So I found myself on Andrew's blog the other day and cam across this tool and thought it would be useful for others, since many times J!! gets hacked from installing and or not upgrading 3rd party components and modules.
www.theartofjoomla.com/extensions/jhttp-scan.html
From the page:jscan_http is a command line utility that scans the directory of a Joomla site for PHP files and tries to access them directly via the web server. Ideally no output should be received from directly accessing any PHP file, with the exception of index.php, index2.php (etc) which should display regular HTML output. Some files will return warning text, such as "Restricted Access", and these will be ignored and considered safe. Any unexpected output will be logged to the console.
Although made for developers, I would think it would be of use to all to check for vulnerable extensions on your own sites.
Cheers,
Rich