Hi JoomShaper Team,
I am writing to express my frustration regarding a serious issue with the Helix Ultimate update mechanism that recently led to our website being compromised by malware.
Our Joomla administrator panel explicitly stated that Helix Ultimate was "Up to Date" at version 2.2.4. However, a malicious web shell backdoor was injected directly into the template's '/offcanvas/3-CenterAlign/' directory. Upon closer inspection, we realized that version 2.2.6 has been available, but your update server failed to communicate this to our Joomla system, leaving us entirely exposed to a known vulnerability. Furthermore, the template details still hardcode a creation date of 2018, adding to the confusion for administrators trying to verify file integrity.
When an update server fails or responds incorrectly, it should log an error, not falsely report to Joomla that the extension is secure and current.
Can you please confirm:
-
Why the update server failed to notify our Joomla 5 site about the 2.2.6 security patches?
-
What steps JoomShaper is taking to ensure update definitions reliably reach Joomla sites moving forward so other users don't suffer similar breaches?
Account Domain:www.comfoot.co.nz
Current Version Installed Manually: 2.2.6
Regards,
Bruce