Hello JoomShaper Team,
I’ve been running an advertising agency for over 20 years, manage around 70 Joomla websites, and also handle my own servers and hosting. Over the years, I’ve become familiar with all well-known template providers — such as JoomlArt, Gavick, YOOtheme, and many others.
However, I have been a conscious choice to be your customer for many years because I’m impressed by your products, your designs, and especially the flexibility in customization.
Nevertheless, I’d like to give you some honest feedback on how you handled the recent security vulnerabilities. I hope you’ll see this as constructive feedback from a long-time customer.
What didn’t go well, in my view
1. The response time was too slow.
Websites were already under attack on Friday, but the first security update wasn’t released until Tuesday around 4 p.m.
2. The official communication came too late.
A request to update wasn’t even sent out until Tuesday evening around 10 p.m.
3. Further security updates were released only gradually.
Helix3 was updated first, followed by Helix Ultimate several days later. Especially when it comes to security vulnerabilities, it would be desirable to release updates as simultaneously as possible.
4. Communication could be much clearer.
Phrases like “Action required” come across as too noncommittal when dealing with security-critical issues. Address the problem openly and make the urgency unmistakably clear.
5. There was no clear guidance for affected customers.
I would have expected all affected customers to receive a prompt email detailing
- which versions are affected,
- what immediate steps are required,
- how to check a website for possible compromise, and
- how to remediate the issue if necessary.
At the same time, there was a similar security incident involving the JCE Editor. Ryan communicated very transparently and clearly in that instance. That’s exactly the kind of openness and clarity I would have liked to see from you as well.
Instead, several dozen inquiries popped up in the forum that your support team had to answer individually. With a detailed security bulletin, you could have significantly reduced the workload for both your customers and your own support team.
My Hopes for the Future
1. Actively use AI for security analysis.
Hackers are already using AI-powered tools today. Take advantage of these capabilities as well to identify vulnerabilities early on. I believe we’re only at the beginning of this development.
2. Quality should take priority over new features.
A good example is the issue of spam in the Form Builder. While the team spent weeks working on features like Dynamic Content and promoting them to us as customers, we agencies had to deal with thousands of spam messages and explain to our clients why their forms were being misused.
In situations like these, I wish stability and security would take priority over new features.
3. Please improve the quality of the releases.
Especially when you — like me — have to update around 50 websites with Helix Ultimate or PageBuilder, it’s very frustrating when the next update is released shortly afterward because bugs in the previous release need to be fixed. Recent examples of this were Helix Ultimate 2.2.7 and 2.2.8.
Such “updates for an update” waste time and do little to build trust. Unfortunately, this isn’t just an isolated occurrence.
One last, but very important point
When I seek help on the forum, I almost always get a solution from your support team — and I’d like to express my sincere thanks for that.
What I would like to see, however, is this: I often find a forum post describing exactly my problem. But it simply states that support resolved the issue using admin access. While this is helpful for the individual customer, it’s unfortunately not helpful for everyone else.
It would be great if you could briefly document afterward what exactly caused the problem and what steps led to the solution. This would make the forum a much more valuable knowledge base, and we could solve many problems on our own without having to open a ticket every time.
Despite my criticism, I want to emphasize that I still highly value your products and use them every day. That’s precisely why I’m taking the time to write this feedback. I hope that JoomShaper will continue to be among the best providers in the Joomla community.
Thank you very much for taking the time to read this feedback.
Best regards...
Steve