RESOURCE / GUIDE
OJS Security and Upgrade Checklist for Journal Publishers
Practical guidance for teams planning or maintaining digital platforms.
Inventory before changing anything
Record the OJS version, PHP version, plugins, theme changes, scheduled tasks and email setup. Confirm who owns the domain, hosting and backups.
Create and verify backups
Back up the database, public files, private files and configuration. Test a restore in a separate environment before changing a live journal.
Upgrade in stages
Check version compatibility and plugin support, then test the upgrade on a copy. Review article pages, PDFs, submissions, editorial roles, email and DOI deposits after the change.
Keep the installation maintained
Apply supported updates, remove unused plugins, limit administrator access, use HTTPS and monitor logs. Malware recovery should include finding the entry point and rotating compromised credentials.
Explore the related service: OJS journal services →