Joomla 6 is the current major CMS line. Joomla 3 reached end of life on 17 August 2023, and paid extended security support ended on 17 February 2025. A Joomla 3 site in 2026 is running core software the Joomla Project will not patch. Joomla 4 is not the destination either. Its security window closed on 14 October 2025. If you still have a 3.x site, the supported landing zone is Joomla 6.1.x (6.2 is next), not a 2021-era Joomla 4 install.
This page used to compare Joomla 4 and Joomla 3. That framing is outdated. Joomla 4 shipped on 17 August 2021 as the way off Joomla 3. Four years later, Joomla 4 is also unsupported. The question in 2026 is simpler: stay on an unpatched 3.x stack, or move to Joomla 6 on modern PHP.
Infyways has migrated Joomla sites since the Mambo era. If you want a managed cutover, use Joomla Upgrade. For the current 6.x train, see Joomla 6.
What you will learn
- How Joomla 6 vs Joomla 3 compares on support, PHP, speed, security, templates, and SEO
- What share of Joomla sites still run version 3, and why that majority is in the danger zone
- Why Joomla 4 is no longer the upgrade target
- Official dates you can cite (EOL, eLTS, current 6.x support)
- The real upgrade path: 3.10 to 4.4 to 5.4 to 6.x (you cannot jump 3 to 6)
- What usually breaks: Protostar, K2, old page builders, abandoned extensions
- When to call Joomla upgrade or support help
How many Joomla sites still run version 3
W3Techs (7 September 2026) reports this mix among websites it detects as Joomla:
| Joomla version | Share of detected Joomla sites | Project patch status in Sep 2026 |
|---|---|---|
| 3.x | 52.6% | None. Community support ended 17 Aug 2023. Paid eLTS ended 17 Feb 2025 |
| 5.x | 20.6% | Supported (bugfix until 13 Oct 2026, security until 12 Oct 2027) |
| 4.x | 8.4% | None. Security support ended 14 Oct 2025 |
| 6.x | 8.1% | Current line (bugfix until 17 Oct 2028, security until 16 Oct 2029) |
| 2.x | 5.9% | None. Retired years ago |
| 1.x | 4.3% | None. Retired years ago |
How to read it:
- About 1 in 2 Joomla sites is still on Joomla 3. That is not a rounding error. It is the majority of the public install base W3Techs can fingerprint.
- About 71% are in the danger zone: versions 1, 2, 3, and 4 together (52.6 + 8.4 + 5.9 + 4.3). Those majors do not get official core patches.
- Only about 29% are on a supported train: Joomla 5 plus Joomla 6 (20.6 + 8.1).
This is a website census, not a poll of “people.” W3Techs counts public sites it can identify. It will miss locked-down intranets. It can also lag a recent upgrade until the next crawl. Treat 52.6% as the public web’s Joomla 3 share, not as Infyways telemetry.
The share is falling, slowly. W3Techs’ version history had Joomla 3 around 61% in July 2025. A year later it is still over half. Migrations are happening. They are not happening fast enough to empty the unpatched pool.
Why Joomla 3 sites are in the danger zone
“Danger zone” here means unpatched core on the public internet, not a marketing label.
- The core will not get another official fix. Any new Joomla 3 vulnerability stays open. Firewalls and Admin Tools lower noise. They do not replace a vendor patch. Community “dot 999” hardening is a stopgap, not a support contract.
- Attackers prefer the popular leftover. When more than half of detected Joomla sites still answer as 3.x, scanners and exploit kits keep Joomla 3 fingerprints in rotation. You are not an interesting target. You are a matching banner.
- The PHP under it is usually old too. Joomla 3 can boot on PHP 5.3.10. Many live 3.x sites sit on PHP 7.4 or 8.0 because a template or checkout dies on 8.3. Old PHP means old OpenSSL, ended distro packages, and a host that will someday force an upgrade and white-screen the site.
- The extension layer is abandoned. Template and page-builder vendors have stopped Joomla 3 security work. A “patched” builder on unpatched core is still an unpatched CMS.
- Joomla 4 is not a safe parking spot. Another 8.4% of detected sites are on 4.x, which lost security support on 14 October 2025. Migrating 3 to 4 and stopping leaves you in the same danger zone under a newer number.
- Compliance already failed. PCI questionnaires, cyber insurance, and enterprise IT reviews ask whether the CMS still receives vendor patches. “Joomla 3.10.12” is a no. “We have not been hacked yet” is not a control.
If you are in that 52.6%, the risk is not theoretical. It is the default condition of an EOL CMS that most of the remaining Joomla web has not left. Upgrade path below. Incident first if you are already compromised: repair a hacked Joomla website.
Joomla 6 vs Joomla 3 at a glance
These figures are from the Joomla Project roadmap, the Joomla 6.0 / 5.4 announcement, Joomla 3 downloads, and the Joomla 6 technical requirements. Current stable 6.x at writing (September 2026) is 6.1.3.
| Area | Joomla 3.10 | Joomla 4.4 | Joomla 6.1 |
|---|---|---|---|
| Last official core | 3.10.12 (11 July 2023) | 4.4.x, security ended 14 Oct 2025 | 6.1.3 (18 Aug 2026), 6.1.4 due 29 Sep 2026 |
| Community support | Ended 17 Aug 2023 | Security ended 14 Oct 2025 | Bugfix until 17 Oct 2028, security until 16 Oct 2029 |
| Paid eLTS | Ended 17 Feb 2025 | None | Not needed while 6.x is current |
| PHP minimum | 5.3.10 | 7.2.5 | 8.3.0 |
| PHP recommended | 8.0 (late 3.x docs) | 8.2 | 8.4 |
| MySQL minimum | 5.1 (InnoDB) | 5.6 | 8.0.13 |
| Frontend template | Protostar (Bootstrap 2 era) | Cassiopeia (Bootstrap 5) | Cassiopeia plus Cassiopeia Extended child |
| Admin template | Isis | Atum | Atum with CSS transitions |
| Core updates | Manual, unsigned in the old model | Manual, later TUF on 5.x | TUF-signed plus automatic core updates |
| Native child templates | No | From 4.1 | Yes, including the Extended child in 6.0 |
| MFA in core | Plugin era | First-class MFA | MFA plus POW captcha in 6.1 |
| Web Services API | Limited / add-on era | Core web services | Core APIs, Framework 4 |
| You should run this in 2026 | No | No | Yes |
Read that table as a support clock, not a feature brochure. Joomla 3 is not “old but patched.” It is unpatched core.


Why you should upgrade now
Waiting made sense in 2022, when Joomla 4 was new and many extensions lagged. It does not make sense in September 2026.
- There is no official Joomla 3 patch at any price. Community support ended 17 August 2023 (project announcement). The commercial eLTS programme closed 17 February 2025. Community hardening repos exist as a stopgap. They are not a product roadmap.
- Joomla 4 is also closed. Teams that migrated 3 to 4 and stopped there are on another EOL line as of 14 October 2025. Stopping at 4 only delays the same job.
- Hosts are dropping the PHP Joomla 3 was built for. Joomla 6 requires PHP 8.3 (8.4 recommended). Shared hosts that still offer PHP 7.4 or 8.0 are shrinking. A 3.x site that “works” on an old PHP pool is one host policy change away from a white screen. If the site is already down, treat it as an incident, then upgrade. Do not patch PHP on production and hope 3.x survives.
- Extension vendors have left 3.x. Major template and page-builder shops have stopped Joomla 3 security work. A patched Helix or SP Page Builder on top of unpatched core is not a secure site.
- Joomla 5.4 bugfix ends 13 October 2026, the same week Joomla 6.2 is planned. If you start from 3.x now, you still pass through 4.4 and 5.4. Starting after those windows close makes the staging work harder, not easier.
- Insurers, payment processors, and enterprise IT questionnaires ask for supported software. “We are on Joomla 3.10.12” fails that test. PCI and cyber policies do not care that the site “has not been hacked yet.”
If the site is already compromised, fix the incident first: repair a hacked Joomla website. Then upgrade. Patching malware on Joomla 3 and staying there repeats the incident.
Speed: Joomla 6 vs Joomla 3
Joomla 3 can feel fine on a tiny brochure site with a CDN in front. The gap shows up in admin, multilingual sites, and anything that loads a pile of modules.
PHP is the largest lever. Joomla 3 can boot on PHP 5.3.10. Plenty of live 3.x sites still sit on PHP 7.4 because a template or VirtueMart fork dies on 8.x. Joomla 6 will not install below PHP 8.3. You pick up years of Zend engine, JIT, and opcode-cache work the 3.x codebase was never written to use. That is not a lab synthetic. It is the language runtime your host actually executes.
Joomla 6 caches language file parsing. The 6.0 release notes added a cache layer around languageHelper::parseIniFile. Multilingual and large language-pack sites spend less time re-parsing INI on every request. Joomla 3 does this the old way.
Asset loading is no longer “jQuery and Bootstrap 2 on every page.” Joomla 3’s Protostar stack is a custom Bootstrap 2.3.2 plus a jQuery era front end. Joomla 4 introduced the Web Asset Manager. Joomla 6 still uses it on Bootstrap 5.3. Extensions that opt in ship only the CSS and JS they need. A 3.x site with five club templates and a page builder often ships several jQuery copies. That is why speeding up Joomla on 3.x is mostly caching and images, while 6.x can also drop unused JS.
Admin is a different application. Isis on Joomla 3 was built for another decade of screens. Atum on 4/5/6 is the accessibility-first admin. Joomla 6 added CSS transitions in Atum and Cassiopeia so admin navigation feels less like a full reload. Editors on 3.x still complain that “Joomla admin is slow.” Often it is PHP workers plus Isis plus uncached language strings. Front-end caching help is in how to speed up Joomla.
Media and images. Joomla 6’s media manager can generate thumbnails for more file types, and 6.1 adds audio, video, and document custom fields. Joomla 3’s media manager is a drag for large libraries. Pair the CMS move with modern formats: WebP for Joomla.
Do not expect a magic “Joomla 6 is 40% faster” number. Measure TTFB and LCP on staging after PHP 8.4, cache, and image work. The consistent pattern we see: origin time drops when you leave PHP 7 and a Bootstrap 2 template, then front-end LCP drops when you stop shipping unused JS.
Security: Joomla 6 vs Joomla 3
Security is the reason to move, not a bullet on a marketing slide.
Unpatched core is the whole story on Joomla 3. New CVE-class bugs in 3.x stay open. Firewalls and “we have Admin Tools” reduce noise. They do not patch core. If you need the honest incident path, we wrote how to repair a hacked Joomla site.
Joomla 6 still gets a security train. Roadmap: regular bugfix for 6.x until 17 October 2028, security-only until 16 October 2029. That is years of project-signed fixes Joomla 3 will never receive.
Updates are signed and can be automatic. Joomla 5.1 introduced TUF-secured updates. Joomla 5.4 and 6.0 added automatic core updates for minor releases (example: 6.1.2 to 6.1.3). Joomla 3’s updater was a manual, often skipped, ritual. Sites die in the gap between “we will update next quarter” and a disclosed exploit.
MFA and bot friction are core. Joomla 4 made multi-factor authentication a first-class system plugin. Joomla 6.1 added a built-in proof-of-work captcha as a core alternative to Google reCAPTCHA. Joomla 3 sites still bolt this on, if they bother.
Password hashing and session handling moved with PHP. Staying on 3.x often means staying on old PHP. Old PHP means old OpenSSL, old hash APIs, and host packages that nobody is backporting.
SVG and media uploads. Joomla 6 improved SVG validation errors in Media Manager so a failed upload is a real diagnostic, not a vague XSS warning. Joomla 3 media uploads are a frequent malware drop if the site allows untrusted users.
Security is also template PHP. Protostar forks and “null” templates from 2016 execute on the same PHP as core. Joomla 6 child templates (how to set up a Joomla child template) let you keep CSS without forking core files that need patches.
Feature comparison: daily CMS work
| Job | Joomla 3 | Joomla 6 |
|---|---|---|
| Edit an article | TinyMCE of that era, fewer field types | TinyMCE 8.x, notes and number custom fields, versioning that includes custom fields |
| Customise the design | Edit Protostar or duplicate the whole template | Child template of Cassiopeia; Cassiopeia Extended ships extra colour and font params |
| Run two languages | Native multilingual exists, incomplete packs leave gaps | Native multilingual plus a language fallback chain in 6.2 |
| Keep core patched | Manual, then impossible after EOL | TUF updates, optional automatic minor updates |
| Workflow | Limited | Graphical workflow editor in 6.1 |
| Headless / app backend | Thin | Core Web Services, Framework 4 |
| Accessibility | Partial | WCAG-oriented admin and frontend from the J4 rewrite onward |
| SEO defaults | SEF plus third-party SEO extensions | Same SEF model, cleaner HTML, better default robots/accessibility; still use a capable SEO extension if you need it |
One correction to older “Joomla 4 vs 3” posts, including the 2023 version of this URL: Joomla 3 already had native multilingual. Joomla 6 does not “add languages.” It makes incomplete language packs less painful and keeps the rest of the stack on a supported PHP line.
What usually breaks on the way off Joomla 3
Plan for these. They are why a 3 to 6 job is a migration, not a one-click installer.
- Protostar and Isis. They do not come across as Cassiopeia and Atum. Rebuild the look as a Cassiopeia child, or replace with a Joomla 6-ready commercial template. Do not copy Protostar PHP into 6.
- K2. K2 is a Joomla 3-era content stack. Move K2 items into core articles or a J6-ready CCK. Infyways runs this as K2 migration.
- VirtueMart and old checkout. Test every payment plugin on PHP 8.3. Some gateways never shipped J4+ builds. That is a commerce project, not a core bump. See VirtueMart upgrade.
- Page builders and Helix/SP Page Builder 3-era sites. Vendor J6 builds exist for current product lines. Joomla 3-only licences do not. Budget a rebuild of landing pages if the builder is abandoned.
- Overrides.
html/com_contentcopies from 2014 will fatal on namespaced J6 classes. Inventory overrides before you touch production. - SEO URLs. Most menu aliases survive. Third-party sh404SEF or similar needs a J6-native replacement or a redirect map. Do not go live without a 301 sheet.
You cannot jump from Joomla 3 to Joomla 6
The installer will not let you. GitHub’s 6.0 notes are explicit for the last hop: do not update to 6.x from anything below 5.4. Get to 5.4 first.
Practical path we use on client sites:
- Joomla 3.10.12 (last official 3.x) with a full backup
- Staging clone, PHP raised as far as 3.10 will run (often 8.0) so the pre-update checker works
- Migrate 3.10 to 4.4 (this is the hard hop: templates and extensions)
- Upgrade 4.4 to 5.4 (upgrade, not a second migration, if extensions dropped J3-only APIs)
- Enable the Behaviour – Backward Compatibility 6 plugin on 5.4, then upgrade 5.4 to 6.1.x
- Retest, then plan to turn the compatibility plugin off once vendors are native
Official notes: Joomla 5.4 to 6.0 migration. For the 3 to 4 hop, Joomla’s 3.10 pre-update checker is still the right first screen. We also keep a dedicated walkthrough at Joomla 3 to Joomla 4 upgrade because that hop is where most sites stall.
Step 1: Inventory the Joomla 3 site
- Record Joomla version, PHP, MySQL/MariaDB, and host.
- Export the extension list (core, libraries, templates, modules, plugins).
- Mark each item: Joomla 6-ready, replace, or drop.
- List overrides, custom cron, payment callbacks, and multilingual associations.
- Capture Search Console, analytics, and a crawl of indexable URLs.
Filter the Joomla Extensions Directory by Joomla 6. If a vendor vanished in 2019, budget a replacement now. Do not discover it on launch night.
Step 2: Fix hosting and PHP first
Joomla 6 needs PHP 8.3+, MySQL 8.0.13+ or MariaDB 10.4+ (10.6 supported, 12.0 recommended), and enough PHP memory (plan 256MB). Raise staging to the J6 target PHP before you chase template bugs. If production cannot offer PHP 8.3, change host before you change CMS. A 6.x site on an old PHP pool will not install.
Step 3: Stage, never upgrade live first
- Full files plus database backup, stored off the server.
- Clone to staging with the same PHP you will use in production for the current hop.
- Disable or remove junk extensions on the clone.
- Run 3.10 to 4.4 on staging until frontend, login, forms, and checkout work.
- Only then continue 4.4 to 5.4 to 6.1.x on that clone.
If staging is not possible, do not improvise on production. That is how “upgrade” becomes an outage. Infyways can run the clone under Joomla Upgrade or outsource Joomla services.
Step 4: Rebuild the template as a child, not a fork
On Joomla 6, create a child of Cassiopeia (or use Cassiopeia Extended) and move only CSS, logo, and overrides you still need. Do not paste Protostar index.php into 6. Details: Joomla child template setup. For a full visual rebuild, Joomla design services.
Step 5: QA, SEO, and production cutover
- Frontend: home, menus, articles, category blogs, search, forms, login, checkout.
- Admin: article edit, media, installer, users, MFA.
- SEO: aliases, canonicals, redirects, XML sitemap, Search Console comparison crawl.
- Performance: cache, CDN, WebP, PHP-FPM workers.
- Security: latest 6.1.x patch, automatic updates policy, failed-login limits.
Cut over in a low-traffic window with a restore point. Then watch logs for 48 hours. Ongoing patching belongs on a retainer: Joomla support and maintenance.
Key takeaways
- Most detected Joomla sites are still on 3.x. W3Techs (7 Sep 2026): 52.6% on version 3. About 71% sit on 1.x, 2.x, 3.x, or 4.x, none of which get official core patches.
- Joomla 6 vs Joomla 3 is not a style debate. Joomla 3 has had no official core patches since August 2023. eLTS ended February 2025.
- Do not migrate 3 to 4 and stop. Joomla 4 security support ended 14 October 2025. Land on Joomla 6.1.x.
- Speed comes from PHP 8.3/8.4, Web Assets, language-file caching, and dropping Bootstrap 2 templates, not from a slogan.
- Security comes from a supported train: TUF-signed updates, optional automatic minor updates, MFA, and vendors who still ship J6 builds.
- You cannot jump 3 to 6. Path is 3.10 to 4.4 to 5.4 to 6.x on staging.
- Budget template, K2, and checkout work. Core is the easy part. Overrides and abandonware are the project.
- Infyways can run the cutover: Joomla Upgrade.
Frequently asked questions
What percentage of Joomla sites still use Joomla 3?
W3Techs reported 52.6% of detected Joomla sites on version 3 on 7 September 2026. About 71% are on any unsupported major (1, 2, 3, or 4). Source: W3Techs Joomla usage.
Is Joomla 3 still supported in 2026?
No. Official community support ended 17 August 2023. Paid eLTS ended 17 February 2025. There is no official Joomla 3 core patch at any price. That is why the 52.6% still on 3.x are in the danger zone.
Should I upgrade Joomla 3 to Joomla 4 or Joomla 6?
Go to Joomla 6. Joomla 4 is a required hop on the path, not the destination. Joomla 4 security support ended 14 October 2025.
Can I upgrade directly from Joomla 3 to Joomla 6?
No. Update to 3.10, migrate to 4.4, upgrade to 5.4, then to 6.x. Do not skip 5.4. The project tells you not to update to 6 from anything below 5.4.
What PHP version does Joomla 6 need compared with Joomla 3?
Joomla 6 requires PHP 8.3.0 minimum and recommends 8.4. Joomla 3.10’s absolute minimum is PHP 5.3.10. That gap is why many 3.x sites cannot even install 6 until hosting changes.
Is Joomla 6 faster than Joomla 3?
Usually yes on real hosting, because you leave PHP 7 and Bootstrap 2, and 6.x caches language parsing and uses the Web Asset Manager. Measure on staging. Do not quote a fake percentage.
Will my Joomla 3 template work on Joomla 6?
Almost never if it is Protostar or a 2016 club fork. Rebuild as a Cassiopeia child or replace with a Joomla 6-ready template.
What about K2 sites still on Joomla 3?
Migrate K2 content before or as part of the CMS move. Core articles or a J6-ready CCK, not a K2 install on Joomla 6. See Joomla K2 migration.
How long does a Joomla 3 to Joomla 6 upgrade take?
A small brochure site with a replaceable template can be days on staging. A VirtueMart plus page-builder plus 80 extensions site is weeks. Inventory first. Infyways quotes after that list, not before: Joomla Upgrade.
Conclusion
Joomla 6 vs Joomla 3 is a supported CMS versus an unpatched one. W3Techs still finds 52.6% of detected Joomla sites on version 3. Speed and UX are real. They are not why you should move this quarter. You should move because that majority is already in the danger zone: no official core patch, aging PHP, abandoned extensions, and Joomla 4 already closed behind you.
Inventory extensions, raise PHP on a clone, walk 3.10 to 4.4 to 5.4 to 6.1.x, and rebuild the template as a child. If you want that done without gambling on production, start with Joomla Upgrade or hire Joomla developers.
