AI-assisted code analysis interface highlighting a “Find Problems” option over software code.

Joomla 3 stopped receiving security updates on August 17, 2023. For the past three years, interGen has continued hosting Joomla 3 sites by adding extra layers of protection around software that is no longer being patched.

That has given clients more time to plan their next step. But it was never a permanent solution.

What changed: AI-assisted attack tools have made it faster and cheaper to find weaknesses in older software and scan large numbers of websites for them.

Why that matters: Our security layers can reduce risk, but they cannot replace security updates. For Joomla 3, those updates are no longer coming.

The result: interGen will stop hosting and supporting Joomla 3 websites no later than January 1, 2027.

Today is August 17, 2026. Exactly three years ago today, Joomla 3.10 reached its official end of life. Since that date, the core software has received no security updates, and none will ever be released. Most third-party extensions and templates were abandoned by their developers around the same time. Beneath the site, the programming language runtime itself is out of date: Joomla 3 depends on older PHP versions that are themselves no longer supported, compounding the security and compatibility problem.

If you run an organization on a Joomla 3 website, you have probably been hearing that you need to upgrade for years.

If your site has worked fine this whole time, it is completely natural that you tuned that advice out. The standard defense for keeping an old site running was simple economics: "We are small, we do not handle sensitive data, and nobody is going to spend the time to attack us."

Small Sites are not being ignored

That logic made more sense when an attacker's time and effort were scarcer resources. Over the last two years, artificial intelligence assisted tools have made parts of the vulnerability research and automated scanning faster and cheaper.

Attackers do not have to sit down and choose one website at a time.

Automated scanners can move across thousands of sites, identify what software they are running, test for known weaknesses, and move on.

When checking one more site costs almost nothing, being small or relatively unknown is not much protection.

That does not mean every Joomla 3 site is about to be hacked. It does mean the old assumption that smaller sites are less worth the effort matters less than it used to.

AI is accelerating something that was already happening 

Automated scanning is not new.  Bots have been testing websites for known weakenesses for years.  

1.  Finding security flaws became fast and cheap.

Joomla 3 extension code is public, unpatched, and written for older software environments.  AI-assisted tools can help bad actors review large amounts of that code, identify potential vulnerabilities, and take advantage in seconds.

2.  The exploitation window got much shorter. 

In software security, the window is the time between when a vulnerability becomes known and when automated scripts start testing it against live sites. On a modern, supported software platform, a rapid update closes that gap. On Joomla 3, there is no patch waiting at the end of the window. Once an issue in an old extension is identified anywhere in the world, sites running that extension can remain vulnerable indefinitely.

3.  Attacks are increasingly automated. 

Automated scanners have long been able to identify what software a website is running and test it for known vulnerabilities. AI-assisted tools make it easier to expand and adapt that process at scale. Nobody has to sit at a desk and specifically choose your website. When testing another site is inexpensive, size offers less protection.

4.  A compromised site can still look completely normal.  

An attacker may quietly use a compromised website to host phishing pages, distribute spam or malware, or create hidden redirects while the legitimate site continues to work. Site owners may first discover the problem when email delivery suffers, search engines issue warnings, or monitoring detects unauthorized files.

5.  Better defenses still cannot patch unsupported software. 

To be fair, modern defensive tools have advanced just as quickly. Firewalls can block malicious requests, scanners can identify suspicious files, and monitoring can help us respond quickly when something changes. But none of those tools can provide a security patch for software that is no longer maintained. 

How We Protect Sites at interGen

interGen has not been leaving Joomla 3 sites exposed without additional protection.

Because we manage hosted environments for many organizations, we built a layered defense to keep legacy systems stable while migrations are planned.  Our hosting setup includes things like:

A Web Application Firewall

We deploy Akeeba Admin Tools Pro on virtually every client site. It filters incoming traffic for suspicious requests before they hit the site and includes a scheduled file scanner. Instead of just alerting us that a PHP file changed, it reports the exact line-by-line code difference so our engineers judge the edit on its actual intent rather than a false alarm.

File Change Monitoring & Nightly Malware Scanning

At the server level, we run nightly malware sweeps that check for known malicious file patterns, monitor upload directories, and flag configuration drift. We also restrict where uploaded files are allowed, which can prevent malicious files from running even if they get uploaded to a directory.

Cloudflare in front of the site

We place Cloudflare in front of client sites that have provided us DNS access, locking origin servers so they can only receive traffic routed through those edge filters.

Off-Site Backups

We maintain off-site backups on a strict retention schedule. Crucially, we do not just rely on a backup utility reporting that a job completed. We verify that the backup files actually arrived in immutable object storage (cloud storage that cannot be edited or deleted once written) and can be restored.

This defensive stack is the reason we have been able to continue hosing Joomla 3 well beyond its official support period.  It buys time to plan a proper migration, and that is its true purpose.

What You Should Do Next

Moving from Joomla 3 to Joomla 6 is a migration, not a simple one-click update. Templates and extensions must be replaced or rebuilt, and content structure must be migrated. You do not need to panic, but you should take methodical steps now:

  • Inventory your site. Find out exactly what you are running. Confirm your core Joomla version, list all active third-party extensions, and check what version of PHP your web host is providing.

  • Verify your backups. Confirm that you have a recent site backup stored entirely off your hosting server, and ensure you or your technical team have successfully tested restoring from it at least once.

  • Schedule your migration as a planned project. A planned migration is a standard, manageable web project with predictable timelines and outcomes. A migration forced by a security compromise is that exact same project, but compressed into an emergency alongside data recovery, downtime, and search engine reputation repair.

  • Talk us about your site. Contact the team at interGen to request a Joomla 3 risk review. We can can review the current site, identify what will need to be rebuilt or replaced, and plan a sensible path forward.