Two real paths, compared without spin

Patch or Migrate? An Honest Comparison

If your site is still on Joomla! 3, you have two real paths forward, and they are not equally right for every situation. Here is what each one actually costs, in money and time, and when each makes sense.

Applying a security patch

Cost: a one time purchase, in the range of twenty dollars, covering the currently known vulnerabilities. Time: minutes, since it installs as a normal Joomla! extension and applies fixes with a click. What you keep: your existing site, theme, and extensions continue running exactly as they do today, nothing about the site changes visually or functionally. What you do not get: new Joomla! features, official long term support, or protection against vulnerabilities discovered after you apply the patch. See the full list of what gets fixed for the technical detail.

Migrating to Joomla! 5

Cost: this varies enormously depending on site complexity, but for anything beyond a very simple brochure site, budget for real agency work, not a weekend project. Time: commonly weeks, not days, once you account for template rebuilding, checking every extension for Joomla! 5 compatibility, and testing. What you get: an actively maintained platform, official security updates going forward, and access to newer Joomla! features. What it costs you beyond money: downtime risk during the migration window, and the real chance that some third party extension you rely on simply has no Joomla! 5 equivalent yet.

When patching makes sense

If budget is constrained right now, if you need the security risk closed immediately, or if you are planning a migration but it realistically will not happen for months, patching is the sensible move. It buys time safely instead of running an unpatched, publicly documented set of vulnerabilities.

When migrating makes sense

If you have budget available now, if you need features Joomla! 3 simply cannot offer, or if the extensions your site depends on already have solid Joomla! 5 versions, migrating now rather than later avoids doing the patching work at all.

The combined strategy most sites actually use

These two options are not mutually exclusive. The most common real world pattern is: apply the security patch now to close the immediate risk, then plan and execute a proper migration to Joomla! 5 on a realistic timeline, without the pressure of an actively exploitable, unpatched site in the meantime. If you want help planning that migration, reach out at artd.ch/kontakt. If you want to close the immediate risk today, get the Joomla! 3 Security Patch.

← Back to the security patch