Hi Neil
we run a lot of JoomlaSites with helix, it is a great solution for us.
But since June we had a lot of injections, malware, backdoors, shells and so on. We spent a lot of time to find all this hidden files and to clean the server.
If you only have Current-item Active">, this is not really a problem:
You can easily solve this with https://github.com/zkrana/joomla-security-scanner/tree/main/dist
But I think you have something more.
Scan your webserver for syshack, antonkil, zypeer, wclient, accesson, .phar, kill.gif, kill.png,
com_jce2
com_jce2.SUSPECT
jce.DISABLED
exploit
cve48907
cve354b80aa
cve4f554e27
cve66a60f7e
xsx17r2
J400779
if you find one of this, you have a bigger problem.
Did you use JCE-Editor also?