Skip to main content
mySites.guru
J!Awards 2026mySites.guru is shortlisted for Your Favourite Tool in Your Joomla WorkflowVote by 11 OctoberHow to vote

1,000+ Days After Joomla 3's End of Life, Everything You Need Is on One Site

1,000+ Days After Joomla 3's End of Life, Everything You Need Is on One Site

Joomla 3 reached end of life on 17 August 2023. On 2 October 2026 that was 1,142 days ago. If you still look after a Joomla 3 site, the questions have not changed in three years: which security holes are open on it, which of its extensions still get fixes, and how long you can reasonably hold off the move to Joomla 5 or 6.

The answers have been scattered across Joomla’s own announcements, a few dozen vendor changelogs and forum threads, and the Joomla 3 posts on this blog. So we have put them on one site: joomla3security.com.

What joomla3security.com is

A free, public reference on where Joomla 3 stands after end of life: the support dates, 46 Joomla extension vendors’ positions, the core and extension vulnerabilities that still apply to Joomla 3, and your options. No account needed to read any of it.

What is on joomla3security.com

The site has six sections:

  • Timeline: the support dates, from Joomla 3.0 in September 2012 to the last paid eLTS release, 3.10.20, in January 2025, and the end of eLTS on 17 February 2025. Since that day there has been no official way to buy a patched Joomla 3 core at any price.
  • Vendors: what each Joomla extension vendor said about Joomla 3, when they said it, and what they did afterwards.
  • Core vulnerabilities: the 39 Joomla security advisories published since 3.10.12 whose flawed code is also in Joomla 3. Each one was fixed in a supported Joomla release, but none has an official Joomla 3 fix, because there are no more Joomla 3 releases.
  • Extension vulnerabilities: the 52 published Joomla extension vulnerabilities that apply to Joomla 3 builds.
  • Your options: stay and patch, migrate, or both, with the costs of each and the community rescue projects compared.
  • An FAQ and a reading list for the detail behind all of it.

The figures behind the site

Joomla 3 sites connected to mySites.guru are measurably worse off than everything else we monitor, and these are some of the best looked-after Joomla sites there are:

5x
More likely to be hacked
4.90% of Joomla 3 sites vs 0.98% on Joomla 6
79%
Have unpatched core files
Of the Joomla 3 sites we can check
68.2%
Behind even 3.10.12
The final free Joomla 3 release
22.3%
Run a vulnerable extension
At least one with a known flaw

Measured across sites connected to mySites.guru on 28 August 2026.

The second and third figures are the fixable ones. The core fixes for most of those holes already exist and no one has applied them, and more than two thirds of Joomla 3 sites are missing years of fixes that Joomla did ship for free before end of life. The agency retainer post goes through what that means for anyone billing a client to keep a Joomla 3 site safe.

Read the vendor tracker first

The core is rarely what gets a Joomla 3 site hacked. The extensions are, and whether an extension still gets security fixes depends entirely on its vendor. The tracker sorts 46 of them into five groups:

13
Stopped
No more Joomla 3 releases
9
Still shipping
Joomla 3 fixes continue
7
Said stopped, kept shipping
Statement and releases disagree

A further 13 vendors have made no public statement and 4 are gone. Counts from joomla3security.com, 2 October 2026.

The seven who said they had stopped and kept shipping are why a written-down end date is worth so little. JoomShaper said its Joomla 3 products would get “no security patches, regardless of severity”, and then Helix Ultimate had its third Joomla 3 patch anyway, followed by an SP Page Builder patch. Thirteen more have never said anything at all. Each vendor has its own page with the quotes, dates and sources, so you can check the extensions you actually run rather than relying on the last announcement you remember.

How mySites.guru patches what Joomla no longer will

joomla3security.com links to the mySites.guru tools that close those gaps, all of them part of the subscription:

See which of your sites are still on Joomla 3

mySites.guru checks every connected site for this automatically and flags it the moment it appears. It runs as part of the full audit on every connected site.

Patch now, migrate one site at a time

Moving from Joomla 3 to Joomla 5 or 6 is closer to a rebuild than a version bump, because templates and plenty of extensions have no direct successor. That makes it a budget conversation with each site owner, and those take time. Most agencies we work with patch every Joomla 3 site now, then migrate them one by one in the order risk and budget allow. The options page sets out when each route makes sense.

Patching has a shelf life, because hosts will eventually drop the PHP versions Joomla 3 needs. It still beats leaving 39 known core holes open while the migration quote waits for sign-off. Start with the timeline and the vendor list, then connect a Joomla 3 site for a free audit to see what is open on yours. Keeping a whole portfolio patched is covered by a single mySites.guru subscription, from £5 a month for one site to £19.99 a month for unlimited.

Further reading

Frequently Asked Questions

What is joomla3security.com?
A reference site from mySites.guru about Joomla 3 after its end of life on 17 August 2023. It holds the support timeline, what every major Joomla extension vendor has said and done about Joomla 3, the core security advisories that have no official Joomla 3 fix, and the choice between patching, migrating or doing both.
Is Joomla 3 still getting security updates?
Not from the Joomla project. Free releases stopped at 3.10.12 in July 2023 and the paid eLTS programme ended on 17 February 2025. Since 3.10.12, Joomla has published 39 security advisories whose flawed code is also in Joomla 3, and none has an official Joomla 3 fix. mySites.guru backports those fixes to 3.10.12 as a one-click patch for subscribers.
Do I need a mySites.guru account to use joomla3security.com?
No. Every page is public. The timeline, the vendor tracker and the vulnerability lists are there to read without signing up. If you want to see which of those holes are open on your own site, you can connect one Joomla 3 site for a free audit with no card.
EU icon: AI MODIFIEDWritten and edited by a human, with AI assistance. Our approach to AI

What our users say

Klaus Brandt
Klaus Brandt
★★★★★

So I'm just two weeks (or so...) here at mySites.guru. What should I say? Perfect. Secure. Reliable. And damn fast! Thank you, Phil, you saved my customers and my soul! :-) Greetings from Germany!

Read more reviews
Billy Tyrcha
Billy TyrchaOwner, Landman Realty LLC
★★★★★

I do not use mySites.guru all the time BUT when I got hacked it was a go to monitoring tool that help dig out the hack along with AI. So, Bookmark mySites.guru if you have a Joomla(s)!

Read more reviews

Read all 285 reviews →

Ready to Take Control?

Start with a free site audit. No credit card required.

Get Your Free Site Audit