Skip to main content
mySites.guru
5+ live

Joomla extension security alerts (22 Aug) Fabrik 4.7.2ZOO: unauth RCEPhoca Cart: unauth SQLiJCE 2.9.99.10SP Page Builder RCE

Our approach to the Cyber Resilience Act

Every company selling software into the EU will have one of these pages by December 2027, because the law will more or less require it. We would rather publish ours before the first deadline than after it. The first deadline is 11 September 2026.

What the CRA is

The Cyber Resilience Act, Regulation (EU) 2024/2847, makes cybersecurity a legal condition of selling software in the EU, which no law had done before. Anything the Act calls a product with digital elements, meaning software or hardware supplied commercially to users in the EU, has to be secure by design, supported with free security updates, and documented, wherever in the world the company behind it sits. Two dates matter. From 11 September 2026, manufacturers must report actively exploited vulnerabilities and serious security incidents to the EU cyber agency ENISA within 24 hours of learning about them. From 11 December 2027, the full regime applies: security requirements, technical documentation, declared support periods and CE marking.

Which part of mySites.guru it covers

Most of mySites.guru is a service you reach through a browser, which the CRA does not treat as a product. The part it does cover is the connector: the extension you install on each Joomla or WordPress site so that we can audit and manage it. The European Commission's guidance of July 2026 puts it plainly:

An application supplied to the user as a locally installed client that executes on the user's device is a product with digital elements.

The connector runs on your server, so that is us. The platform behind it counts as the connector's remote data processing, which means the Act's security requirements follow the connector into our infrastructure rather than stopping at your site. We think that is the right outcome. The component we ask you to trust on your server should be the part the law holds us to.

The connector's core functionality is site management and auditing, which the Act classifies as a standard product that the manufacturer assesses itself. None of this reaches you, either: installing or running our connector creates no CRA obligations for you, because the duties belong to the people who make software, not the people who use it.

We have been doing most of this since 2012

The honest reason this page is short on drama is that the CRA asks software companies to behave the way this one already does. We publish a security contact and disclosure policy in our security.txt, and we sit on the other side of that process constantly: our founder is credited as the reporter on more than 60 CVEs, most of them in Joomla extensions, found while protecting the sites on this platform. Security updates to the connector have always been free, shipped promptly and delivered automatically. When a vulnerability in a third-party extension or plugin puts our customers' sites at risk, we research it, report it to the vendor, and flag affected sites in every customer's dashboard.

Our commitments

  • At least five years of free security updates for the connector, the CRA's minimum support period. The connector itself is free, and we will supply and patch it for at least five years. That is a promise about the software, not five years of free service: the mySites.guru subscription is separate. In practice the connector has been updated continuously since 2012 and we have no plans to stop.
  • From 11 September 2026, we report any actively exploited vulnerability in our software, and any serious incident affecting its security, to ENISA and the relevant national incident response team within the Act's 24 and 72 hour windows, and we tell affected customers what happened and what to do.
  • Before 11 December 2027, we will complete the technical documentation, software bill of materials, conformity assessment and CE marking the Act requires for the connector.
  • We will not claim to be certified against the CRA before such a thing exists. The technical standards behind the Act are still being written, so no software company can honestly claim that today, whatever their sales page says.

What this means for agencies

The same law covers the companies behind the commercial extensions, plugins and templates your client sites run. From 11 September 2026 they carry the same reporting duties we do, and from December 2027 the same security and support obligations. Expect vulnerability disclosures to become more frequent and more formal over the next eighteen months, because for the first time sitting on a known exploited flaw is illegal rather than merely shabby. The practical effect on your week is more advisories and more updates that genuinely matter, which is precisely the work mySites.guru already does for you: tracking versions and flagging vulnerable extensions across your whole portfolio of client sites. And when a client's compliance process asks about the tools you use, point them here.

In plain terms

We follow the law that applies to us, in the UK, in Jersey and in the EU where our customers are. This page, like our AI statement, exists so you can see exactly where we stand rather than take a badge on faith. If your own compliance process needs something specific from us in writing, ask and a person will reply.

Last reviewed . This page is maintained by hand and reviewed when the law or our practice changes.