JoomShaper Ends Joomla 3 Security Fixes

Update, 15 July 2026: JoomShaper has reversed this
Six days after the announcement below, JoomShaper released Joomla 3 security patches for Helix Ultimate, Helix3 and SP Page Builder. The "no security patches, regardless of severity" line no longer holds. The rest of the policy does: no new features, no bug fixes, no technical support, and Joomla 3 remains end of life. We read the patch code, and there is a version gate that stops it installing on older Helix builds. Read our breakdown of what is in the patches. The article below stands as written on 9 July.
JoomShaper, the developer behind SP Page Builder and the Helix framework, has stopped supporting Joomla 3. In an announcement on 9 July 2026 the company confirmed that the Joomla 3 versions of all its products now get no updates, and one line stands out: “No security patches, regardless of severity.” On the company’s stated policy, a critical flaw in the Joomla 3 build of SP Page Builder tomorrow does not get fixed.
That is a defensible decision, and JoomShaper explains it well: they can secure their own code, but “we can’t secure the Joomla core underneath it,” and the Joomla 3 core has been end of life for a long time. The problem is not the decision. The problem is how many live sites this leaves exposed, and how recently JoomShaper’s own extensions have produced exactly the kind of flaw this policy now leaves unpatched.
“No security patches, regardless of severity.”
What JoomShaper Actually Announced
JoomShaper has ended support for the Joomla 3 versions of every product it makes. That covers SP Page Builder, the Helix framework (both Helix Ultimate and the older Helix3), EasyStore, Power Admin, and its Joomla templates. The Joomla 4, 5, and 6 builds of these products are unaffected and still supported. Only the Joomla 3 versions are frozen.
The policy is blunt on purpose. No feature updates, no compatibility fixes, and no security patches “regardless of severity” for the Joomla 3 builds. JoomShaper’s stated reasoning is that patching its own extension does nothing when the platform beneath it, the Joomla 3 core, no longer receives fixes either. That is true, and it is the honest position. It also means a Joomla 3 site running these extensions now has two unpatched layers instead of one.
One clarification worth making, because it gets muddled: Gantry is not a JoomShaper product. Gantry is a RocketTheme framework, and this announcement does not touch it. If you run Gantry-based templates, this specific news is not about you, though the wider Joomla 3 end-of-life problem still is.
Why This Is Worse Than a Normal End-of-Life Notice
Here is the editorial connection JoomShaper did not make, and it is ours, not theirs. Following a disastrous month of security issues for their products, they are freezing Joomla 3 support just as the risk to those products is at its most visible. SP Page Builder had a critical remote code execution flaw exploited in the wild, and the Helix framework produced two more serious issues in the same window. Now the Joomla 3 builds of exactly those products get no more fixes.
In June 2026, SP Page Builder had an unauthenticated file upload vulnerability, CVE-2026-48908, scored CVSS 10.0, the maximum. It let anyone on the internet upload and run a file with no login, and it was used in the wild to plant hidden Joomla Super User accounts. JoomShaper fixed it promptly in version 6.6.2. That fix reached Joomla 4, 5, and 6 sites. Under the policy announced this week, the equivalent fix for a Joomla 3 site would not exist.
This is not hypothetical. SP Page Builder and Helix are among the most widely installed Joomla extensions in the world, precisely the kind of large, front-facing code that keeps producing this class of bug. A vulnerability of the same severity will turn up again. On the policy as announced, Joomla 3 sites would be on their own when it does. JoomShaper has since patched Joomla 3 once, on 15 July, without committing to do it again.
How Many Sites Does This Affect?
More than half of all live Joomla sites. According to W3Techs, as of July 2026 Joomla 3 still accounts for 54.3 percent of every Joomla site online, the single largest share by version. Joomla 5 sits at around 20 percent, Joomla 4 under 10, and Joomla 6 is still in the single digits.
That number is the whole story. This is not a niche announcement affecting a handful of legacy holdouts. It is a policy change that applies to the majority of the Joomla web, most of which also runs SP Page Builder or Helix because those are the tools people built Joomla 3 sites with in the first place. If you manage Joomla sites for clients, the odds are high that some of them fall in exactly this gap.
How Do I Find Every Joomla 3 Site I Manage?
The first job is knowing your exposure, and doing it by hand does not scale. Logging into each site to check its Joomla version and installed extensions is fine for three sites and impossible for thirty. You need one screen that shows every site, its Joomla version, and which JoomShaper extensions each one runs.
mySites.guru keeps a live inventory of every Joomla and WordPress site in your account, with the core version and the full extension list for each. You can filter for Joomla 3 sites in seconds, then cross-reference which of them run SP Page Builder or Helix, so you know which sites are in the danger zone rather than guessing. It also flags end-of-life versions automatically, so an unsupported core shows up as a warning without you going looking for it.
Find your Joomla 3 exposure in one place
Filter for Joomla 3 sites and search for SP Page Builder or Helix to see which sites are exposed. Not a subscriber? Sign up free and connect your sites.
Can I Keep a Joomla 3 Site Patched While I Migrate?
Yes, as a stopgap for the core, but not forever and not for the extensions. There are two separate holes to think about: the Joomla 3 core, and the vendor extensions on top of it.
For the core, mySites.guru can apply the Joomla 3.10.999 project’s backported security patches with a single toggle. That project quietly backported the critical fixes that shipped in Joomla 4 to end-of-life Joomla 3 sites, so a site with the toggle on has the known core holes closed. It is the closest thing to keeping an unsupported core safe, and it does not need an eLTS subscription or any manual file edits.
Patch every known Joomla 3 core issue in one click
mySites.guru applies the backported Joomla 3.10.999 security patches across all your Joomla 3 sites from one screen. It buys you time to migrate. See how the one-click Joomla 3 fix works.
For the extensions, the position changed on 15 July: JoomShaper released Joomla 3 security patches for SP Page Builder, Helix3 and Helix Ultimate after all. Apply the vendor patch where it installs, and check your Helix version first, because the Helix Ultimate package refuses anything below 2.1.0. mySites.guru also backports the same fix logic into the Joomla 3 builds as an in-place guard, applied across every site in your account from one toggle rather than site by site. Either way it is a stopgap, not a solution: closing the door on the flaws we already know about does not make an end-of-life extension supported again. Keeping a Joomla 3 site patched and guarded is sensible while you plan the move; leaving it on SP Page Builder indefinitely is not.
The Real Fix Is Migration
Patching is a holding pattern. The actual answer to an end-of-life core and an end-of-life vendor policy is to get off Joomla 3, and the supported targets are Joomla 5 and Joomla 6. Note that Joomla 4 is not a safe destination either: its own security support ended in October 2025, so migrating from 3 to 4 would land you on another unsupported line. Aim for 5 or 6 directly.
Migration is real work, and the honest framing is that it takes planning rather than a click. The part that trips agencies up is keeping sites connected to their management tooling through the version jump. mySites.guru’s connector handles that, so a site stays monitored and backed up right through the migration rather than dropping off your dashboard mid-move. The migration walkthrough covers the connector swap step by step.
Before you touch anything, take a full backup, and ideally test the migration on a staging copy first. A Joomla 3 site with SP Page Builder content has a lot of layout data that needs to survive the jump, and you want to find any problems on a copy, not on the live site.
This Is Part of a Wider Pattern in Joomla Extensions
JoomShaper freezing Joomla 3 is not an isolated event. It sits inside a run of critical Joomla extension flaws we have documented over recent weeks, and the common thread is unauthenticated file uploads leading to remote code execution. The same class of bug turned up in PageBuilder CK, iCagenda, and Balbooa Forms, and JoomShaper’s own Helix framework had a critical fix shipped quietly as a plain “Security Update” that then fed a defacement wave stored in the database, alongside a separate unauthenticated menu write in Helix Ultimate.
The lesson for anyone running Joomla at scale is that the extension layer is where the attacks land, and a Joomla 3 site now carries that risk with no vendor safety net on either the core or the biggest extensions. That is why the version you run matters as much as the extensions you install.
The Bottom Line
JoomShaper has done the responsible thing by being clear rather than quietly letting Joomla 3 support rot, and “no security patches, regardless of severity” is at least honest. But it applies to more than half the Joomla web, weeks after their own SP Page Builder had a CVSS 10.0 flaw exploited in the wild. Six days later the company patched Joomla 3 anyway, which is the right outcome and worth saying plainly, though it arrived after a week of telling people no fix was coming. If you manage Joomla sites, find every Joomla 3 install you look after, confirm which run SP Page Builder or Helix, apply the vendor patch where it installs, keep the core patched as a stopgap, and move the priority sites to Joomla 5 or 6. Start with a free audit on one site to see what your Joomla 3 exposure actually looks like.
Further Reading
- JoomShaper: Ending Joomla 3 Support - the original vendor announcement, including the “no security patches, regardless of severity” policy.
- JoomShaper: Security Update for Joomla 3 Users - the 15 July reversal, shipping Joomla 3 patches for Helix Ultimate, Helix3 and SP Page Builder.
- Joomla End of Life dates (endoflife.date) - a live reference for which Joomla versions are still supported and when each line reaches end of life.
- Joomla Extended Security Support (eLTS) - the official Joomla project programme that patched Joomla 3 until it ended on 17 February 2025.
- W3Techs Joomla version usage - the current breakdown of live Joomla sites by version, showing how much of the web still runs Joomla 3.
- CVE-2026-48908 - the SP Page Builder unauthenticated file upload record, the flaw that makes this policy change bite.


