End of life since 17 August 2023

Joomla! 3 End of Life: What It Actually Means

On 17 August 2023, the Joomla! Project officially stopped supporting Joomla! 3. That single date changed what "running Joomla! 3" actually means for every site still on it, even though most of those sites kept working exactly as before. Here is what changed, why so many sites are still on it, and what your real options are.

What "end of life" means, technically

End of life is not a switch that gets flipped on your site. Nothing broke on 17 August 2023. What changed is upstream: the Joomla! Project stopped publishing security patches, bug fixes, and compatibility updates for the 3.x line. Every fix, every hardening measure, every response to a newly discovered vulnerability now goes into Joomla! 4, 5, and 6 only. Joomla! 3 is frozen at whatever code shipped in its final release.

New vulnerabilities keep being found in code that Joomla! 3 shares with the newer versions. Some of these get fixed upstream in Joomla! 5 or 6 and simply never get backported to 3.x, because there is no official channel left to backport them through.

Why so many sites are still on it

Joomla! 3 was a long lived, stable release, and a huge number of sites, templates, and third party extensions were built against it. Migrating to Joomla! 5 is rarely a simple upgrade: templates often need rebuilding, extensions need to be checked one by one for compatibility, and content structures sometimes need adjusting. For an agency managing dozens of client sites, or a site owner with a working, revenue generating site, that is real budget and real time, and it competes with every other priority.

So the honest picture is: a large share of the web is still running Joomla! 3, not because anyone thinks that is ideal, but because migrating everything at once is not realistic for most organizations.

Your three real options

1. Migrate to Joomla! 5 or 6

This is the only option that gets you back onto an actively maintained platform with new features and long term support. It is also the most expensive and time consuming option, and it needs to be planned properly rather than rushed.

2. Apply independent security patches

A verified, independently researched set of fixes for the known Joomla! 3 core vulnerabilities keeps a site secure and running on current PHP versions while you plan a migration. This is what our Joomla! 3 Security Patch does: it is not a substitute for migrating, it is a way to buy time safely instead of running unpatched. See the full list of 50 vulnerabilities it addresses if you want the technical detail.

3. Do nothing

This is a real option some site owners choose, usually without fully realizing it. The risk is not abstract: known, documented vulnerabilities in the Joomla! 3 core are public information, and automated scanners actively look for exactly this kind of unpatched CMS.

Patch now, migrate later is a valid strategy

These options are not mutually exclusive. Many sites patch the known vulnerabilities now to close the immediate risk, then migrate to Joomla! 5 on a realistic timeline. If you want to compare the actual cost and effort of each path side by side, see our honest comparison of patching versus migrating.

← Back to the security patch