Joomla SEO: friendly URLs, canonicals, security headers and schema.org
Published 7 October 20268 min readBy the SmoothSeen editorial team
Joomla SEO can be handled almost entirely with core features: friendly URLs and rewriting in Global Configuration, canonicals and redirects through the System - SEF plugin, security headers through System - HTTP Headers and structured data through the Schema.org plugins. Only the XML sitemap needs an extension. Everything below applies to Joomla 5.4 and 6.1.
Key points
- The current release is Joomla 6.1; Joomla 5.4 stops receiving bug fixes on 13 October 2026 and gets security fixes only until 12 October 2027.
- Joomla only adds a canonical tag if you fill in the Site Domain field of the System - SEF plugin; without it there is no canonical at all.
- The System - HTTP Headers plugin ships enabled and sends X-Frame-Options, Referrer-Policy and Cross-Origin-Opener-Policy; HSTS and CSP have to be switched on.
- Since Joomla 5, core outputs JSON-LD through nine Schema.org plugins (Article, BlogPosting, Book, Event, JobPosting, Organization, Person, Recipe and Custom); there is no LocalBusiness or Product type.
- Core Joomla does not generate an XML sitemap: you need an extension.
To check it on your own site: SEO audit
On this page
- Which Joomla version should you run in October 2026?
- How do you turn on friendly URLs in Joomla?
- How does Joomla prevent duplicate content?
- How do you configure Joomla's robots.txt?
- Which security headers does Joomla send out of the box?
- How do you add structured data in Joomla without extensions?
- What about the XML sitemap?
- How to check it
- What SmoothSeen does with this
- What to do this week
- Frequently asked questions
Joomla is an open-source PHP content management system. It controls URLs, page titles and metadata, the canonical tag, robots.txt (a file in the web root), several HTTP headers and schema.org markup. It does not control the server: the server-level redirect from http to https, compression and browser caching depend on Apache, Nginx or your host. Labels below are quoted exactly as they appear in Joomla's English language files.
Which Joomla version should you run in October 2026?
The current major release is Joomla 6, launched on 14 October 2025; its latest version is 6.1.4 and 6.2.0 is scheduled for 13 October 20261. Joomla 5.4 is in bug-fix-only mode until 13 October 2026 and will get security fixes until 12 October 20271. If you are still on 5, plan the move to 6 this year. Every SEO setting in this guide exists in both lines.
- What
- Clean URLs without
index.php - Joomla does it
- Yes, with rewriting enabled
- You (or the server) do it
- Rename
htaccess.txtor configure Nginx
- What
- Canonical
- Joomla does it
- Yes, once Site Domain is set
- You (or the server) do it
- Check extensions that add a second one
- What
- robots.txt
- Joomla does it
- Created at install
- You (or the server) do it
- Add the Sitemap line and your AI policy
- What
- Security headers
- Joomla does it
- X-Frame-Options, Referrer-Policy, COOP, HSTS and CSP
- You (or the server) do it
X-Content-Type-Optionscomes from.htaccess
- What
- Structured data
- Joomla does it
- Organization, Person, Article and six more types
- You (or the server) do it
- LocalBusiness or Product through the Custom plugin
- What
- XML sitemap
- Joomla does it
- No
- You (or the server) do it
- An extension from the official directory
How do you turn on friendly URLs in Joomla?
The options live under System > Global Configuration, Site tab, SEO section2:
- Search Engine Friendly URLs:
Yes. Turnsindex.php?option=com_content&view=article&id=1into readable paths. - Use URL Rewriting:
Yes, but prepare the server first. On Apache and LiteSpeed, renamehtaccess.txtto.htaccess; on IIS,web.config.txttoweb.config; on Nginx you must configure the server2. Switch it on without doing so and inner pages may stop loading. - Add Suffix to URL:
No, unless you already have.htmlURLs indexed. - Unicode Aliases:
Nofor an English site. WithNo, Joomla transliterates aliases, so «über» becomes «ueber» in en-GB. - Site Name in Page Titles:
Afterappends the site name to each<title>.
On the Server tab, Force HTTPS has three values: None, Administrator Only and Entire Site. Choose Entire Site only once the certificate works, and enable Behind Load Balancer if TLS ends at a proxy or load balancer2.
Renaming htaccess.txt comes with a bonus: the Joomla 6.1 file already sends X-Content-Type-Options: nosniff and disables JavaScript inside SVG files opened directly3.
How does Joomla prevent duplicate content?
Through the System - SEF plugin. Global Configuration itself points out that more SEO settings live there2. Find it under System > Plugins and review these options4:
- Option
- Site Domain
- What it does
- Preferred domain for the canonical;
https://example.comandhttps://www.example.comcount as different domains - Suggested value
- Your domain with
https://
- Option
- Strict Routing
- What it does
- 301-redirects URLs the router treats as duplicates
- Suggested value
- On
- Option
- Strict handling of index.php
- What it does
- Strips
index.phpfrom URLs and redirects requests that contain it - Suggested value
- On if you use rewriting
- Option
- Trailing slash for URLs
- What it does
- Forces URLs with or without a trailing slash, with a redirect; only without a suffix
- Suggested value
- Whatever form is already indexed
The detail almost nobody knows is in the plugin code: if Site Domain is empty, Joomla adds no canonical tag at all. Once you fill it in, the plugin outputs <link rel="canonical"> with your domain plus the current path and query string, or rewrites with your domain any canonical a component has already set5. Google treats the canonical as a strong signal when choosing the representative URL among duplicates6, so filling in that field is the cheapest SEO step in Joomla.
Titles and descriptions are written in two places. On the menu item, the Page Display tab holds Browser Page Title and the Metadata tab holds Meta Description and Robots. On the article, the Publishing tab holds Meta Description, Keywords and Robots7.
How do you configure Joomla's robots.txt?
Joomla ships a robots.txt.dist, and the installer renames it to robots.txt if none exists8. Updates never touch your robots.txt: they drop in a fresh robots.txt.dist for you to compare. If Joomla lives in a subfolder, the file must go to the domain root with the folder prefixed to every path (Disallow: /joomla/administrator/)9.
This is the Joomla 6.1 file with two additions: the Sitemap line, which Google requires as a full URL10, and a group for training crawlers. We checked it with Protego, which applies Google's rules: articles, /images/ and /media/ (where Joomla has kept CSS and JavaScript since version 4) stay open to Googlebot, OAI-SearchBot, Claude-SearchBot and PerplexityBot; the admin area and the API stay closed.
User-agent: *
Disallow: /administrator/
Disallow: /api/
Disallow: /bin/
Disallow: /cache/
Disallow: /cli/
Disallow: /components/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /layouts/
Disallow: /libraries/
Disallow: /logs/
Disallow: /modules/
Disallow: /plugins/
Disallow: /tmp/
# Model training: blocking it does not remove you from ChatGPT or Google
User-agent: GPTBot
User-agent: ClaudeBot
User-agent: Google-Extended
User-agent: Applebot-Extended
User-agent: CCBot
Disallow: /
Sitemap: https://www.example.com/sitemap.xmlThe second group is optional and editorial. GPTBot and ClaudeBot are for model training; the crawlers that decide whether ChatGPT or Claude can cite you are OAI-SearchBot and Claude-SearchBot, and Google-Extended has no effect on Google Search111213.
Which security headers does Joomla send out of the box?
Since version 4, Joomla includes the System - HTTP Headers plugin, enabled on new installs1415. You will find it under System > Plugins. This is what it sends and what you have to decide16:
- Header
- X-Frame-Options
- Default
- On,
SAMEORIGIN - What to do
- Keep it
- Header
- Referrer-Policy
- Default
strict-origin-when-cross-origin- What to do
- Keep it
- Header
- Cross-Origin-Opener-Policy
- Default
same-origin- What to do
- Keep it; review it if a payment or login pop-up stops working
- Header
- Strict-Transport-Security (HSTS)
- Default
- Off; suggested
max-ageof one year - What to do
- Turn it on with a short
max-ageand raise it later
- Header
- Content-Security-Policy
- Default
- Off; when enabled, Report-Only is ticked
- What to do
- Start in Report-Only with the Nonce option
- Header
- Force HTTP Headers
- Default
- Empty
- What to do
- Add Permissions-Policy if you need it
Two warnings. Joomla's own guide to this screen recommends a max-age of one or two years and ticking Preload15. Preload is the opt-in to the browsers' preload list, which forces HTTPS on the domain and every subdomain, and getting off it takes months1617. Start with a one-day max-age, check that everything, subdomains included, works over https, and only then raise it and consider Preload.
The second: a CSP applied in one go breaks things. Enable Content-Security-Policy with Report-Only, read the warnings in the browser console and add the missing directives. Joomla can attach a nonce to scripts and styles loaded through its API, but not to ones an extension hard-codes. If you would rather set headers on the server, the guide to Apache .htaccess HTTPS, HSTS and security headers has ready-made blocks; just do not set them in both places.
How do you add structured data in Joomla without extensions?
Since Joomla 5, core ships a System - Schema.org system plugin plus one plugin per schema type18. In 6.1 the types are Article, BlogPosting, Book, Event, JobPosting, Organization, Person, Recipe and Custom, all enabled on a new install14. Output is JSON-LD in the page <head>19.
- Go to System > Plugins, open System - Schema.org and fill in Base Type (Organization or Person), Name, Image and Social Media Accounts. Until you save it, the Schema tab on articles only shows a notice that configuration is pending19.
- On each article, open the Schema tab, choose the type (Article or BlogPosting for a blog, Event for listings, Recipe for recipes) and fill in the fields.
- For anything not on the list, the Schema.org - Custom plugin accepts your own JSON-LD and warns you if
@contextor@typeis missing20. That is the route for a LocalBusiness with address and opening hours on your contact page.
Do not use Custom to mark up FAQ or HowTo for Google's benefit: HowTo stopped showing as a rich result in 2023 and FAQ in 202621.
What about the XML sitemap?
Core Joomla does not generate an XML sitemap. You need an extension from the Joomla Extensions Directory; pick one maintained for Joomla 6 that leaves out items set to noindex. Then add the Sitemap: line to robots.txt and submit the sitemap in Search Console.
How to check it
- Canonical: view the source of an article and search for
rel="canonical". If it is missing, check Site Domain. - Headers:
curl -I https://www.example.com/should showx-frame-options,referrer-policy,x-content-type-optionsand, if enabled,strict-transport-security. Mozilla's HTTP Observatory scores them. - Structured data: run an article and the home page through the Rich Results Test.
- robots.txt and sitemap: Search Console's robots.txt and Sitemaps reports.
What SmoothSeen does with this
SmoothSeen checks a page of your site for what this guide configures: robots.txt, sitemap, canonical and noindex, titles and descriptions, structured data, HTTPS and the redirect to https, and security headers via Mozilla's HTTP Observatory. On the AI side it looks at which crawlers your robots.txt allows, separating search from training, and whether your server returns a 403 to any of them while serving the page to a browser.
What to do this week
Open the System - SEF plugin and set Site Domain to your https:// domain. Then enable HSTS in System - HTTP Headers with a one-day max-age and check the header with curl -I. To see the rest of the list measured, run an SEO audit with SmoothSeen.
Frequently asked questions
Why doesn't Joomla add a canonical tag to my pages?
Because the System - SEF plugin only adds it when the Site Domain field has a value. That is how the plugin is written, not a fault in your template. Fill it in with your preferred domain, including https:// and with or without www to match how your site is indexed, then clear Joomla's cache so stored pages are rebuilt with the tag.
Do I need to rename htaccess.txt if my server runs Nginx?
No. Nginx does not read .htaccess files: URL rewriting goes in the server block, passing to index.php any request that does not match a real file. Joomla links from the Use URL Rewriting option itself to its Nginx hosting notes. Remember that the X-Content-Type-Options header the .htaccess file provides must then be set in Nginx too.
Should I enable HSTS Preload in the Joomla plugin?
Only after weeks of HSTS running without problems, with a two-year max-age and every subdomain served over HTTPS with a valid certificate. The plugin itself warns that leaving the preload list takes months. For most sites, HSTS without Preload already protects returning visitors.
Do the Schema.org plugins replace an SEO extension?
They cover the most common types for a content site and the organisation's identity without installing anything. They do not build a sitemap, manage redirects or offer ecommerce types. For a blog, an events site or a corporate site they are probably enough; if you sell products, you will need more.
Sources
- 1Joomla! Roadmap, Joomla! Developer Network, accessed 7 October 2026.
- 2Global Configuration strings (com_config.ini), official joomla/joomla-cms repository, 6.1-dev branch, accessed 7 October 2026.
- 3htaccess.txt, official joomla/joomla-cms repository, 6.1-dev branch, accessed 7 October 2026.
- 4System - SEF plugin strings (plg_system_sef.ini), official joomla/joomla-cms repository, 6.1-dev branch, accessed 7 October 2026.
- 5plugins/system/sef/src/Extension/Sef.php, onAfterDispatch function, official joomla/joomla-cms repository, 6.1-dev branch, accessed 7 October 2026.
- 6How to specify a canonical URL with rel="canonical" and other methods, Google Search Central, updated 10 July 2026.
- 7Common admin strings (joomla.ini), official joomla/joomla-cms repository, 6.1-dev branch, accessed 7 October 2026.
- 8installation/src/Model/CleanupModel.php, official joomla/joomla-cms repository, 6.1-dev branch, accessed 7 October 2026.
- 9robots.txt.dist, official joomla/joomla-cms repository, 6.1-dev branch, accessed 7 October 2026.
- 10How Google interprets the robots.txt specification, Google Search Central, updated 31 August 2026.
- 11Overview of OpenAI Crawlers, OpenAI, accessed 7 October 2026.
- 12Does Anthropic crawl data from the web, and how can site owners block the crawler?, Anthropic, updated 7 April 2026.
- 13AI features and your website, Google Search Central, updated 10 December 2025.
- 14installation/sql/mysql/base.sql (extensions enabled at install), official joomla/joomla-cms repository, 6.1-dev branch, accessed 7 October 2026.
- 15Security HTTP Headers, Joomla! User Manual, accessed 7 October 2026.
- 16System - HTTP Headers plugin strings (plg_system_httpheaders.ini), official joomla/joomla-cms repository, 6.1-dev branch, accessed 7 October 2026.
- 17Strict-Transport-Security header, MDN Web Docs, updated 11 September 2026.
- 18Schema.org System Plugin, Joomla! User Manual, accessed 7 October 2026.
- 19System - Schema.org plugin strings (plg_system_schemaorg.ini), official joomla/joomla-cms repository, 6.1-dev branch, accessed 7 October 2026.
- 20Schema.org - Custom plugin strings (plg_schemaorg_custom.ini), official joomla/joomla-cms repository, 6.1-dev branch, accessed 7 October 2026.
- 21Latest Google Search documentation updates, Google Search Central, accessed 7 October 2026.
How to cite this article
SmoothSeen. (2026, October 7). Joomla SEO: friendly URLs, canonicals, security headers and schema.org. https://smoothseen.com/en/blog/joomla-seo/
Keep reading
What is SEO? How search engine optimisation works and how to improve it in 2026
What SEO is, how Google decides which pages to show and a prioritised checklist to improve your rankings with free tools.
.htaccess force HTTPS: redirect to https, enable HSTS and add security headers in Apache
How to force HTTPS in .htaccess or an Apache VirtualHost, roll out HSTS safely and add security headers. Every snippet tested on Apache 2.4.69.
.htaccess gzip and Brotli: browser caching and blocking AI bots in Apache
How to enable gzip and Brotli, set browser caching and block AI training bots in Apache .htaccess without dropping out of ChatGPT search. Tested.