TYPO3 maintenance

TYPO3 maintenance: security updates, operations, handover

At Sharpness Solutions GmbH in Oldenburg, TYPO3 maintenance means this: every TYPO3 security bulletin is checked against your installation on the day it is published, and updates run on staging first, then live — inside the window agreed in the service level agreement. Alongside that: extension maintenance, a PHP version that is still supported, backups with tested restores, and support for your editors. We also take over installations somebody else built. Before we do, we look at the code and the hosting and put our assessment in writing. The contract comes after that, not before.

Make an enquiry 0441 21 21 63 0 Mo – Fr, 9:00 – 16:00 Uhr

Where it usually goes wrong

Hardly any enquiry about TYPO3 maintenance starts with an attack. It starts when somebody notices that nobody has touched the system for two years. W3Techs reports shares per TYPO3 major version (retrieved 16 August 2026): 24.8 per cent on version 13, 24.7 per cent on version 12, 17.0 per cent on version 11, 10.3 per cent on version 10, 1.2 per cent on version 14, the rest on older versions. Versions 13 and 14 — the ones still receiving free support — therefore account for 26.0 per cent; the remaining figure of roughly 74 per cent is our own arithmetic and does not appear at W3Techs in that form. The base is the TYPO3 sites recorded by W3Techs whose major version could be identified, not every TYPO3 installation. This is not the exception. This is the normal case.

The old TYPO3 agency has stopped answering

Calls go unanswered, tickets sit open for weeks, the developer who knew the system has left. The website still runs. Nobody knows who would bring it back up if it stopped.

TYPO3 v12: free support ended on 30 April 2026

Free support for TYPO3 v12.4 ended on 30 April 2026. Since then security fixes are only available through paid ELTS, most recently 12.4.48 of 14 July 2026. If you neither buy ELTS nor upgrade, you have been collecting open vulnerabilities since that date.

The updates arrive faster than anyone reacts

On 9 June 2026, fourteen TYPO3 security advisories appeared in a single day, five of them rated High. Affected were the Form Framework, the File Abstraction Layer, the HTML Sanitizer, the DataHandler and Indexed Search — across versions 10 to 14.

Nobody knows whether the TYPO3 backup can be restored

Backups of the TYPO3 database and of fileadmin are running. Whether a working installation can be rebuilt from them has never been tested. In our experience that only becomes clear at the moment it matters.

The editorial team has stopped getting answers

A new colleague is supposed to maintain TYPO3 and cannot find the file upload. At the current provider a question like that starts a ticket process with a quote attached. So nobody asks any more, and the content quietly goes stale.

There is no record of the TYPO3 updates

The data protection officer or the auditor asks when the system was last updated. There is no list, no log, no report. Nothing can be demonstrated with that — and Article 32 of the GDPR (General Data Protection Regulation, in German DSGVO) requires a process for regular review, not a good feeling.

What TYPO3 maintenance actually involves

TYPO3 maintenance consists of four jobs that have little to do with each other: core updates, extension maintenance, keeping the underlying stack current, and support for editors. Regular maintenance releases appear on Tuesdays, roughly once a month per active LTS version. Security releases normally appear on the same Tuesdays — in 2026 on 9 June, 14 July and 11 August — and then for all supported versions at once. The TYPO3 Security Team announces important bulletins beforehand, as a pre-announcement in the TYPO3-PSA format; in urgent cases TYPO3 expressly reserves the right to publish without notice. So the date is predictable, the scope is not: on 9 June 2026 there were fourteen advisories at once. If you only look again at the next monthly slot, until then you are running an installation with publicly documented holes.

A TYPO3 security bulletin is not a warning, it is a work order with everything in it: affected component, vulnerability type, severity, CVSS v4.0 vector, CVE and CWE number, affected and fixed versions. TYPO3-CORE-SA-2026-021 of 11 August 2026, for instance, reports broken access control in ext:backend and ext:install, severity High, CVE-2026-19418, affecting 13.0.0 to 13.4.33 and 14.0.0 to 14.3.5, fixed in 13.4.34 and 14.3.6. From that you can decide in minutes whether an installation is affected. Provided somebody is reading.

We follow the TYPO3 security bulletins through the typo3-announce mailing list, the RSS feed and the channels of the TYPO3 Security Team. Nothing goes straight into production: updates run on a staging copy first, where we check the backend, forms, search, image processing and mail delivery, and only then does the deployment follow. The TYPO3 documentation is quite clear on this: within an LTS line you install every patch release — 13.4.33 is followed by 13.4.34, there are no other steps. Anyone still on a sprint release such as 13.2 has to move to the 13.4 LTS line, because the earlier versions are no longer supported. That is not an agency recommendation, it is in the manual.

TYPO3 versions and support deadlines (as of 16 August 2026)

The version you are running is shown in the backend under Help > About TYPO3 and at the top of the Install Tool; on the command line, composer show typo3/cms-core gives the exact patch version, and in Composer installations so does vendor/bin/typo3 --version. From the outside the version cannot be read reliably. A domain name on its own is therefore not enough for a sound assessment.

As of 16 August 2026 only TYPO3 v13 LTS and TYPO3 v14 LTS receive free security updates. The current patch releases at that date are 13.4.34 and 14.3.6, both of 11 August 2026. Free support runs until 31 December 2027 for v13 LTS and until 30 June 2029 for v14 LTS. TYPO3 v12.4 dropped out on 30 April 2026, v11.5 on 31 October 2024, v10.4 on 30 April 2023. For TYPO3 v9 and older there is no update path left at all: paid ELTS ended for v9.5 on 30 September 2025 and for v8.7 back on 31 March 2024. Source: get.typo3.org, retrieved 16 August 2026. We check versions and deadlines against that source every month.

According to the W3Techs figures of 16 August 2026, the installations they detect break down like this: TYPO3 v13 at 24.8 per cent, v12 at 24.7 per cent, v11 at 17.0 per cent, v10 at 10.3 per cent, v14 at only 1.2 per cent. Held against the support deadlines, 26 per cent of the installations recorded by W3Techs receive free security updates. Another 22 per cent of them run on version 9 or older and have no path left at all. For those 22 per cent a version jump is as a rule no longer an upgrade but a relaunch: the extensions in use mostly no longer exist in a compatible form, and the route across several major versions costs more than a rebuild on TYPO3 v13 LTS with content, media and redirects carried over. If your installation is out of date, you are in the majority. That does not make it any safer.

Between ELTS and an upgrade, the deciding factor is the remaining runtime, not taste. ELTS is bought time: since April 2026 TYPO3 GmbH charges 3,200 euros per year and instance for v12 before discounts, and 2,800 euros unchanged for v10 and v11. An upgrade costs more once and ends the question. The underlying stack always belongs to it: v13 and v14 both require PHP 8.2 to 8.5, MariaDB from 10.4.3 or MySQL from 8.0.17, and Composer from 2.1. Since PHP 8.2 reaches its end of life on 31 December 2026, we plan straight for 8.3 or 8.4 — otherwise the next migration is due within months.

Why an unmaintained installation gets expensive

An unmaintained TYPO3 installation does not get expensive on the day of the attack, but in the months before it: the distance between your version and the current one grows, and with it the number of steps an update has to catch up on. A TYPO3 instance nobody has touched for two years is not one update away, it is a chain: the core jump, extensions with no compatible successor, the PHP version, the database, and custom code in between that nobody documented. Each step depends on the one before it. That is exactly why an update turns into a project with a quote, a schedule and a budget approval.

The second cost of an unmaintained TYPO3 installation is time pressure. When a security bulletin appears and your own instance is affected, there is no longer a choice between doing it properly and doing it fast. That was the situation on 9 June 2026. A maintained system takes fourteen advisories in one pass. An unmaintained one needs an inventory first, then a test environment, then rework on extensions — all at the same time and all in a hurry.

The third cost is the missing record, and it usually turns up only when somebody asks for it. Article 32(1) of the GDPR requires technical and organisational measures in line with the state of the art, expressly including the ongoing assurance of confidentiality, integrity, availability and resilience, rapid restoration after an incident, and a process for regular review. Since December 2025 the German NIS2 implementation act (NIS2-Umsetzungsgesetz) applies on top, to around 30,000 companies in 18 sectors — 11 sectors of high criticality under Annex 1, 7 more under Annex 2 — with a duty to register and reporting deadlines of 24 and 72 hours. Whether your company falls under it is for a lawyer to judge, not your agency.

What a maintenance contract cannot do is prevent a break-in. It shortens the window between bulletin and patch, keeps the underlying stack on a supported version, and makes it demonstrable when action was taken. Nothing more. Anyone who promises more is confusing maintenance with insurance.

Taking over a TYPO3 installation somebody else built

We take over existing TYPO3 installations regardless of who built them — including as ongoing maintenance with no prior work together. That is the most common reason people get in touch: the previous agency has stopped responding, has closed down, or the working relationship is ending for other reasons. What we need is backend access with administrator rights, SSH and SFTP access to the server, access to the Git repository and, ideally, control of the domain and DNS. SSH is the critical point: without shell access, looking after a TYPO3 project takes a considerable detour. If your predecessor does not answer, we request the credentials ourselves.

The inventory comes before the commitment, not after it. We look at the core version and the extension inventory, at the backend accounts and which of them are still in use, at the PHP and database versions, at whether this is a Composer or a legacy installation, at how much custom extension code there is, at TypoScript and TSConfig including the parts stored in the database — and we look in fileadmin for files that have no business being there. If we find traces of a compromise, this is not a maintenance case: then a clean rebuild is due, with its own quote. You cannot take responsibility for a state you do not know.

What turns up is rarely surprising and unpleasant all the same: missing documentation, proprietary extensions without source code, commercial licences in the old agency's name, domain or hosting registered to somebody else, backups that were never restored, unresolved rights of use for bespoke development. We document the initial state and have it confirmed in writing, so that later it stays possible to tell what we found from what we caused. And we say no when a system is built in a way we cannot stand behind.

What a maintenance contract looks like here

A maintenance contract with us has a fixed part and an agreed part. Fixed are: watching the TYPO3 security bulletins and assessing whether you are affected, installing security and bugfix releases after a test on staging, extension maintenance including the question of what happens to unmaintained extensions, keeping PHP and the database current, backups with restore tests, monitoring, and a log of the work carried out. What gets agreed are response and service times: those go into an individual service level agreement, because a university website has different requirements from a sales portal. For public authorities and universities the usual paperwork comes with it: a data processing agreement under Article 28 of the GDPR, servers located in Germany, and update logs in a form you can put in front of your data protection officer. Testing and remediating accessibility under BITV 2.0 (the German accessibility regulation for public-sector websites) is a separate project.

Our regular hours are Monday to Friday, 9:00 to 16:00 CET. A bulletin published on a Friday evening gets assessed on Monday. If you need cover outside those hours, you agree an on-call arrangement in the service level agreement — it costs extra, and without an explicit agreement it does not exist. If operations are part of the deal, the installation runs in our managed hosting, on our own Proxmox clusters, on servers in Germany. Report ongoing faults through the support form at sharpness.de/support or by phone on +49 441 21 21 63 0.

Not included in the maintenance contract are major upgrades between two main versions — from TYPO3 v12 via v13 to v14, for instance — because they mean breaking changes, the upgrade wizard and changes to custom code. New features, redesigns and additional extensions are projects too. At first glance that is less than providers who include everything. Whether it works out cheaper for you depends on how often a major version jump comes round — and one is due at the latest when free support for your LTS line ends.

Support for editors is the fourth of these jobs, and here it is part of TYPO3 maintenance rather than an extra line item. Short questions from the editorial team — why an image is not appearing in the frontend, how a content element is copied into another language, what the cache is currently holding back — get answered without turning into a quotation process. And we set the arrangement up so that you can end it: source code in your repository, credentials and licences issued to your company, domains registered in your name, the installation documented. Dependency is a poor business model and an even poorer argument.

Process

We look inside your TYPO3 installation first.

Send us the domain and, if you have one, a backend login. You get a free written first assessment covering version, extensions and update status — before any contract. Sharpness Solutions GmbH, Edewechter Landstraße 161, 26131 Oldenburg, phone +49 441 21 21 63 0, info@sharpness.de, Monday to Friday, 9:00 to 16:00 CET. We work remotely across Germany, with on-site meetings in Oldenburg and the north-west.

  1. 01

    First conversation, and sorting out access

    You describe the situation, we establish what is there: TYPO3 version, hosting, who the contact at the previous provider is. If credentials are missing, we handle the correspondence with the old agency — you do not have to have an awkward conversation.

  2. 02

    Inventory before the commitment

    We go through the core version, the extension inventory, custom code, TypoScript and TSConfig, the PHP and database versions, the backend accounts and fileadmin. The result is a written assessment: what works, what is open, what will get expensive. Only then do we talk about a contract.

  3. 03

    Staging copy and first test run

    We mirror the live installation into a staging environment and run the first complete update pass there. Whatever breaks, breaks on a copy. This is also where it shows whether the existing backup can actually be restored.

  4. 04

    Handing over operations

    The deployment route, the repository, monitoring and the backup chain move onto our processes. Credentials are issued to your company, not to us. Whether the installation stays with your current hosting or moves to our Proxmox clusters on servers in Germany is your decision.

  5. 05

    First maintenance cycle

    We install the pending security and bugfix releases, clear out unmaintained extensions and document the state of the system. At the end there is a log you can put in front of your management or your data protection officer.

  6. 06

    Ongoing operation, the same contact

    After that the work follows the agreed service level agreement: watching bulletins, testing and installing updates, checking backups, answering questions from the editorial team. You write to the same address and reach the same person as in the first conversation, not a shared inbox.

Projects on this system

A selection — not the full client list.

Frequently asked questions

What is included in a TYPO3 maintenance contract and what is not?

Included are security and bugfix updates to the TYPO3 core, extension maintenance, keeping PHP and the database current, backups with restore tests, monitoring and a log of the work carried out. Not included are major upgrades between two main versions, new features, redesigns and the development of additional extensions — those are separate projects with their own planning and their own quote. Response and service times are not stated as a blanket figure in the contract; they are agreed individually as a service level agreement.

What does a TYPO3 maintenance contract cost at Sharpness?

A maintenance contract is billed by time and materials: a fixed monthly retainer for the standing work, everything beyond it by the hours actually spent. There is no price list, because the price hangs on things that can be checked: the number and type of extensions, the amount of custom code, the level of the service level agreement, whether hosting is included and whether several sites run on one instance. Anyone quoting a monthly price without looking inside the installation is calculating an average, and you pay for it. The first assessment based on the domain and backend access is free; the quote follows the inventory.

Are major upgrades such as TYPO3 v12 to v14 included in the maintenance contract?

No, major upgrades are a separate project and not part of ongoing maintenance. A jump between main versions brings breaking changes, requires the upgrade wizard, means checking every single extension for compatibility and usually means changes to custom code. From v12 to v14 it is also two steps rather than one: the documented route goes via v13, because the core only carries upgrade wizards for the most recent main versions. Updates within a version, from 13.4.30 to 13.4.34 for instance, do belong to maintenance.

Are there guaranteed response times if the website goes down?

We agree guaranteed response times in the service level agreement, graded by the severity of the fault — we do not put a blanket figure on a website. Without an SLA, the general commitment from our support page applies: enquiries are handled in the order received within 48 hours during our business hours, Monday to Friday, 9:00 to 16:00 CET. In the SLA we distinguish response time, meaning when somebody starts work, from restoration time, meaning when the system is running again. Both figures, and any on-call cover outside business hours, are set together with you.

How quickly is the update installed after a TYPO3 security release?

The assessment starts on the day of the bulletin: TYPO3 publishes the patched version at the same time as the advisory, so we check on the same working day whether the listed versions and components affect your particular installation at all — TYPO3-CORE-SA-2026-021 of 11 August 2026, for example, only affected 13.0.0 to 13.4.33 and 14.0.0 to 14.3.5. Then comes the test run on staging, then the deployment. How fast that has to happen at each severity level is written in the SLA, not in an advertising promise.

Which TYPO3 versions still receive free security updates?

As of 16 August 2026 only TYPO3 v13 LTS and TYPO3 v14 LTS receive free security updates. Free support runs until 31 December 2027 for v13 LTS and until 30 June 2029 for v14 LTS. TYPO3 v12.4 dropped out on 30 April 2026, v11.5 on 31 October 2024 and v10.4 on 30 April 2023; for those, fixes are only available through paid ELTS. For TYPO3 v9 and older there is no path left at all. Source: get.typo3.org.

What happens to our website now that TYPO3 12 support has run out?

A website on TYPO3 v12.4 keeps running technically after 30 April 2026 but receives no more free security fixes — every newly reported vulnerability is fixed only in the paid ELTS programme. The current ELTS version is 12.4.48 of 14 July 2026, and the path runs to 30 April 2030. TYPO3 GmbH has charged 3,200 euros per year and instance for it since April 2026, before discounts. Without ELTS and without an upgrade, known vulnerabilities stay open indefinitely.

Should we go to TYPO3 v13 or straight to TYPO3 v14?

For existing projects TYPO3 v13 LTS is currently the recommended version; v14 LTS is worth it mainly when larger changes are due anyway. v13 is maintained free of charge until 31 December 2027, v14 until 30 June 2029 — the longer horizon argues for v14, provided the extensions and the custom code come along. The system requirements do not separate the two: both need PHP 8.2 to 8.5, MariaDB from 10.4.3 or MySQL from 8.0.17, and Composer from 2.1. The decision is made on extensions, custom code and remaining runtime.

What should we do if a TYPO3 website has been hacked?

With a compromised TYPO3 installation the order is this: take the instance off the network or put it into maintenance mode, lock the backend accounts, change the passwords and the encryption key, secure a snapshot of the compromised state instead of overwriting it, then check fileadmin, typo3temp, scheduler tasks and administrator accounts for entries that do not belong — and only then restore. If personal data is affected, the 72-hour reporting deadline under Article 33 of the GDPR is running. You can reach us Monday to Friday, 9:00 to 16:00 CET; outside those hours only with an agreed on-call arrangement.

Do you maintain the extensions as well, or only the TYPO3 core?

Extensions belong to maintenance, because a patched core on its own is not enough. Extensions have bulletins of their own. If an author does not deliver a fix in reasonable time, the Security Team removes the affected versions from the TYPO3 Extension Repository and recommends uninstalling — as in 2026 with TYPO3-EXT-SA-2026-004 on the “Amazon AWS SDK” extension. An extension can even undo a core fix: in TYPO3-EXT-SA-2026-001 of 20 January 2026 the mailqueue extension overrode the FileSpool component, and the vulnerability stayed exploitable despite a patched core until mailqueue itself was updated to 0.5.1 or 0.4.3 respectively.

Can you take over our TYPO3 website even though you did not build it?

Yes, taking over TYPO3 installations built by somebody else is the most common reason people start working with us. We look at the code, the extensions and the hosting before we commit and put our assessment in writing; the contract comes after that. That is not a formality, it is the condition. In rare cases we say no, for instance when central bespoke development was delivered without source code or when we find traces of a compromise — a clean rebuild is then more honest than a maintenance contract.

What can we do if the old TYPO3 agency has stopped responding?

If your previous provider does not respond, we request the credentials ourselves and take over the correspondence — you do not have to have an awkward conversation. What we need is backend access with administrator rights, SSH and SFTP access, the Git repository and, ideally, control of the domain and DNS. In our experience this drags on for weeks. If the domain or the hosting is registered to the old agency, it becomes a legal matter — then a lawyer belongs in the process, and the handover is delayed accordingly.

Do we have to change hosting, or can you work on our server?

We can look after a TYPO3 installation on somebody else's infrastructure as well, as long as there is SSH access, a clean deployment route and sufficient PHP and database versions. Where those are missing, every piece of maintenance costs more than the move would. We run our own Proxmox clusters on servers in Germany; a switch is possible but not a condition. We put the line between hosting and application in writing before we start, so that nobody has to go looking when something breaks.

Are we legally obliged as operators to install TYPO3 updates?

No law states an explicit obligation to update TYPO3. Article 32(1) of the GDPR does require technical and organisational measures in line with the state of the art and a process for reviewing them regularly. An installation carrying vulnerabilities that have been publicly reported for months is hard to justify on that basis, and the accountability under Article 5(2) of the GDPR sits with the controller, not with the agency. Since December 2025, NIS2 applies on top for certain companies. Whether you fall under it is for a lawyer to judge.

Enquiry

Who is looking after your TYPO3 right now?

If the answer is “nobody” or “no idea”, you are in the right place. We look at the code, the hosting and the state of the extensions and tell you what has to happen first — before anyone talks about a contract.

  • An answer from someone who knows the system — no phone queue
  • An assessment before the quote, even when it advises against the project
  • Your details are sent to us by email, not into a third-party CRM

Spam protection: Cloudflare Turnstile — no cookies, no tracking.

Call Start a project