Latest posts Visit blog

On 31 July 2024 the transition period for Shopware 5 came to an end - since then, no more security patches have been released for this version (Shopware). Anyone still running their online shop on Shopware 5 in 2026 is working with software whose known vulnerabilities no one officially fixes anymore. Two years after end of life, this is no longer a theoretical residual risk but a concrete security and liability question. This guide shows why the move to Shopware 6 is now due, how it differs from an ordinary update and how to plan cost, duration and process realistically - so that a mandatory deadline becomes a controlled migration process rather than an emergency.

What Ended on 31 July 2024

After a roughly four-year transition period, Shopware 5 was finally discontinued at the end of July 2024 (Shopware). End of life means more than the absence of new features: there are no more security patches, no bug fixes and no official compatibility maintenance with new PHP versions (Shopware). Support in the official Shopware 5 forum has also been discontinued. A shop on this foundation remains technically operational, but from the deadline onward it ages without a brake - every new vulnerability that becomes known in one of its components stays open permanently.

This is not a niche issue. Estimates suggest that thousands of shops in the DACH region are still running Shopware 5 in 2026 without any safeguard in place (Storeleads). Many of them have grown over years and are deeply interlinked with inventory management, payment services and individually developed extensions - which is exactly what makes the switch complex and tempts people to postpone it. But postponing does not shift the risk, it enlarges it. The longer a legacy shop sits online without patches, the greater the number of known but unclosed attack points becomes.

An important distinction: end of life is not the same as an immediate shutdown. The shop does not disappear, and on day one nothing seems to change for the operator. This deceptive calm is precisely the trap. The damage does not occur on the deadline but creeps in - in the form of new vulnerabilities, outdated dependencies and a growing distance from the current state of technology. The same applies to other discontinued building blocks in the shop environment, such as the database layer, whose support has likewise expired.

End of life means the window is already open

The deadline was in July 2024. In 2026, every remaining Shopware 5 shop has therefore been outside of security support for over two years. The question is no longer whether to migrate, but only how orderly the switch will be - planned and tested, or under time pressure after an incident.

Why a Legacy Shop Becomes a Liability Risk in 2026

The threat landscape has worsened noticeably in recent years. Around 34 percent of companies fell victim to a ransomware attack in 2025 (Bitkom Economic Protection 2025), and roughly 80 percent of all security-relevant incidents hit small and medium-sized enterprises (Bitkom Economic Protection 2025) - precisely the businesses that rarely maintain their own security team. The total economic damage from cyberattacks, data theft and sabotage in Germany adds up to around 289 billion euros per year (Bitkom 2025).

For an unpatched shop this is especially relevant, because attackers prefer to target where known gaps stay open. In the current Verizon Data Breach Investigations Report, the exploitation of vulnerabilities is, at around 31 percent, for the first time the most common initial attack path and grew by roughly 55 percent year over year (Verizon DBIR 2026). At the same time the number of new vulnerabilities is rising: the German Federal Office for Information Security records around 24 percent more new security gaps per day in its situation report (BSI). And retail is a preferred target - between 2023 and 2024 alone, more than 230 billion attacks on commerce organisations were recorded (Akamai).

Beyond the pure security question comes the legal dimension. The GDPR requires technical and organisational measures in line with the state of the art (Art. 32 GDPR). Deliberately continuing to run software that has received no security updates for over two years is hard to defend as such a state of the art in the event of damage. Anyone processing payment data additionally falls under the card payment standard: since April 2025 all requirements of PCI DSS 4.0.1 are binding, and every assessment in 2026 is conducted against this version (PCI SSC). Non-compliance can be penalised, depending on merchant level, with 5,000 to 100,000 US dollars per month (PCI SSC). An outdated, no longer maintained shop foundation makes meeting these requirements considerably harder, as our article on PCI DSS 4.0 compliance shows in detail.

Unpatched gaps are an open gate

Attackers scan the internet automatically for known vulnerabilities in widely used software. A shop whose core and libraries have not been updated since end of life offers an ever-growing attack surface over time. Manipulations in the payment flow are especially critical: a single injected script can siphon off card data. How to detect and defend against such checkout skimming depends heavily on a current, well-maintained foundation.

Shopware 5 versus Shopware 6: What Changes Technically

Shopware 6 is not a revised version of Shopware 5, but a platform rebuilt from the ground up. This explains why the switch involves more effort than a version jump within one product line - and why it pays off. Instead of the older foundation from the Shopware 5 era, Shopware 6 relies on a modern stack: the current release 6.7 is based on Symfony 7 and supports PHP 8.2, 8.3 and 8.4 (Shopware). The admin backend is a standalone application built on Vue, the system is API-first from the outset and can therefore also be run headless.

AspectShopware 5 (EOL)Shopware 6
Security patchesNone since 07/2024Ongoing
PHP basePHP 7.x at its limitPHP 8.2 to 8.4
FrameworkOlder stackSymfony 7, Twig
ArchitectureMonolithicAPI-first, headless-ready
Extensions5.x pluginsApps and plugins rebuilt
AccessibilityHard to retrofitCleanly achievable

The difference in the extension system is particularly significant in practice. Plugins from the Shopware 5 world do not run under Shopware 6 - they must be replaced with current extensions or rebuilt. The same applies to individually developed code and the theme. Anyone wanting to know how deeply the extension architecture has changed between the generations will find a technical insight in our article on plugin migration to 6.7. For operators, the key insight is: the functional scope is reassembled, not simply copied.

The Switch Is a Rebuild, Not an Update

Unlike a minor update, Shopware 5 cannot be transferred to Shopware 6 at the push of a button. The database structure, templating and extension concept differ fundamentally. The path therefore leads through a parallel rebuild: a fresh Shopware 6 is set up, and the existing data is transferred in a targeted way. For this, Shopware provides a migration connector that moves master and transactional data from the legacy shop into the new environment (Shopware).

Typically transferred are articles, categories, customers, orders and media. Not transferred are the theme, individually developed code and plugins - these building blocks are recreated in the new system. This is exactly where the main effort of a migration lies, and exactly where the later quality of the shop is decided. The rebuild is therefore less a loss than an opportunity to shed ballast accumulated over years and to clean up the structure.

Gets migrated

Articles, categories, customers, orders and uploaded media - the actual data foundation of the shop is transferred via the connector.

Gets rebuilt

Theme, individually developed code and all 5.x plugins are recreated in the new system or replaced with current extensions.

Gets reconnected

Interfaces to inventory management, payment and shipping are reconfigured and tested for Shopware 6 - for example the ERP connection.

Planning Cost and Timeline Realistically

Because every migration reflects the individual layout of a grown shop, there is no flat rate. As guidance: shops with their own theme, individual plugins or an ERP connection typically need three to six months for the full move (Shopware/Qualimero). For the cost range alone, very different figures circulate depending on scope. A simple migration of a largely standard shop with little individual development is often budgeted in the range of around 15,000 to 25,000 euros (Qualimero); complex B2B projects with deep ERP and PIM integrations tend to lie well above that. These figures are reference points, not fixed requirements - the real effort depends on the following drivers.

Cost driverLow effortHigh effort
Theme and designClose to standardFully custom
Number of pluginsFew standard appsMany custom builds
InterfacesNone or oneERP, PIM, several systems
Data volume and historyManageableExtensive, many years
Custom logicBarely anyComplex B2B processes
What postponing costs

The one-off migration budget stands against the ongoing risk of an unpatched shop. A single successful attack can trigger lost revenue, recovery costs, potential fines and loss of trust all at once - with 34 percent of companies hit by ransomware in 2025 (Bitkom Economic Protection 2025), that is not an exceptional scenario. The migration is therefore less an expense than insurance for the ongoing business.

Migration Step by Step

An orderly switch follows a clear sequence. The following steps have proven themselves in practice and can be applied regardless of shop size:

  1. Inventory: capture the current state - installed plugins, interfaces, individual developments, data volume and special logic. This audit determines scope and budget.
  2. Target definition: decide what is taken over, what is replaced and what is rethought. Not every legacy feature has to move one to one - the switch is the right moment to tidy up.
  3. Test data migration: run the migration connector in a test environment first, checking the completeness and correctness of the transferred records.
  4. Frontend and theme anew: implement the design in Shopware 6 - a good moment to build in performance and accessibility from the start.
  5. Plugins and interfaces: set up or newly develop the required extensions and configure the connections to inventory management, payment and shipping.
  6. Test and sign-off: check the order process, payment, tax and data transfer end to end in a staging environment before the shop goes public.
  7. Go-live with an SEO move: use 301 redirects to lead the old URLs to the new addresses so that rankings and existing links are preserved.
  8. Anchor maintenance: after go-live, establish regular updates and monitoring so the new shop stays current in the long term.
Test the data transfer first

The migration connector moves large amounts of data automatically - which is exactly why every transfer belongs in a test environment first. Only when articles, prices, customers and orders arrive there completely and correctly does the productive run follow. Just as important is the SEO move: without carefully placed 301 redirects, the shop risks visibility losses that are only laboriously recovered later.

Using the Migration as an Opportunity

A forced switch sounds like an obligation at first. In reality, though, the rebuild in Shopware 6 opens up options that were hard or impossible to reach on Shopware 5. Anyone tackling the migration anyway should deliberately take these levers along instead of merely rebuilding the old shop.

Performance and load time

The modern foundation and a cleanly built frontend enable short load times and good Core Web Vitals - a factor that influences both conversion and visibility.

Accessibility from the start

Since 2025 the German Accessibility Strengthening Act applies, and authorities now scan shops automatically for accessibility. Shopware 6 allows a barrier-free implementation cleanly from the ground up instead of grafting it on afterwards.

B2B capabilities

For business customers the new platform offers mature building blocks - from price lists to approval workflows. Our overview of B2B e-commerce shows the possibilities.

Secure, maintained operation

With regular updates and managed hosting the shop stays current in the long run - security moves from a special project to a normal state.

So that the new shop does not become outdated again within a few years, a reliable update process belongs to it from the start. How to apply updates safely without endangering ongoing operations is as much part of the planning as the migration itself. That turns a one-off effort into a durable, sustainable operation.

  • The shop still runs on Shopware 5 and has received no security patches since 07/2024
  • Installed plugins and interfaces are recorded and checked for Shopware 6 availability
  • A realistic timeline and budget are set out according to complexity
  • The data transfer was first checked in a test environment
  • 301 redirects for SEO preservation are prepared
  • An update and maintenance concept secures the new shop for the long term

Plan Now Instead of Postponing Further

Running a Shopware 5 shop in 2026 is not a neutral state but a risk that grows with every month. The good news: the switch can be shaped in a planned way and in calm waters, as long as it is not forced by an incident. As a Shopware agency we accompany the path from the inventory and concept through the tested data transfer to go-live with a clean SEO move. Anyone who additionally approaches the switch with IT security in e-commerce in mind turns a mandatory task into a real modernisation step.

The best time for the migration was the deadline in July 2024. The second best is now - before the known risk turns into concrete damage. Talk to us if you would like to review the current state of your shop and set up a realistic roadmap for the move to Shopware 6.

Sources

This article draws on the official Shopware information about the end of life of Shopware 5 and the migration to Shopware 6, the Bitkom Economic Protection 2025 (ransomware exposure, share of affected SMEs, annual total damage), the Verizon Data Breach Investigations Report 2026 (exploitation of vulnerabilities as the most common attack path), the situation reports of the German Federal Office for Information Security (BSI), information from the PCI Security Standards Council (PCI SSC) on PCI DSS 4.0.1, threat data from Akamai as well as market and cost estimates from Storeleads and Qualimero. The figures mentioned may change over time and serve as guidance; this article does not replace individual security or legal advice. As of August 2026.

Technically, a Shopware 5 shop keeps running after July 2024. However, there are no more security patches, bug fixes or compatibility maintenance (Shopware). The shop therefore ages without a brake: every new vulnerability stays open, and the attack surface grows over time. Usable here does not mean secure - continued operation is a deliberately accepted and rising risk.

There is no fixed legal migration date. The security-relevant deadline, however, was 31 July 2024, when the security updates ended (Shopware). Since the risk rises with every month without patches and around 34 percent of companies were hit by ransomware in 2025 (Bitkom Economic Protection 2025), experience suggests: the sooner the better. A planned migration is much calmer than one forced after an incident.

Shops with their own theme, individual plugins or an ERP connection typically need three to six months (Shopware/Qualimero). Largely standard shops with little individual development are usually finished faster. The actual duration depends on the extent of customisation, the number of interfaces and the data volume - a prior inventory provides a reliable estimate.

There is no flat rate, because every grown shop is laid out differently. A simple migration of a standard shop is often budgeted in the range of around 15,000 to 25,000 euros (Qualimero); complex B2B projects with deep ERP and PIM integrations tend to lie above that. The main drivers are the theme, the number of plugins, interfaces and individual logic. An inventory provides clarity here.

For the data move, Shopware provides a migration connector that typically transfers articles, categories, customers, orders and media (Shopware). The theme, individually developed code and 5.x plugins, by contrast, are not taken over but rebuilt or replaced in the new system. The data transfer should first be checked in a test environment before the productive run takes place.

With a platform switch, URL structures often change. So that rankings and existing links are preserved, the old addresses are led to the new ones via 301 redirects. If this SEO move is carefully planned, visibility can usually be largely retained. Without clean redirects, by contrast, avoidable losses loom that are only laboriously recovered later.