Available for projects & agency overflow · Quick reply, from the person who does the work

PHP versions past end of life

A PHP version that’s no longer maintained stops receiving any security patches, even if a critical flaw is found in it after its end-of-life date: the site keeps running, which creates a false sense of security.

Describe my issue Send a message

What "end of life" actually means

PHP is the language PrestaShop, WooCommerce and WordPress run on. Every major PHP version follows an officially published support cycle: roughly two years of active support, during which bugs and security flaws are fixed, followed by a further two years of security-only support, where only critical security fixes are still released. After that, the version isn’t supported at all any more, regardless of how serious a flaw discovered afterwards turns out to be.

The trap lies in a simple detail: a site running on a PHP version past end of life usually keeps working perfectly normally. Nothing shows up, no alert warns the merchant. The site looks stable in a way that’s entirely disconnected from its actual security state.

  • PHP 8.0 / 8.1 already past end of life, no security fixes at all
  • 31/12/2026 end of security support for PHP 8.2
  • 31/12/2027 end of security support for PHP 8.3
  • 31/12/2028 end of security support for PHP 8.4

Politique officielle de support PHP

The particular case of PrestaShop 1.6

PrestaShop officially announced the end of maintenance for version 1.6 as of 30 June 2019. A store still running on that version isn’t only missing patches for the CMS itself: it’s effectively also stuck on an old PHP version that’s long past its own end of life, since recent PHP releases are often no longer compatible with such old code. These two exposed surfaces stack up: the CMS core and the language it runs on both stop receiving any patches at the same time.

How to check your PHP version

  1. Check your hosting control panel

    Most hosts display the active PHP version for your site directly in their management interface.

  2. Check the CMS’s system information page

    Both PrestaShop and WordPress usually show the PHP version in use on a diagnostics or system-information page within the back office.

  3. Compare against the official schedule

    The official supported-versions page, maintained by the PHP project itself, lists exactly which versions are still actively supported, which are in security-only support, and which are fully past end of life.

  4. Contact your host if the change looks risky

    Changing PHP version can reveal incompatibilities with an older module. A reputable host can usually offer a test environment before switching the version in production.

Related reading

Describe your need in one minute

A few targeted questions so I can reply with an estimate rather than another questionnaire.

constat
plateforme
depuis-quand (facultatif)
sauvegarde
Please provide an email or a phone number so I can get back to you.

Please provide an email or a phone number so I can get back to you.

Frequently asked questions

Will updating PHP break my site?
That’s the main risk of putting off an update for too long: the bigger the version gap, the more likely incompatibilities become with existing code, core or modules. Testing the migration on a separate environment before going live limits this risk.
How do I find out which PHP version my hosting offers?
The hosting control panel usually shows it, and your host’s support team can confirm it directly if it’s not visible in the interface.
Can a store on PrestaShop 1.6 still run securely?
Maintenance for PrestaShop 1.6 ended on 30 June 2019. Without updating the CMS or PHP, no flaw found since then can be officially fixed any more, regardless of severity.
Who should handle migrating to a recent PHP version?
A host can usually change the available version, but checking that the site’s code, core and modules, stays compatible before switching requires technical work on the CMS itself.
Is there a grace period after the official end-of-life date?
No. Once that date passes, no security patch is released for that version any more, no matter how serious a flaw discovered afterwards turns out to be.