1,000+ Days After Joomla 3's End of Life, Everything You Need Is on One Site

Joomla 3 reached end of life on 17 August 2023. On 2 October 2026 that was 1,142 days ago. If you still look after a Joomla 3 site, the questions have not changed in three years: which security holes are open on it, which of its extensions still get fixes, and how long you can reasonably hold off the move to Joomla 5 or 6.
The answers have been scattered across Joomla’s own announcements, a few dozen vendor changelogs and forum threads, and the Joomla 3 posts on this blog. So we have put them on one site: joomla3security.com.
What joomla3security.com is
A free, public reference on where Joomla 3 stands after end of life: the support dates, 46 Joomla extension vendors’ positions, the core and extension vulnerabilities that still apply to Joomla 3, and your options. No account needed to read any of it.
What is on joomla3security.com
The site has six sections:
- Timeline: the support dates, from Joomla 3.0 in September 2012 to the last paid eLTS release, 3.10.20, in January 2025, and the end of eLTS on 17 February 2025. Since that day there has been no official way to buy a patched Joomla 3 core at any price.
- Vendors: what each Joomla extension vendor said about Joomla 3, when they said it, and what they did afterwards.
- Core vulnerabilities: the 39 Joomla security advisories published since 3.10.12 whose flawed code is also in Joomla 3. Each one was fixed in a supported Joomla release, but none has an official Joomla 3 fix, because there are no more Joomla 3 releases.
- Extension vulnerabilities: the 52 published Joomla extension vulnerabilities that apply to Joomla 3 builds.
- Your options: stay and patch, migrate, or both, with the costs of each and the community rescue projects compared.
- An FAQ and a reading list for the detail behind all of it.
The figures behind the site
Joomla 3 sites connected to mySites.guru are measurably worse off than everything else we monitor, and these are some of the best looked-after Joomla sites there are:
Measured across sites connected to mySites.guru on 28 August 2026.
The second and third figures are the fixable ones. The core fixes for most of those holes already exist and no one has applied them, and more than two thirds of Joomla 3 sites are missing years of fixes that Joomla did ship for free before end of life. The agency retainer post goes through what that means for anyone billing a client to keep a Joomla 3 site safe.
Read the vendor tracker first
The core is rarely what gets a Joomla 3 site hacked. The extensions are, and whether an extension still gets security fixes depends entirely on its vendor. The tracker sorts 46 of them into five groups:
A further 13 vendors have made no public statement and 4 are gone. Counts from joomla3security.com, 2 October 2026.
The seven who said they had stopped and kept shipping are why a written-down end date is worth so little. JoomShaper said its Joomla 3 products would get “no security patches, regardless of severity”, and then Helix Ultimate had its third Joomla 3 patch anyway, followed by an SP Page Builder patch. Thirteen more have never said anything at all. Each vendor has its own page with the quotes, dates and sources, so you can check the extensions you actually run rather than relying on the last announcement you remember.
How mySites.guru patches what Joomla no longer will
joomla3security.com links to the mySites.guru tools that close those gaps, all of them part of the subscription:
- The one-click Joomla 3 core patch backports all 39 core advisories to Joomla 3.10.12. One toggle changes 85 core files, and switching it off restores the stock files. The October 2026 update added 14 more fixes, each reproduced on a real 3.10.12 site first.
- JoomShaper’s own Joomla 3 security packages for Helix Ultimate, Helix3 and SP Page Builder deploy across every site in an account, checked against a pinned hash with a backup taken first.
- Every connected site is checked against the mySites.guru Joomla extension vulnerability rules, so a newly disclosed hole in an extension you run gets flagged without you going looking.
See which of your sites are still on Joomla 3
mySites.guru checks every connected site for this automatically and flags it the moment it appears. It runs as part of the full audit on every connected site.
Patch now, migrate one site at a time
Moving from Joomla 3 to Joomla 5 or 6 is closer to a rebuild than a version bump, because templates and plenty of extensions have no direct successor. That makes it a budget conversation with each site owner, and those take time. Most agencies we work with patch every Joomla 3 site now, then migrate them one by one in the order risk and budget allow. The options page sets out when each route makes sense.
Patching has a shelf life, because hosts will eventually drop the PHP versions Joomla 3 needs. It still beats leaving 39 known core holes open while the migration quote waits for sign-off. Start with the timeline and the vendor list, then connect a Joomla 3 site for a free audit to see what is open on yours. Keeping a whole portfolio patched is covered by a single mySites.guru subscription, from £5 a month for one site to £19.99 a month for unlimited.
Further reading
- Joomla is 18! and Extended Security Support for Joomla 3, the Joomla project’s end-of-life and eLTS announcement
- Joomla Extended Long Term Support, the paid programme that ended on 17 February 2025
- The Joomla 3.10.999 project, where the community backports began


