# PHP versions past end of life

> A PHP version that’s no longer maintained stops receiving any security patches, even if a critical flaw is found in it after its end-of-life date: the site keeps running, which creates a false sense of security.

- Source canonique : [https://allaux.fr/en/securite/versions-de-php-en-fin-de-vie](https://allaux.fr/en/securite/versions-de-php-en-fin-de-vie)
- Langue : EN
- Dernière mise à jour : 2026-09-30

## Direct answer

> Read the PHP version actually running: in WordPress under Tools then Site Health, Info tab; in PrestaShop under Advanced Parameters then Information. Compare it with the support calendar published on php.net. Before switching version in your hosting panel, check the compatibility stated by your CMS version and by your modules.

## What "end of life" actually means

PHP is the language PrestaShop, WooCommerce and WordPress run on. Every major PHP version follows an officially published support cycle: roughly two years of active support, during which bugs and security flaws are fixed, followed by a further two years of security-only support, where only critical security fixes are still released. After that, the version isn’t supported at all any more, regardless of how serious a flaw discovered afterwards turns out to be.

The trap lies in a simple detail: a site running on a PHP version past end of life usually keeps working perfectly normally. Nothing shows up, no alert warns the merchant. The site looks stable in a way that’s entirely disconnected from its actual security state.

| Valeur | Description |
|---|---|
| PHP 8.0 / 8.1 | already past end of life, no security fixes at all |
| 31/12/2026 | end of security support for PHP 8.2 |
| 31/12/2027 | end of security support for PHP 8.3 |
| 31/12/2028 | end of security support for PHP 8.4 |

Source : Politique officielle de support PHP

## The particular case of PrestaShop 1.6

PrestaShop officially announced the end of maintenance for version 1.6 as of 30 June 2019. A store still running on that version isn’t only missing patches for the CMS itself: it’s effectively also stuck on an old PHP version that’s long past its own end of life, since recent PHP releases are often no longer compatible with such old code. These two exposed surfaces stack up: the CMS core and the language it runs on both stop receiving any patches at the same time.

## "It still works" is not a security indicator

> A working site on an unsupported PHP version can look perfectly fine for months, even years, before a flaw discovered after its end-of-life date gets exploited with no patch ever able to be released to fix it.

## How to check your PHP version

1. **Check your hosting control panel** — Most hosts display the active PHP version for your site directly in their management interface.
2. **Check the CMS’s system information page** — Both PrestaShop and WordPress usually show the PHP version in use on a diagnostics or system-information page within the back office.
3. **Compare against the official schedule** — The official supported-versions page, maintained by the PHP project itself, lists exactly which versions are still actively supported, which are in security-only support, and which are fully past end of life.
4. **Contact your host if the change looks risky** — Changing PHP version can reveal incompatibilities with an older module. A reputable host can usually offer a test environment before switching the version in production.

## Related reading

- **Abandoned modules and extensions** — Another silent gap between what still runs and what’s genuinely up to date. ([/securite/modules-et-extensions-abandonnes](/securite/modules-et-extensions-abandonnes))
- **SQL injections explained** — The type of flaw most often affected by a lack of security patches. ([/securite/injections-sql-expliquees](/securite/injections-sql-expliquees))
- **Securing your store after a hack** — The full checklist if an infection has already taken place. ([/securite/se-proteger-apres-un-nettoyage](/securite/se-proteger-apres-un-nettoyage))

## FAQ

### Will updating PHP break my site?

That’s the main risk of putting off an update for too long: the bigger the version gap, the more likely incompatibilities become with existing code, core or modules. Testing the migration on a separate environment before going live limits this risk.

### How do I find out which PHP version my hosting offers?

The hosting control panel usually shows it, and your host’s support team can confirm it directly if it’s not visible in the interface.

### Can a store on PrestaShop 1.6 still run securely?

Maintenance for PrestaShop 1.6 ended on 30 June 2019. Without updating the CMS or PHP, no flaw found since then can be officially fixed any more, regardless of severity.

### Who should handle migrating to a recent PHP version?

A host can usually change the available version, but checking that the site’s code, core and modules, stays compatible before switching requires technical work on the CMS itself.

### Is there a grace period after the official end-of-life date?

No. Once that date passes, no security patch is released for that version any more, no matter how serious a flaw discovered afterwards turns out to be.
