Why CMS Updates Matter More Than You Think
If I could give only one piece of security advice to every CMS administrator, it would be this: keep your software updated. Not tomorrow. Not next week when you have time. As soon as a security update is available.
It sounds simple, and yet outdated software remains the leading cause of CMS compromises by a wide margin. Let me explain why this problem is worse than most people realize.
The Numbers Are Stark
A 2008 study of compromised websites found that over 60% were running outdated versions of their CMS platform at the time of the breach. Among Joomla sites specifically, the figure was even higher - many were multiple major versions behind.
The pattern is always the same. A vulnerability is discovered and patched. The CMS vendor releases an update. The administrator does not apply it. An attacker uses a publicly available exploit against the known vulnerability. The site is compromised.
The critical detail is the timeline. When a security patch is released, the vulnerability details become public knowledge. Security researchers publish advisories. Exploit code appears in databases like Milw0rm and on security mailing lists. Automated scanning tools are updated to detect the vulnerability. Within days - sometimes hours - of a patch release, attackers are actively scanning the internet for sites that have not updated.
The Window of Exposure
Before a patch is released, a vulnerability may be known only to the vendor and the researcher who reported it. This is the responsible disclosure period. During this time, the risk is relatively low because the details are not public.
The moment the patch drops, the clock starts. Security researchers reverse-engineer the patch to understand what was fixed. This is standard practice - it helps defenders understand the risk, but it also gives attackers a roadmap. A diff between the old code and the patched code reveals exactly where the vulnerability was and how to exploit it.
For a typical CMS security update, the window looks something like this:
- Day 0: Patch released
- Day 0-1: Advisories published, exploit details emerge
- Day 1-3: Automated exploit tools updated
- Day 3-7: Mass scanning campaigns begin
- Day 7+: Compromises peak among unpatched sites
If you have not applied the update within the first few days, you are in the high-risk zone. After a week, you are essentially running a site with a known, publicly documented vulnerability and active exploitation in the wild.
Why People Do Not Update
I have heard every excuse. Here are the common ones and why they do not hold up.
“I am afraid the update will break my site.” This is legitimate but solvable. Take a backup before updating. If something breaks, restore and investigate. The risk of a broken layout is far smaller than the risk of a full compromise.
“I have custom modifications to core files.” Then you have a bigger problem. Core modifications should be avoided entirely - use the override systems your CMS provides. If you have modified core files, every update becomes painful, and the temptation to skip updates grows. Fix the root cause.
“I do not have time right now.” Security updates for most CMS platforms take less than 15 minutes. WordPress can be updated in under a minute from the dashboard. If you do not have 15 minutes for security, you do not have time to deal with the aftermath of a compromise - which will take days or weeks.
“My site is small and nobody would target it.” Attackers do not manually select targets. They use automated tools that scan millions of sites. Your small Joomla blog is being probed by the same bots that hit enterprise sites. Size does not matter - vulnerability does.
Setting Up Update Notifications
At minimum, you should know when updates are available. Here is how to stay informed for each major CMS.
Joomla: Subscribe to the Joomla Security Strike Team announcements at developer.joomla.org. The admin dashboard also shows a notification when updates are available, but only if you log in regularly.
WordPress: The dashboard shows available updates automatically. For email notifications, the WordPress Automatic Upgrade Notification plugin sends you an alert when core, plugin, or theme updates are available.
Drupal: Subscribe to the Drupal Security Advisories at drupal.org/security. Drupal also provides an Update Status module (included in core since Drupal 6) that checks for available updates and displays them in the admin interface.
Automatic Updates vs Manual Review
WordPress 2.7 introduced automatic minor updates for security releases. This is a reasonable default for most sites. Security releases are tested specifically to avoid breaking changes.
For major version updates and plugin updates, manual review is more appropriate. Read the changelog, check the support forums for reported issues, take a backup, and then update.
Joomla and Drupal do not have automatic update mechanisms as of this writing. This means you need to be proactive about checking. Set a recurring calendar reminder if nothing else. Weekly checks are a good frequency.
A Simple Update Workflow
Here is the process I follow for every update:
- Read the release notes. Understand what is being fixed.
- Take a full backup. Database and files. Verify the backup is complete.
- Apply the update on a staging environment if you have one.
- Test critical functionality. Forms, login, key pages.
- Apply to production. If staging went smoothly.
- Verify the production site. Spot-check the same functionality.
For security releases, I compress steps 3-4 and go directly to production after backup. The risk of delaying a security patch outweighs the risk of a minor regression.
The Bottom Line
Updating your CMS is not optional. It is not something you get to when you have a quiet afternoon. It is the single most impactful security measure available to you, and it costs almost nothing in time or money. Every day you delay an available security update, you are running a site with a known vulnerability that attackers are actively exploiting.
Set up your notifications. Build the habit. Treat security updates like you would a fire alarm - respond immediately, not when it is convenient.