none and are flagged outofscope (Admin Tools’ own files, not a security concern), so there’s no indication of a hack here.

To fix this at the source rather than just silencing the report, could you do the following on one of the 3 affected sites:

  1. Connect with FTP/SFTP (or your host’s File Manager) and open administrator/components/com_admintools/tmpl/. Confirm you see both a capitalised folder (e.g. AdminPassword) and a lowercase folder (e.g. adminpassword) listed side by side.
  2. Delete the capitalised folders — they aren’t part of the current package and shouldn’t be there. Keep only the lowercase ones.
  3. Run the file scan again; the “modified” reports for these paths should stop.

If you’d rather not touch files manually, reinstalling Admin Tools 7.9.2 over itself (Extensions → Manage → Install, upload the same package again) will recreate the correct lowercase folders, though it won’t remove the stray capitalised ones on its own — step 2 is still needed for those.

Technical information

  • Admin Tools’ file scanner stores each scanned file’s path and checksum in the database, and looks up a file’s previous record with a case-insensitive comparison (MySQL’s default collation). When two files exist whose paths differ only by case, each scan’s lookup for one path returns the other file’s cached checksum, which never matches, so both are reported as “modified” forever. This is a downstream symptom of the invalid folder duplication, not something to fix by making the lookup case-sensitive — a Joomla site should never have two same-named-but-differently-cased folders on disk in the first place.
  • If you’d like to know how the duplicate capitalised folders were created on these 3 sites specifically (an old manual upload, a migration between servers with different filesystem case sensitivity, etc.), that would need to be investigated on your end, since we have no visibility into your server’s history.

Moira Fari

Support Specialist

🇬🇧English: native 🕐 My time zone is Asia / Nicosia
Kindly note that my replies are fully vetted by our developers.

marcmarc
Hi, ok, this makes sense. What I've done is to delete the /administrator/components/com_admintools/tmpl folder and replace it with a freshly donwloaded one found in the pkg_admintools-7.9.2-pro. It works fine now. Thanks

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!