Joomla 9.4.0 Stable
Released on: Wednesday, 07 October 2026 10:41
What's new
Version 9.4.0 is a security and maintenance release, and we recommend all users update. It also adds a Task - JCH Optimize plugin to schedule the Recache routine with the Joomla! Scheduler.
Requirements: this release requires PHP 8.1 or later and Joomla! 5.0 or later.
Security: this release fixes a cross-site scripting issue where encoded characters in URLs, such as search query links, could be decoded during optimization. It also requires a form token and administrator permissions for all administrator tasks, fixes an open redirect, validates image paths returned by the image optimization service, and secures the Page Cache hit counter. Bundled third-party libraries have been updated to current stable releases.
Settings exports are now downloaded directly and no longer include the Cloudflare API token or Redis password. Cache storage now stores identical optimized content only once, which reduces cache size on disk.
Several bugs were fixed, including the Recache Base URL fallback, responsive background CSS on LCP images, critical CSS for imported stylesheets, cache garbage collection, cache size reporting, and image dimension attributes.
Developed and tested on up to PHP 8.5.11 and Joomla! 6.1.4Changelog
New features
- Add a Task - JCH Optimize plugin to schedule the Recache routine with the Joomla Scheduler.
- Show a warning on the JCH Optimize dashboard when system plugins aren't in the order JCH Optimize needs, with a button to reorder them.
- Show a warning on the Page Cache page when System Debug turns off Use HTTP Requests (Capture Cache).
Changes
- Importing settings keeps the site's current Cloudflare API token and Redis password when the file doesn't include them.
- Improve cache storage by deduplicating identical optimized content, reducing cache size on disk.
- Raise the minimum requirements to PHP 8.1 and Joomla! 5.0.
- Settings exports are now downloaded directly and no longer include the Cloudflare API token or Redis password.
- Update bundled third-party libraries to current stable releases, including Symfony DomCrawler, Guzzle and Laminas.
- When the Site URL ($live_site) is set in Global Configuration, Page Cache only stores pages requested on that host.
Bug fixes
- [HIGH] Fix a cross-site scripting vulnerability where encoded characters in URLs, such as search query links, were decoded during optimization.
- [HIGH] Fix an open redirect through the return parameter in Mode Switcher and Utility tasks.
- [HIGH] Fix the Page Cache hit counter allowing a request to run any component's model. Hits are now only recorded for published articles, contacts, news feeds, tags and categories the visitor can access.
- [HIGH] Remove the jchbackend URL parameter that disabled optimization for any visitor.
- [HIGH] Require a valid form token and administrator permissions for all administrator tasks that change settings or files.
- [HIGH] Validate image URLs and paths returned by the image optimization service and keep image folders within the site root.
- [LOW] Fix HTML minification options and settings serialization.
- [LOW] Fix Order Plugins leaving JCH Optimize before other system plugins that have a high ordering value.
- [LOW] Fix Pro-only administrator features appearing in the free edition.
- [LOW] Fix hits not being recorded for cached contact, tag and news feed pages.
- [LOW] Fix invalid width and height attributes on images.
- [LOW] Fix relative URLs on pages with a tag being resolved against the page URL instead of the base, affecting combined files, image dimensions, CDN URLs and preloads.
- [LOW] Fix the Component Configuration dashboard link checking the wrong permission.
- [LOW] Fix the port being dropped from page URLs when the Site URL ($live_site) uses a non-standard port.
- [LOW] Fix the total cache size being under-reported for some cache storage adapters.
- [LOW] Fix the untranslated Page Cache toggle error message, and the success message always saying "enabled".
- [LOW] Validate Page Cache IDs before deleting cached pages.
- [MEDIUM] Escape file and folder names in the Optimize Images file tree.
- [MEDIUM] Fix critical CSS from @import chains overwriting each other in the cache.
- [MEDIUM] Fix garbage collection removing cache files that were still in use.
- [MEDIUM] Fix responsive background CSS being lost on LCP images and excluded files.
- [MEDIUM] Fix the Recache command and task not falling back to the site URL when Recache Base URL is empty.
- [MEDIUM] Fix the jchnooptimize URL parameter not disabling optimization.
- [MEDIUM] Ignore malformed Host headers instead of letting them change the detected page URL.
- [MEDIUM] Reject malformed host names in Page Cache and Capture Cache keys, and unsafe characters and path segments in Capture Cache file paths.
JCH Optimize for Joomla!
Joomla 4.4 Joomla 5.0 Joomla 5.1 Joomla 5.2 Joomla 5.3 Joomla 5.4 Joomla 6.0 Joomla 6.1
pkg_jchoptimize-9.4.0-core.zip
Download now
| Downloaded | 354 times |
| File size | 1.49 Mb |
| MD5 Signature | 072799d74664a7ff59fbfeed4232d53f |
| SHA1 Signature | fa763df0635640cb0e660f8134fb1b273e0bf4e5 |
| SHA-256 Signature | d8c77a496081375759484ec32f020ca1c547a4dc23a863ff74f94082e52d029b |
| SHA-384 Signature | 7566a1784fc817c86e10d63191d775a790ce5d7ef991b6102c34ac795f479490393522769f701647461fe54bb6d4a02b |
| SHA-512 Signature | 62d14db13f1ecd10016286e92d246aab92cb915466212bc44d6ecb796d7e1e5f1d358a150fd19d6fb3c302a57a1bb3725bd1dd437c95f76298b581d1ef5bcd28 |
| Compatibility | Joomla 4.4 Joomla 5.0 Joomla 5.1 Joomla 5.2 Joomla 5.3 Joomla 5.4 Joomla 6.0 Joomla 6.1 |
JCH Optimize performs several front-end optimizations for fast downloads.