hi! i installed , run jts on joomla 1.0.13. first value 92%. saw astatspro not have (_validmos...) thing. removed it. furthermore, i've set folders 755 , files 644. yeah, know, really... cool. so, baically, everythig read-only. got false positives joomlapack (2 zip files necessary create installer), 2 zip files (backups), , joomlacomment (logo.jpeg). jpeg... says script. cpanel says so, because downloaded file check out. intelligible thing " hell, i've put .htaccess file in /administrator folder allowing ip only. use rather strong pass. user registration enabled, captcha , e-mail confirmation. have categories registered users , content set registered (to avoid cross-settings). php safe mode off. register globals off. emulate register globals off. in nutshell, did taught should do. still, 92%. what's there more? maybe remaining 8% due 3rd party extensions, modules , bots. so... site safe? i'm new joomla! (1 month old, actually). hi, just commenting on sh404s...