According to market share estimates (as of May 2026), Joomla 3.x is currently used on more than 50% of all installed Joomla sites worldwide. However, official support for Joomla 3.x ended in February 2025 (counting the eLTS program).
Back in April we launched the first version of Joomla 3.x UTD - an up-to-date distribution of the Joomla 3.x content management system, built to ensure code security, support modern PHP & MySQL/MariaDB versions & fix any broken behaviour that never got sorted before the release of newer major versions of Joomla.
Releases 3.11 to 3.16 delivered on those primary goals: PHP up to 8.5 and security in-line with Joomla 5 & 6. A few days ago we wrote about what's coming next - fixing what was left unfinished (database drivers beyond MySQL/MariaDB) or never properly implemented (frontend templates that actually showcase a capable CMS).
Well, that's all in v3.17, released today. And then some.
A new home: j3xutd.joomlaworks.net
Joomla 3.x UTD now has its own website at https://j3xutd.joomlaworks.net.
Up until now, everything about this project lived in the README file on GitHub. The new site puts it all in one place, in a format that's a lot easier to browse & share with clients, colleagues or your hosting company:
- What's new in the latest release
- The 3 new templates, with screenshots for desktop, mobile & dark modes
- Install & upgrade instructions (Web UI, SSH one-liner and fresh installs) with copy-paste ready commands
- The command line & MCP server, including the full list of all 100 commands
- Compatibility notes for PHP and a database support table for every database vendor
- The changelog of every release since v3.11
- A full list of security fixes per release, with their origin (backported from Joomla 5/6, CVE IDs, or issues found in stock Joomla 3 by us)
- Our long-term plan & ways to get involved
The GitHub repository at https://github.com/joomlaworks/joomla-3.x remains the place for code, releases, discussions & issues - and you can subscribe to the releases feed to be notified of new versions.
3 live demo sites, one for each new template
Each of the 3 new templates runs live with its own sample data, exactly as a new site gets it from the installer. All 3 demo sites run on PHP 8.5 with SQLite as the database:
- Hammond (news portals & magazines): https://j3xutd-demos.joomlaworks.net/hammond/
- Finch (blogs & personal sites): https://j3xutd-demos.joomlaworks.net/finch/
- Rookwood (studios, agencies & company sites): https://j3xutd-demos.joomlaworks.net/rookwood/
Click around, test them on your phone, and torture them as much as you like - we're still eager to see how SQLite holds up!
What's new in v3.17
Here's a summary:
- Every major database, tested: MySQL/MariaDB (native & PDO), PostgreSQL (native & PDO, now fixed for PHP 8.1+), SQL Server & Azure SQL (tested on SQL Server 2022 with both drivers) and SQLite (new). MySQL 8.0, 8.4 and 9.x work with their default authentication (caching SHA-2) - no more
my.cnfchanges to switch to "native" passwords. - SQLite (experimental): a whole site in one file. We use WordPress' emulation layer, so MySQL SQL from Joomla and your extensions runs unchanged. WAL mode lets visitors keep reading while a write happens, and sessions are kept in PHP so browsing writes nothing to the database. Ideal for spinning up dev sites in seconds or keeping a site in Dropbox/OneDrive, but also practical for small to medium sites with caching enabled. Busy shops or forums with many concurrent writers are still better off on MySQL/MariaDB.
- A brand new installer: app-style, with a sidebar of steps, dark mode and right-to-left support, built with plain HTML, CSS & JavaScript. It supports every database driver, removes the
installationfolder for you when you continue to the site, and once installed, only the browser that installed the site can go on. - 3 brand new frontend templates: Hammond (news), Finch (blogs) and Rookwood (studios & companies). Plain CSS & JavaScript, no jQuery, Bootstrap or MooTools, system fonts & SVG icons, built for Google's Core Web Vitals and using 100% core Joomla extensions. Each comes with an
editor.cssso your WYSIWYG editor shows articles with the site's fonts, colours & layout, and acss/custom.cssthat updates never touch. - Sample data made for each template: News (227 articles in ten sections), Blog (20 essays in four topics) and Studio (9 case studies & 16 journal posts). Pick one in the installer, or switch sets later from the Control Panel, as if the site had been installed with that set from the start.
- A command line for everything:
cli/joomla.phpnow ships with 100 commands for content (articles, categories, tags, modules, menus), templates (with undoable changes & backups), databases (export, import, optimize anddatabase:convertbetween MySQL, PostgreSQL & SQLite in any direction), health checks, logs and more. Every command has JSON output and dry runs, and where Joomla 4 or newer has a command, ours uses the same name. - A built-in MCP server: Claude, ChatGPT, Gemini, Qwen, Kimi, GLM and other AI assistants can work with your site through the Model Context Protocol. It's read-only unless you allow writes (
--allow-write), anything that puts code on the server needs--allow-codetoo, and every change is recorded in the User Actions Log. Details in our AI & CLI guide. - TinyMCE 8 is the default editor for new sites: image uploads by dropping or pasting, a toolbar builder per user group and 61 languages. TinyMCE 4 stays as "Editor - TinyMCE (legacy)" for existing sites.
- Quality of life in the backend: a new responsive login page, one-click Clean Cache in the status bar (plus Clean Everything and Global Check-in for administrators), Install from Web back as the first tab, and Help buttons that work again.
- Post-installation Messages now tell the story of this distribution, one message per release since v3.11, instead of stock Joomla's notes from the 3.2–3.10 era.
- Thousands of fixes: long-standing bugs in the API sorted, database errors handled as Joomla expects on PHP 8.1+, and every PHP deprecation we could find removed - including thousands while Smart Search indexes.
22 security fixes
v3.17 also includes 22 security fixes. And this time most of them were not backports - they were issues present in stock Joomla 3 all along, found while auditing the codebase ourselves. A few examples:
- Crafted packages could write files outside the site's folders through Joomla Update's extraction, the extension installer or the archive code - such packages are now refused as a whole.
- Anyone could run the installer again on an installed site while the
installationfolder remained. - The configuration writer could put PHP code into
configuration.phpthrough a crafted setting name. - The MySQL (PDO) and PostgreSQL drivers ran several SQL statements given at once - every driver now runs one, like "mysqli".
{loadmoduleid}showed any module to anyone, whatever its access level or publishing dates.
Our opt-in Little WAF plugin (introduced in v3.16) now also checks form data and encoded spellings of the tags it filters.
The full list is on the security section of the new site and in the detailed changelog.
How to upgrade (or start fresh)
For existing Joomla 3.x sites (any 3.x release), in the backend open the Joomla Update options (or Global Configuration) and set:
- Update Channel: Custom URL
- Minimum Stability: Stable
- Custom URL:
https://joomlaworks.github.io/joomla-3.x/list.xml
Refresh and v3.17 will show up. If your site is already on Joomla 3.x UTD, it's waiting for you there already.
Prefer SSH? cd into your Joomla site's folder and run:
wget -qO- https://github.com/joomlaworks/joomla-3.x/archive/refs/heads/main.tar.gz | tar -xz --strip-components=1 && rm -rf installation .github .gitignore *.md For new sites, download the latest release and open it in a browser, or install a complete site on SQLite from the command line in about a second (sample data included):
wget -q https://github.com/joomlaworks/joomla-3.x/releases/download/rolling/joomla-latest.zip && unzip -q joomla-latest.zip && rm joomla-latest.zip && php cli/joomla.php core:install --site-name="My Site" --admin-email=This email address is being protected from spambots. You need JavaScript enabled to view it. --admin-username=admin --sample-data=news (Swap news for blog or studio.)
What's next
With v3.17, Joomla 3.x UTD is secure, current & - for the first time - showcases what a fast, approachable CMS built on Joomla 3.x can look like out of the box. We'll keep backporting security fixes & fixing bugs as they're reported.
In parallel, our leaner fork based on Joomla 3.x (a separate project) is moving along very actively: stripped down, K2 for content, first-class MySQL/MariaDB, PostgreSQL & SQLite support, a refreshed administrator and modern JavaScript only. The command line & MCP server in v3.17 are the seed for what we want that project to become: a truly agentic CMS.
If you're a Joomla extension developer reading this, make sure your extension update XML files don't stop at Joomla 3.10.x. Do your users a favour ;)
Found a bug? Report it in our GitHub Discussions. Want to contribute a fix or a meaningful upgrade? Open an issue.
Happy updating!