It isn't just WordPress
Joomla — and platforms like it — share the same architecture: a
database, a server running code on every visit, an admin login on
the public internet, and a catalogue of third-party extensions
doing the real work. Joomla's record is better, partly because a
smaller target draws less fire, but the underlying problem is
identical: your website is only as secure as the worst extension
someone else wrote for it.
Joomla adds a treadmill of its own — major version upgrades that
land every few years and can amount to rebuilding the site anyway.
Most owners put that rebuild off, which is how more than half the
world's Joomla sites are still on Joomla 3, three years after its
final security patch. If you're going to rebuild, rebuild onto
something that ends the cycle. We migrate Joomla sites the same
way: content, URLs and rankings preserved.
54.8% of Joomla sites still run Joomla 3 — no security fixes since August 2023
3 in 4 Joomla sites run a version that no longer receives security fixes at all
"Uninstall" Joomla's official advice for extensions on its vulnerable list with no patch available