Hi,
I would like to raise a concern regarding EasyStore Pro and security updates.
I build and maintain several Joomla websites for customers using JoomShaper templates/Quickstart packages. Some of these packages included EasyStore Pro as part of the template setup.
The problem occurs when a security update such as EasyStore 3.0.1 is released. The installed EasyStore Pro version originally came with the JoomShaper template, but downloading the updated Pro package now requires an All Access subscription.
I completely understand requiring an active subscription for new features, support and regular product updates. However, security updates are a different matter. In this case, vulnerabilities have been disclosed that affect older EasyStore versions, including a critical vulnerability.
This leaves websites originally built with an official JoomShaper Quickstart package running a vulnerable extension, while the developer maintaining the website may have no way to obtain the security fix without purchasing a different subscription plan.
Would it be possible to provide a security-only patch for existing EasyStore Pro installations? For example, a downloadable patch containing only the files required to fix the vulnerabilities, without providing access to new Pro features or the complete latest Pro package.
Alternatively, is there an officially supported way to update these installations to the secure EasyStore Free 3.0.1 version without losing existing products, configuration or functionality?
I think having a way to apply critical security fixes to EasyStore versions distributed with JoomShaper templates would be very helpful for developers maintaining customer websites.
Thanks!