Joomla

Joomla

Loads core CMS functionality scripts on Joomla-powered websites, including extension integrations and component libraries. Third-party Joomla extensions may load additional scripts that collect usage analytics or personal data depending on the plugins installed and configured by site operators.

Overview

Joomla is an open-source content management system (CMS) used to build and manage websites. Unlike SaaS platforms, Joomla runs as self-hosted software on the site operator's server. Its core scripts handle page rendering, user authentication, content management, and extension loading. Joomla's privacy footprint is determined primarily by which third-party extensions the site operator installs.

What This Script Does

Joomla's core scripts are served from the site's own domain and provide:

  • CMS framework: Loads JavaScript libraries (jQuery, Bootstrap, custom Joomla scripts) required for page interactivity, form handling, and component rendering.
  • Authentication: Manages user login sessions via PHP session cookies and CSRF token validation. Session cookies are set upon login and maintained for authenticated navigation.
  • Extension loading: Third-party Joomla extensions (plugins, modules, components) can load additional scripts with varying privacy implications — analytics trackers, marketing tools, social integrations, etc.
  • Form handling: Core form components (contact forms, registration forms) process user-submitted data within the local Joomla installation and database.
  • No external tracking: Joomla's core does not send data to external servers or set third-party cookies. Any external data transmission comes from installed extensions, not from Joomla itself.

Consent & Compliance

Joomla's core falls under the essential/functional consent category. The CMS framework scripts and authentication cookies are necessary for the website to function.

Under GDPR and ePrivacy, Joomla's core session cookies are "strictly necessary" for website operation and exempt from consent. The CMS scripts load from the site's own domain with no third-party involvement. Extensions that add analytics or marketing functionality would require their own consent assessment.

Under CCPA/CPRA, Joomla's core does not collect or share personal information with third parties. Data processing is limited to the site operator's own server and database.

Should You Block This Without Consent?

No. Joomla's core scripts are essential CMS infrastructure that the website requires to function. Blocking them would render the entire website non-functional. Any privacy-sensitive functionality comes from third-party extensions, which should be evaluated and consented independently.

Is Joomla GDPR compliant?

Joomla typically loads functional trackers, which are not strictly necessary for your site to work. Under the GDPR and the ePrivacy Directive, non-essential cookies and trackers must stay blocked until a visitor gives clear opt-in consent. So Joomla can be fully GDPR compliant, but only if your site holds its scripts until consent is granted and lets visitors decline just as easily. Compliance depends on how your site loads Joomla, not on Joomla itself.

Visit website

Consent Categories

Also Known As

joomlajoomla cmsjoomla extensionsjoomla plugins privacyjoomla cookie consentjoomla gdpr

Industries

Computers Electronics and Technology

Tracked Domains (1)

joomla.orgEssential

joomla.org is an essential domain operated by Joomla, used to keep the site working, including security, load balancing, and sessions.

Frequently Asked Questions

Related Vendors

Matomo
Matomo
Open-source web analytics platform that self-hosting teams use as a privacy-respecting alternative to Google Analytics. Matomo tracks page views, events, goals, and funnels. Can operate without cookies when configured for cookieless tracking, keeping all data under the site owner's control.
Wufoo
Wufoo
Embeds contact forms, surveys, payment forms, and event registration forms directly on web pages. Collects all personally identifiable information users enter into form fields, including names, email addresses, phone numbers, and payment details depending on the form configuration.
accessiBe
accessiBe
accessiBe is an AI-powered web accessibility platform that remediates WCAG and ADA compliance gaps. Scripts inject a widget interface for users to adjust contrast, font size, and motion preferences. The AI engine scans and adjusts page elements for screen reader and keyboard navigation compatibility.
Securiti.ai
Securiti.ai
Enables consent management banners, cookie preference centers, and data subject request intake workflows on websites. Scans page content to auto-categorize cookies, collects and stores granular consent signals, and enforces data processing restrictions based on jurisdiction-specific privacy regulations.
Medusa.js
Medusa.js
Medusa.js is an open-source headless e-commerce platform that provides API-driven backend services for custom storefronts. It serves product catalogs, cart, and order data through REST and GraphQL endpoints. Browser-side scripts are determined by the storefront implementation rather than Medusa itself.
Secure Privacy
Secure Privacy
Secure Privacy is a consent management platform providing GDPR, CCPA, and ePrivacy compliance tools. Scripts display cookie consent banners, perform automatic cookie scanning, and block non-consented tracking scripts. Consent logs are maintained per visitor for regulatory audit trails.

Manage consent for Joomla

ConsentStack automatically detects and manages Joomla trackers so your site stays compliant with global privacy regulations.