Skip to content

Joomla SEO: friendly URLs, canonicals, security headers and schema.org

Published 7 October 20268 min readBy the SmoothSeen editorial team

Joomla SEO can be handled almost entirely with core features: friendly URLs and rewriting in Global Configuration, canonicals and redirects through the System - SEF plugin, security headers through System - HTTP Headers and structured data through the Schema.org plugins. Only the XML sitemap needs an extension. Everything below applies to Joomla 5.4 and 6.1.

Key points

  • The current release is Joomla 6.1; Joomla 5.4 stops receiving bug fixes on 13 October 2026 and gets security fixes only until 12 October 2027.
  • Joomla only adds a canonical tag if you fill in the Site Domain field of the System - SEF plugin; without it there is no canonical at all.
  • The System - HTTP Headers plugin ships enabled and sends X-Frame-Options, Referrer-Policy and Cross-Origin-Opener-Policy; HSTS and CSP have to be switched on.
  • Since Joomla 5, core outputs JSON-LD through nine Schema.org plugins (Article, BlogPosting, Book, Event, JobPosting, Organization, Person, Recipe and Custom); there is no LocalBusiness or Product type.
  • Core Joomla does not generate an XML sitemap: you need an extension.

To check it on your own site: SEO audit

On this page

Joomla is an open-source PHP content management system. It controls URLs, page titles and metadata, the canonical tag, robots.txt (a file in the web root), several HTTP headers and schema.org markup. It does not control the server: the server-level redirect from http to https, compression and browser caching depend on Apache, Nginx or your host. Labels below are quoted exactly as they appear in Joomla's English language files.

Which Joomla version should you run in October 2026?

The current major release is Joomla 6, launched on 14 October 2025; its latest version is 6.1.4 and 6.2.0 is scheduled for 13 October 20261. Joomla 5.4 is in bug-fix-only mode until 13 October 2026 and will get security fixes until 12 October 20271. If you are still on 5, plan the move to 6 this year. Every SEO setting in this guide exists in both lines.

What
Clean URLs without index.php
Joomla does it
Yes, with rewriting enabled
You (or the server) do it
Rename htaccess.txt or configure Nginx
What
Canonical
Joomla does it
Yes, once Site Domain is set
You (or the server) do it
Check extensions that add a second one
What
robots.txt
Joomla does it
Created at install
You (or the server) do it
Add the Sitemap line and your AI policy
What
Security headers
Joomla does it
X-Frame-Options, Referrer-Policy, COOP, HSTS and CSP
You (or the server) do it
X-Content-Type-Options comes from .htaccess
What
Structured data
Joomla does it
Organization, Person, Article and six more types
You (or the server) do it
LocalBusiness or Product through the Custom plugin
What
XML sitemap
Joomla does it
No
You (or the server) do it
An extension from the official directory

How do you turn on friendly URLs in Joomla?

The options live under System > Global Configuration, Site tab, SEO section2:

  1. Search Engine Friendly URLs: Yes. Turns index.php?option=com_content&view=article&id=1 into readable paths.
  2. Use URL Rewriting: Yes, but prepare the server first. On Apache and LiteSpeed, rename htaccess.txt to .htaccess; on IIS, web.config.txt to web.config; on Nginx you must configure the server2. Switch it on without doing so and inner pages may stop loading.
  3. Add Suffix to URL: No, unless you already have .html URLs indexed.
  4. Unicode Aliases: No for an English site. With No, Joomla transliterates aliases, so «über» becomes «ueber» in en-GB.
  5. Site Name in Page Titles: After appends the site name to each <title>.

On the Server tab, Force HTTPS has three values: None, Administrator Only and Entire Site. Choose Entire Site only once the certificate works, and enable Behind Load Balancer if TLS ends at a proxy or load balancer2.

Renaming htaccess.txt comes with a bonus: the Joomla 6.1 file already sends X-Content-Type-Options: nosniff and disables JavaScript inside SVG files opened directly3.

How does Joomla prevent duplicate content?

Through the System - SEF plugin. Global Configuration itself points out that more SEO settings live there2. Find it under System > Plugins and review these options4:

Option
Site Domain
What it does
Preferred domain for the canonical; https://example.com and https://www.example.com count as different domains
Suggested value
Your domain with https://
Option
Strict Routing
What it does
301-redirects URLs the router treats as duplicates
Suggested value
On
Option
Strict handling of index.php
What it does
Strips index.php from URLs and redirects requests that contain it
Suggested value
On if you use rewriting
Option
Trailing slash for URLs
What it does
Forces URLs with or without a trailing slash, with a redirect; only without a suffix
Suggested value
Whatever form is already indexed

The detail almost nobody knows is in the plugin code: if Site Domain is empty, Joomla adds no canonical tag at all. Once you fill it in, the plugin outputs <link rel="canonical"> with your domain plus the current path and query string, or rewrites with your domain any canonical a component has already set5. Google treats the canonical as a strong signal when choosing the representative URL among duplicates6, so filling in that field is the cheapest SEO step in Joomla.

Titles and descriptions are written in two places. On the menu item, the Page Display tab holds Browser Page Title and the Metadata tab holds Meta Description and Robots. On the article, the Publishing tab holds Meta Description, Keywords and Robots7.

How do you configure Joomla's robots.txt?

Joomla ships a robots.txt.dist, and the installer renames it to robots.txt if none exists8. Updates never touch your robots.txt: they drop in a fresh robots.txt.dist for you to compare. If Joomla lives in a subfolder, the file must go to the domain root with the folder prefixed to every path (Disallow: /joomla/administrator/)9.

This is the Joomla 6.1 file with two additions: the Sitemap line, which Google requires as a full URL10, and a group for training crawlers. We checked it with Protego, which applies Google's rules: articles, /images/ and /media/ (where Joomla has kept CSS and JavaScript since version 4) stay open to Googlebot, OAI-SearchBot, Claude-SearchBot and PerplexityBot; the admin area and the API stay closed.

User-agent: *
Disallow: /administrator/
Disallow: /api/
Disallow: /bin/
Disallow: /cache/
Disallow: /cli/
Disallow: /components/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /layouts/
Disallow: /libraries/
Disallow: /logs/
Disallow: /modules/
Disallow: /plugins/
Disallow: /tmp/

# Model training: blocking it does not remove you from ChatGPT or Google
User-agent: GPTBot
User-agent: ClaudeBot
User-agent: Google-Extended
User-agent: Applebot-Extended
User-agent: CCBot
Disallow: /

Sitemap: https://www.example.com/sitemap.xml

The second group is optional and editorial. GPTBot and ClaudeBot are for model training; the crawlers that decide whether ChatGPT or Claude can cite you are OAI-SearchBot and Claude-SearchBot, and Google-Extended has no effect on Google Search111213.

Which security headers does Joomla send out of the box?

Since version 4, Joomla includes the System - HTTP Headers plugin, enabled on new installs1415. You will find it under System > Plugins. This is what it sends and what you have to decide16:

Header
X-Frame-Options
Default
On, SAMEORIGIN
What to do
Keep it
Header
Referrer-Policy
Default
strict-origin-when-cross-origin
What to do
Keep it
Header
Cross-Origin-Opener-Policy
Default
same-origin
What to do
Keep it; review it if a payment or login pop-up stops working
Header
Strict-Transport-Security (HSTS)
Default
Off; suggested max-age of one year
What to do
Turn it on with a short max-age and raise it later
Header
Content-Security-Policy
Default
Off; when enabled, Report-Only is ticked
What to do
Start in Report-Only with the Nonce option
Header
Force HTTP Headers
Default
Empty
What to do
Add Permissions-Policy if you need it

Two warnings. Joomla's own guide to this screen recommends a max-age of one or two years and ticking Preload15. Preload is the opt-in to the browsers' preload list, which forces HTTPS on the domain and every subdomain, and getting off it takes months1617. Start with a one-day max-age, check that everything, subdomains included, works over https, and only then raise it and consider Preload.

The second: a CSP applied in one go breaks things. Enable Content-Security-Policy with Report-Only, read the warnings in the browser console and add the missing directives. Joomla can attach a nonce to scripts and styles loaded through its API, but not to ones an extension hard-codes. If you would rather set headers on the server, the guide to Apache .htaccess HTTPS, HSTS and security headers has ready-made blocks; just do not set them in both places.

How do you add structured data in Joomla without extensions?

Since Joomla 5, core ships a System - Schema.org system plugin plus one plugin per schema type18. In 6.1 the types are Article, BlogPosting, Book, Event, JobPosting, Organization, Person, Recipe and Custom, all enabled on a new install14. Output is JSON-LD in the page <head>19.

  1. Go to System > Plugins, open System - Schema.org and fill in Base Type (Organization or Person), Name, Image and Social Media Accounts. Until you save it, the Schema tab on articles only shows a notice that configuration is pending19.
  2. On each article, open the Schema tab, choose the type (Article or BlogPosting for a blog, Event for listings, Recipe for recipes) and fill in the fields.
  3. For anything not on the list, the Schema.org - Custom plugin accepts your own JSON-LD and warns you if @context or @type is missing20. That is the route for a LocalBusiness with address and opening hours on your contact page.

Do not use Custom to mark up FAQ or HowTo for Google's benefit: HowTo stopped showing as a rich result in 2023 and FAQ in 202621.

What about the XML sitemap?

Core Joomla does not generate an XML sitemap. You need an extension from the Joomla Extensions Directory; pick one maintained for Joomla 6 that leaves out items set to noindex. Then add the Sitemap: line to robots.txt and submit the sitemap in Search Console.

How to check it

  • Canonical: view the source of an article and search for rel="canonical". If it is missing, check Site Domain.
  • Headers: curl -I https://www.example.com/ should show x-frame-options, referrer-policy, x-content-type-options and, if enabled, strict-transport-security. Mozilla's HTTP Observatory scores them.
  • Structured data: run an article and the home page through the Rich Results Test.
  • robots.txt and sitemap: Search Console's robots.txt and Sitemaps reports.

What SmoothSeen does with this

SmoothSeen checks a page of your site for what this guide configures: robots.txt, sitemap, canonical and noindex, titles and descriptions, structured data, HTTPS and the redirect to https, and security headers via Mozilla's HTTP Observatory. On the AI side it looks at which crawlers your robots.txt allows, separating search from training, and whether your server returns a 403 to any of them while serving the page to a browser.

What to do this week

Open the System - SEF plugin and set Site Domain to your https:// domain. Then enable HSTS in System - HTTP Headers with a one-day max-age and check the header with curl -I. To see the rest of the list measured, run an SEO audit with SmoothSeen.

Frequently asked questions

Why doesn't Joomla add a canonical tag to my pages?

Because the System - SEF plugin only adds it when the Site Domain field has a value. That is how the plugin is written, not a fault in your template. Fill it in with your preferred domain, including https:// and with or without www to match how your site is indexed, then clear Joomla's cache so stored pages are rebuilt with the tag.

Do I need to rename htaccess.txt if my server runs Nginx?

No. Nginx does not read .htaccess files: URL rewriting goes in the server block, passing to index.php any request that does not match a real file. Joomla links from the Use URL Rewriting option itself to its Nginx hosting notes. Remember that the X-Content-Type-Options header the .htaccess file provides must then be set in Nginx too.

Should I enable HSTS Preload in the Joomla plugin?

Only after weeks of HSTS running without problems, with a two-year max-age and every subdomain served over HTTPS with a valid certificate. The plugin itself warns that leaving the preload list takes months. For most sites, HSTS without Preload already protects returning visitors.

Do the Schema.org plugins replace an SEO extension?

They cover the most common types for a content site and the organisation's identity without installing anything. They do not build a sitemap, manage redirects or offer ecommerce types. For a blog, an events site or a corporate site they are probably enough; if you sell products, you will need more.

Sources

  1. 1Joomla! Roadmap, Joomla! Developer Network, accessed 7 October 2026.
  2. 2Global Configuration strings (com_config.ini), official joomla/joomla-cms repository, 6.1-dev branch, accessed 7 October 2026.
  3. 3htaccess.txt, official joomla/joomla-cms repository, 6.1-dev branch, accessed 7 October 2026.
  4. 4System - SEF plugin strings (plg_system_sef.ini), official joomla/joomla-cms repository, 6.1-dev branch, accessed 7 October 2026.
  5. 5plugins/system/sef/src/Extension/Sef.php, onAfterDispatch function, official joomla/joomla-cms repository, 6.1-dev branch, accessed 7 October 2026.
  6. 6How to specify a canonical URL with rel="canonical" and other methods, Google Search Central, updated 10 July 2026.
  7. 7Common admin strings (joomla.ini), official joomla/joomla-cms repository, 6.1-dev branch, accessed 7 October 2026.
  8. 8installation/src/Model/CleanupModel.php, official joomla/joomla-cms repository, 6.1-dev branch, accessed 7 October 2026.
  9. 9robots.txt.dist, official joomla/joomla-cms repository, 6.1-dev branch, accessed 7 October 2026.
  10. 10How Google interprets the robots.txt specification, Google Search Central, updated 31 August 2026.
  11. 11Overview of OpenAI Crawlers, OpenAI, accessed 7 October 2026.
  12. 12Does Anthropic crawl data from the web, and how can site owners block the crawler?, Anthropic, updated 7 April 2026.
  13. 13AI features and your website, Google Search Central, updated 10 December 2025.
  14. 14installation/sql/mysql/base.sql (extensions enabled at install), official joomla/joomla-cms repository, 6.1-dev branch, accessed 7 October 2026.
  15. 15Security HTTP Headers, Joomla! User Manual, accessed 7 October 2026.
  16. 16System - HTTP Headers plugin strings (plg_system_httpheaders.ini), official joomla/joomla-cms repository, 6.1-dev branch, accessed 7 October 2026.
  17. 17Strict-Transport-Security header, MDN Web Docs, updated 11 September 2026.
  18. 18Schema.org System Plugin, Joomla! User Manual, accessed 7 October 2026.
  19. 19System - Schema.org plugin strings (plg_system_schemaorg.ini), official joomla/joomla-cms repository, 6.1-dev branch, accessed 7 October 2026.
  20. 20Schema.org - Custom plugin strings (plg_schemaorg_custom.ini), official joomla/joomla-cms repository, 6.1-dev branch, accessed 7 October 2026.
  21. 21Latest Google Search documentation updates, Google Search Central, accessed 7 October 2026.

How to cite this article

SmoothSeen. (2026, October 7). Joomla SEO: friendly URLs, canonicals, security headers and schema.org. https://smoothseen.com/en/blog/joomla-seo/

Who writes this

SmoothSeen is a website audit tool that measures visibility in search engines and AI assistants and delivers reports under the agency's own brand.

This blog belongs to SmoothSeen: when an article discusses the product, it does so knowing the product is ours. Third-party figures link to their original source.

Change history

  • First version.

Keep reading

Joomla SEO for Joomla 5 and 6: URLs, headers, schema