How mySites.guru keeps Joomla 3 sites patched while you plan the move
Joomla stopped patching Joomla 3 on 17 August 2023, and no one has sold a patch since 17 February 2025. mySites.guru still closes the published core holes in one click, deploys JoomShaper's own Joomla 3 packages, and tells you on every connected site which known vulnerabilities are open. It is all part of the subscription, with no eLTS licence, and it is a holding position until the site moves.
Percentages measured across sites connected to mySites.guru, 28 August 2026. The advisory count is from the current patch set.
The one-click Joomla 3 core patch
We backport each Joomla core fix that reaches Joomla 3 to 3.10.12 ourselves, test it against a stock 3.10.12 install, and ship it with the mySites.guru connector.
The tool is called Fix Known Joomla 3 End Of Life Security Issues and sits in each site's snapshot as a toggle. Switch it on and the connector changes 85 core files: 84 are replaced with patched copies, and one, a form rule behind the language override fix that Joomla 3 never shipped, is created. That closes 39 published core advisories, every one listed with its CVE and Joomla's own advisory on the core vulnerabilities page. Switch it off and the files go back to stock 3.10.12, and the added file is deleted again.
The patches come from the same open-source 3.10.999 project that has backported Joomla 3 security fixes since end of life, including fixes for code that the paid eLTS releases themselves shipped broken. No eLTS licence is involved, and none is needed.
Finding it, and patching every site at once
Search for "Fix All Known Joomla 3 End Of Life Security Issues" in the Cmd-K command palette, or open any Joomla 3 site's snapshot. Both lead to an overview of every Joomla 3.10.12 site you manage with its patch status, and the bulk view gives each site its own toggle on one screen. For a portfolio of client sites, that screen is where the work gets done.
How the audit knows whether a site is patched
Each audit compares the 85 files with our patched copies and counts the ones that do not match. Zero means the site has every patch we ship today. Any other number is how many files still need patching, and one toggle fixes all of them. A file you have edited by hand counts as unpatched, and switching on replaces it with our copy. Files for parts of Joomla you have uninstalled, such as the Hathor or Beez3 templates, are skipped rather than put back.
When Joomla publishes a new advisory that reaches Joomla 3 and we add it to the patch set, every site that was fully patched shows as behind again until the toggle is switched on once more. The sites list shows a "Patches Available" badge on those sites, so you see a new backport without having to remember to check.
After patching, an audit lists the changed files under Core File Changes, because they no longer match the 3.10.12 release. That is expected, and you can read every diff there.
What it needs
Joomla 3.10.12 or a later 3.x build, and the PHP zip extension on the server. Without zip, the audit says so, labels the site as missing the module, and does not offer the toggle. The tool never applies to Joomla 4 or later, and it is not offered on anything older than 3.10.12: update those sites within 3.x first.
JoomShaper's own Joomla 3 packages, deployed and revertible
JoomShaper said it would ship no more Joomla 3 security patches, then shipped them for Helix Ultimate, Helix3 and SP Page Builder. mySites.guru finds the sites that need them and installs them.
The packages have two problems that make them hard to manage by hand. They install only onto specific extension versions, and once applied they leave the version number unchanged, so to Joomla's updater, the Extensions manager and any scanner that compares versions, a patched site and an unpatched one look the same. JoomShaper has also shipped several releases of each package since July 2026, and every new one turns a "patched" site back into an outdated one.
So mySites.guru reads the files instead. The Unpatched JoomShaper Security Holes tool runs on every snapshot of a connected Joomla 3 site and looks inside the installed files for a string that exists only in a given release of JoomShaper's patch. For each of Helix Ultimate, Helix3 and SP Page Builder it reports whether the extension is installed, whether any patch has been applied, and whether that patch is the current release.
Applying it is one click on that site's tool page. mySites.guru then:
- backs up the files the vendor package is about to overwrite, and stops if the backup fails
- downloads JoomShaper's own package from our CDN and checks it against a pinned SHA-256, so the site receives the exact file JoomShaper published
- installs it through Joomla's own extension installer, so the vendor's version check runs and a site on the wrong version is turned away, just as it would be if you installed it by hand
- reports the outcome per extension, so a failed backup, download or install shows as a failure rather than a success with nothing changed
Undoing it is one click too, restoring the backed-up originals. We install the whole vendor package because the patched files call methods that exist only in other patched files, and splicing them in one at a time would leave a site that fatals. The tool also covers one hole no JoomShaper package reaches, a local file include in the SP Page Builder 3.8.x addon loader, with a small guard on that one line and its own backup and revert. The background is in the one-click way to patch JoomShaper extensions on Joomla 3.
See what is still open on one of your Joomla 3 sites
Connect one site and mySites.guru audits it free, with no card and no time limit. You see its core patch status, the JoomShaper packages it needs, and every extension on it with a known hole.
End-of-life warnings on every Joomla 3 site
mySites.guru tells you a site is end of life without you having to go looking.
Every Joomla 3 site in mySites.guru shows a "Joomla 3 is end of life" banner. Where the site's version matches published core vulnerabilities, the banner names the count: the site is exposed to that many published core security vulnerabilities that will never be patched by Joomla. When some of them can be closed by the one-click patch, it says how many, and it links to the patch, to what a migration means for the connector, and to how mySites.guru treats end-of-life versions.
Across a portfolio, the End Of Life Joomla filter in the left-hand menu lists every connected Joomla site on an end-of-life version in one place. That list is usually the starting point for a migration plan: it shows how many sites the conversation covers, and each one links straight to its own warnings.
mySites.guru keeps supporting old versions on purpose, right back to Joomla 1.5, so that you can see those sites and move them.
Every published core CVE, flagged per site
An end-of-life core becomes a count you can show a client.
Each site gets a core vulnerability card that lists every published Joomla core CVE whose affected range includes that site's exact version. The heading counts only what is still open, with the worst rating among them, so a patched site is never told it is exposed to work it has already done. Where some of the open ones can be fixed with one click, the card says how many.
Fixed CVEs are never hidden. A site that has applied every patch we ship still sees each matching CVE, marked as fixed, because hiding them would let an owner believe a published flaw never affected their version. When every one is fixed, the heading says so instead. The card also has a button that copies the CVE ids, for a client report or a ticket.
Where a site reports a version mySites.guru cannot order, for example a build string a fork invented, the card says the core vulnerabilities were not checked, and does not guess. That is the practical cost of the invented version numbers described on the options page.
Vulnerable Joomla extension alerts
On Joomla 3 most of the damage comes in through the extensions.
mySites.guru keeps a database of published vulnerabilities in Joomla extensions, with the affected version range for each. Every snapshot of a connected site, taken twice a day, reads the extensions and versions actually installed and matches them against those rules, so a site running a vulnerable version is flagged without anyone looking it up. New rules reach connected sites within the hour of being added.
52 of those rules currently name Joomla 3, across 25 extensions, and they are listed on the Joomla 3 extension vulnerabilities page. In the mySites.guru dataset 22.3% of Joomla 3 sites run at least one extension with a known vulnerability, and an affected Joomla 3 site averages 3.30 of them.
A flag tells you the hole exists. Whether a fix exists for Joomla 3 is a question for the vendor, and the answer has changed more often than the vendors' own statements suggest. The vendor tracker records what each one said and did, with sources.
Malware scanning and core integrity
Patching closes the way in. It does not remove what an attacker already left behind, so a Joomla 3 site needs both.
The mySites.guru audit scans every file on the site against a library of roughly 1,500 regex patterns, and flags matches as a Hacked File. Instead of grepping a whole web space by hand, you get a short list, and you can read the suspect content of any file inline before deciding what to do with it.
The audit also checks core integrity. The connector compares the site's core files with the hashes of the official files for the Joomla release it reports, including 3.10.12, the release the one-click patch is built on. The paid eLTS builds were never published, so there is no official reference to compare them with, and the integrity check skips them. On a 3.10.12 site that has had the one-click patch, the patched files show up as Core File Changes with a readable diff, as you would expect.
Some compromises live in the database rather than in files. mySites.guru has targeted detection for specific database-resident compromises seen on Joomla sites, each with a one-click fix: rogue Super Admin accounts, the Helix Ultimate mega menu hack, the Helix3 template code hack, rogue SP Page Builder assets, and malicious JCE editor profiles. These are targeted checks for known campaigns rather than a general database malware scan.
In the mySites.guru dataset 4.90% of Joomla 3 sites are flagged as hacked, against 0.98% of Joomla 6 sites, and those are sites someone is paying to have watched.
Is a Joomla 3 site hacked right now?
We clean it for a single fixed fee of £120 per incident, usually the same day. We screen it before you pay, so in the rare case it cannot be fixed you are not charged, and non-subscribers get a free month of mySites.guru with it. Get it fixed
Bulk updates within Joomla 3
The core patch needs 3.10.12, and 68.2% of the Joomla 3 sites in the mySites.guru dataset are behind it. Getting them there is the first job.
mySites.guru's mass upgrade asks each selected site for the update path it currently sees, which is what you would get on the Joomla update page in that site's own admin, and then runs the updates across every site you choose. For an older Joomla 3 site the update path ends at 3.10.12, the final public release, which is the version the core patch needs.
The tool itself warns you not to mass upgrade a site that has core file changes, because the update writes clean core files over them, or a site that is not backed up. Very old Joomla 3 builds are also less reliable at reporting an update path than 3.8.0 and later, which is a fault in those Joomla releases. So the order for a site behind 3.10.12 is: back up, update to 3.10.12, run an audit, then switch on the core patch.
Extension updates work the same way across sites, so wherever a vendor is still shipping Joomla 3 releases, you can push them to every site that runs the extension in one pass.
What mySites.guru does not do for Joomla 3
A holding position is only useful if you know where its edges are.
- It does not migrate sites. Moving from Joomla 3 to Joomla 4 or later is a mini-migration with no update path, so the mass upgrade tool cannot do it, and we do not sell a fixed-fee migration. See what a migration involves.
- It does not make Joomla 3 a long-term home. The highest PHP version Joomla 3 runs on is PHP 8.1, which reached end of life on 31 December 2025, and no patch changes that.
- The core patch does not clean a hacked site. Find and remove the malicious files first, then patch.
- The core patch covers Joomla core only. Extension fixes come from their vendors, apart from the JoomShaper packages above, which are still JoomShaper's own code.
- There is no general database malware scan. The database checks are targeted at the specific compromises listed above.
- There is no user-facing whitelist and no way to mark a flagged file as a false positive. A file the audit flags stays in front of you until it is dealt with.
- It cannot vouch for a version that never existed. Forks that number their releases 3.11 or 3.15 cannot be matched against vulnerability data, and eLTS builds have no public core hashes to check against.
A Joomla 3 site with the core patch, the vendor fixes and a clean audit is in a far better state than most Joomla 3 sites, and still needs moving.
Find every unpatched Joomla 3 site you look after
Connect one site and mySites.guru audits it free, with no card. You see the core vulnerabilities still open on it, the extensions with known holes, and a one-click fix for the core ones.
Keeping Joomla 3 patched is part of the subscription
The one-click core patch, JoomShaper's Joomla 3 packages, vulnerable extension alerts and malware scanning are all included, alongside everything else mySites.guru does for Joomla and WordPress. No per-site fees, and no price increases since 2012.
Keep your Joomla 3 sites patched while you plan the move
Part of the subscription, from £5 a month for one site. Start with one free audit of one site, no card and no time limit.