PHP versions past end of life
A PHP version that’s no longer maintained stops receiving any security patches, even if a critical flaw is found in it after its end-of-life date: the site keeps running, which creates a false sense of security.
What "end of life" actually means
PHP is the language PrestaShop, WooCommerce and WordPress run on. Every major PHP version follows an officially published support cycle: roughly two years of active support, during which bugs and security flaws are fixed, followed by a further two years of security-only support, where only critical security fixes are still released. After that, the version isn’t supported at all any more, regardless of how serious a flaw discovered afterwards turns out to be.
The trap lies in a simple detail: a site running on a PHP version past end of life usually keeps working perfectly normally. Nothing shows up, no alert warns the merchant. The site looks stable in a way that’s entirely disconnected from its actual security state.
- PHP 8.0 / 8.1 already past end of life, no security fixes at all
- 31/12/2026 end of security support for PHP 8.2
- 31/12/2027 end of security support for PHP 8.3
- 31/12/2028 end of security support for PHP 8.4
Politique officielle de support PHP
The particular case of PrestaShop 1.6
PrestaShop officially announced the end of maintenance for version 1.6 as of 30 June 2019. A store still running on that version isn’t only missing patches for the CMS itself: it’s effectively also stuck on an old PHP version that’s long past its own end of life, since recent PHP releases are often no longer compatible with such old code. These two exposed surfaces stack up: the CMS core and the language it runs on both stop receiving any patches at the same time.
How to check your PHP version
-
Check your hosting control panel
Most hosts display the active PHP version for your site directly in their management interface.
-
Check the CMS’s system information page
Both PrestaShop and WordPress usually show the PHP version in use on a diagnostics or system-information page within the back office.
-
Compare against the official schedule
The official supported-versions page, maintained by the PHP project itself, lists exactly which versions are still actively supported, which are in security-only support, and which are fully past end of life.
-
Contact your host if the change looks risky
Changing PHP version can reveal incompatibilities with an older module. A reputable host can usually offer a test environment before switching the version in production.
Related reading
Describe your need in one minute
A few targeted questions so I can reply with an estimate rather than another questionnaire.