Skip to main content

Joomla 3 end of life, answered

The questions agencies and site owners ask us most about Joomla 3, now that it has been end of life since 17 August 2023 and the paid eLTS programme has been closed since 17 February 2025. Every figure is a percentage measured across sites connected to mySites.guru, 28 August 2026, unless the answer gives another date.

Joomla 3 questions

When did Joomla 3 reach end of life?
On 17 August 2023. Joomla 3.0 was released on 27 September 2012, and the series shipped 106 stable releases over ten years and ten months. The last public release was 3.10.12 on 8 July 2023. Since end of life the Joomla project has shipped no free security fixes for the 3.x core at any severity. The full sequence is on the Joomla 3 timeline.
Is there still paid support for Joomla 3?
No. The paid Extended Long Term Security support programme (eLTS) patched Joomla 3 for a fee after end of life, and it closed on 17 February 2025. Its last build was 3.10.20 on 7 January 2025. Since then there has been no official route to a patched Joomla 3 core at any price. What remains is community backporting, such as the 3.10.999 project, which the mySites.guru one-click patch applies.
How many Joomla sites are still on Joomla 3?
More than most people assume. Of the Joomla sites in the mySites.guru database that reported in during the 30 days to 29 September 2026, 26.0% were still on Joomla 3. And 68.2% of those Joomla 3 sites are behind even 3.10.12, the final public release. These are managed sites whose owners pay for monitoring, so they are the good end of the Joomla 3 population.
Is a Joomla 3 site actually more likely to be hacked?
Yes, and we can measure it. Across the Joomla sites connected to mySites.guru, 4.90% of Joomla 3 sites are flagged as hacked, against 0.98% of Joomla 6 sites, which is five times the rate. Joomla 4 sits at 4.67% and Joomla 5 at 2.67%. The further a site is from a supported release, the more likely it is to have been compromised. Turned the other way up, 95.1% of Joomla 3 sites in the same dataset are not flagged. The risk depends on what a site runs and whether anyone is watching it.
Can I keep a Joomla 3 site secure without migrating?
You can make it much safer, though it stays unsupported, so treat it as a holding position while you plan the move. Three layers matter: the core, which the community backport patches; the extensions, which only their vendors can fix and which several vendors still do for Joomla 3; and PHP, where Joomla 3 tops out at PHP 8.1, itself end of life since 31 December 2025. The first two can be closed today. The third cannot, which is why migration is still the only real fix. The detail is on your options.
What does the one-click Joomla 3 core patch fix?
It closes 39 published Joomla core advisories that reach back into Joomla 3, by changing 85 core files on the site: 84 replaced with patched copies and one added. It needs Joomla 3.10.12 or a later 3.x build and the PHP zip extension, and switching it off returns the files to stock 3.10.12. It patches the Joomla core only, and it does not clean a site that has already been hacked. Every advisory it closes is listed on the core vulnerabilities page. In the mySites.guru dataset, 79% of the Joomla 3 sites we can check have unpatched core files the patch could fix.
We migrated everything to Joomla 4. Are we safe?
Probably less safe than you think. Joomla 4 has itself reached end of life, with security support ending in October 2025, and in the mySites.guru dataset Joomla 4 sites have the widest vulnerable-extension spread of any branch: 50.6% run at least one Joomla extension with a known vulnerability, against 22.3% of Joomla 3 sites. Joomla 3 is worse on depth, averaging 3.30 vulnerable extensions on an affected site against 2.52 on Joomla 4, so neither branch is in good shape. Migrating once did not solve the problem, because the problem was never the version number.
Why do agencies still have so many Joomla 3 sites?
It is seldom neglect or ignorance. A move from Joomla 3 to Joomla 5 or 6 is closer to a rebuild than an upgrade, because the template and several extensions usually have no direct successor. That makes it a cost conversation the client has to agree to, and if the site visibly works, the client often says no. Underneath that is a commercial problem: most of those sites were sold as a one-off project with no ongoing maintenance attached, so there is no budget line, no retainer and no one being paid to watch the version number.
Can a Joomla 3 fork or patcher keep my sites safe instead of migrating?
No. Several projects exist to extend Joomla 3, including continued 3.x development on GitHub, a fork that numbers its releases 3.11 and up, patchers, and work to make Joomla 3 run on PHP 8. Three problems apply to all of them. They patch the core, but in the mySites.guru dataset the damage is coming through extensions such as YOOtheme Installer, SP Page Builder and JCE, which no core fork touches. Forks that emit version numbers that never existed cannot be read by Joomla's updater, vulnerability databases, WAF rules or inventory tools like ours, so no one can tell you whether the site is safe. And keeping the Joomla name leaves clients and incoming developers unable to tell what they are running. The PHP 8 work is the most useful of the group, but it solves the hosting deadline and leaves the security one open.
What happens when my host removes PHP 7?
A Joomla 3 site that has not been made PHP 8 compatible stops working. On some hosts the switch is also irreversible: Fasthosts is a common example, where a customer moves a site to PHP 8 to test it, finds that it fails, and then discovers there is no route back to PHP 7. And even a site made PHP 8 compatible reaches its ceiling at PHP 8.1, which has been end of life since 31 December 2025. So the real choice is between migrating on a date you chose, with a rollback plan, and migrating on the date your host chose.
Does mySites.guru work with Joomla 3?
Yes. mySites.guru has a dedicated Joomla 3 connector and supports Joomla versions right back to 1.5, so those sites stay visible and watched while you move them. For Joomla 3 specifically it applies the one-click core patch, deploys JoomShaper's own Joomla 3 packages for Helix Ultimate, Helix3 and SP Page Builder, flags every published core CVE against each site's exact version, and alerts you to vulnerable extensions. The Joomla 3 connector does not run on Joomla 4 or later, so a migrated site is reconnected with the Joomla 4+ connector. The full list is on how mySites.guru helps.
Can mySites.guru migrate my Joomla 3 site to Joomla 5 or 6?
No. Moving from Joomla 3 to Joomla 4 or later is a migration with no update path, so the mass upgrade tool cannot do it, and mySites.guru does not sell a fixed-fee migration either, because no two Joomla 3 sites have the same template, extensions and custom code. It does make the move plannable: it shows what every site runs, keeps the old site patched and monitored until it is switched off, and monitors the new one once it is reconnected. The steps are in migrating to Joomla 4 or later when using mySites.guru.
What does the free trial include?
One free audit of one site, with no card and no time limit. Connect a Joomla 3 site and you see its core patch status, the published core vulnerabilities that match its version, the extensions on it with known vulnerabilities, and the full security audit. Keeping sites patched after that is part of the subscription, from £5 a month for a single site or £19.99 a month for unlimited sites, with prices on the mySites.guru pricing page. Start the free audit.
How should I sell ongoing maintenance to a client who says no?
Sell maintenance as the running cost of a thing that is alive, rather than as insurance against a problem that has not happened. Software is a purchase that never completes. It is closer to a child: a large investment at the start, a steady cost for years, predictable spikes at known milestones such as a major Joomla version change, and the occasional emergency that arrives without warning. A client who accepts that framing is budgeting for something they already own. The longer argument is in Joomla 3 didn't fail, your retainer did.
Is this site run by Joomla?
No. joomla3security.com is published by mySites.guru, which has been securing Joomla sites since 2012. It is not affiliated with or endorsed by the Joomla! Project or Open Source Matters. Joomla! is a trademark of Open Source Matters, and the official Joomla 3 announcements are on joomla.org; every vendor statement on this site links to its source.

Get the answer for your own Joomla 3 site

Connect one site and mySites.guru audits it free, with no card and no time limit. You see which of the 39 core advisories are still open on it, the extensions with known holes, and a one-click fix for the core ones.

Keeping Joomla 3 patched is part of the subscription

The one-click core patch, JoomShaper's Joomla 3 packages, vulnerable extension alerts and malware scanning are all included, alongside everything else mySites.guru does for Joomla and WordPress. No per-site fees, and no price increases since 2012.

Single site
£5/month
Upgrades itself to Unlimited when you add a second site
Unlimited sites
£19.99/month
Every site you manage, one price
Unlimited, yearly
£199.99/year
£16.66 a month

See the full pricing

Keep your Joomla 3 sites patched while you plan the move

One free audit of one site, no card and no time limit.

Audit a Joomla 3 site free