Is my PHP version safe?
Find out which PHP version you're running, whether it still gets security fixes, and what else to check.
A PHP version is "safe" only while it still receives security fixes, and even then only if the rest of the stack is kept up too. This guide shows you how to find your version, how to read the answer, and what to do next.
Book a free conversationLegacy System Assessment, from £2,500
Step 1: Find your PHP version
Easiest: ask your host or developer. If you can't, try one of these.
| Where | How |
|---|---|
| Hosting control panel | Look for "PHP version", "MultiPHP" or "Select PHP version" (cPanel, Plesk and most hosts have one) |
| Command line (server) | Run php -v |
| Laravel application | Run php artisan about |
| Composer projects | Check the require → php line in composer.json. That's the minimum the project asks for, not necessarily what's running |
| WordPress | Tools → Site Health → Info → Server |
| A test page | A file that calls phpinfo() shows everything. Delete it straight after. It exposes information attackers use |
Two traps
- The version your website uses can differ from the one on the command line. Many servers run several PHP versions. Check the version the website uses.
- "Supported by my host" isn't the same as "supported by the PHP project". Check both.
Step 2: Is it still supported?
Dates from the official PHP supported-versions page, checked October 2026. Always confirm at php.net/supported-versions.
| PHP version | Security support ended / ends | Status |
|---|---|---|
| 5.6 and older | 2018 or earlier | End of life |
| 7.0 - 7.3 | 2019 - 2021 | End of life |
| 7.4 | November 2022 | End of life |
| 8.0 | November 2023 | End of life |
| 8.1 | 31 December 2025 | End of life |
| 8.2 | 31 December 2026 | Security fixes only, ending soon |
| 8.3 | 31 December 2027 | Security fixes only |
| 8.4 | 31 December 2028 | Supported |
| 8.5 | 31 December 2029 | Supported |
End of life means a vulnerability found tomorrow will never be fixed in that version. Attackers know this and scan for old versions automatically.
Step 3: Read your result
| If you're on | What it means | What to do |
|---|---|---|
| 5.6, 7.x, 8.0, 8.1 | Unsupported. No security fixes | Plan an upgrade now. The older the version, the bigger the jump. PHP upgrade service |
| 8.2 | Supported for a few more weeks | Plan the move before 31 December 2026 |
| 8.3 | Supported until the end of 2027 | Fine for now. Put the next upgrade in your diary |
| 8.4 or 8.5 | Current | Keep it updated, and check everything else below |
"Supported" doesn't mean "safe"
The PHP version is one layer. An application is only as safe as its weakest part. Check these too.
- Your framework or CMS. Laravel, Symfony, CodeIgniter, Drupal, WordPress and others have their own support dates. Laravel upgrades
- Plugins, themes and packages. Abandoned ones are a common way in. If you have command-line access to a Composer project,
composer auditreports known vulnerabilities in your dependencies. - The database. Old versions of MySQL or MariaDB stop receiving fixes too.
- The operating system. End-of-life Linux releases stop getting security updates, which affects everything running on them.
- Your own code. Old applications often contain weaknesses that no update fixes. Security audit
- Backups, logging and access controls. Prevention is only half the job. Detection and recovery matter too.
A note on "backported" fixes
Some Linux vendors and hosts backport security fixes to older PHP versions after the PHP project has stopped supporting them, and some offer paid extended support.
- It can be a legitimate short-term bridge, because the version number alone doesn't tell the full story.
- It's not a long-term answer. It costs money every month, doesn't fix the underlying problem, and may still be flagged by insurers, auditors and customer security questionnaires.
- Ask your host exactly what's covered and for how long.
Why this matters beyond security
- Your host will drop old versions on their schedule, not yours. Sites break with little warning.
- Cyber insurance, Cyber Essentials and customer audits increasingly ask about unsupported software. Data protection and security
- Modern libraries, payment providers and APIs increasingly require current PHP.
- Each year you wait, the jump gets bigger and costlier.
What to do next
- Find your version (Step 1).
- Check it against the table (Step 2).
- Ask your host for any end-of-support dates they've set, in writing.
- If you're unsupported, or close to it, get an assessment. It maps what an upgrade involves and what could break, before you commit to anything. Legacy System Assessment, from £2,500
- If something already looks wrong (redirects, spam pages, a host warning), treat it as urgent. Hacked site cleanup
Frequently asked questions
Is PHP 8.1 still safe?
No, it no longer receives security fixes. Support ended on 31 December 2025. Plan the upgrade to a supported version.
My site works fine on an old version. Why upgrade?
Working isn't the same as safe. It works until a vulnerability is exploited, your host drops the version, or a customer asks for evidence. Fixing it on your own timetable is cheaper than doing it in a crisis.
Is it safe to just change the PHP version in my hosting panel?
Not on its own. Old code often breaks on newer PHP. A change can take a site down, so test on a copy first. How I upgrade safely
How often does PHP release a new version?
About once a year. Each version is supported for around four years in total. That's why this is a routine task and not a one-off.
Can you check my version for me?
Yes. Tell me where the site lives and I'll find out. Get in touch
Tell me what you've inherited.
Not sure what you're running or how exposed you are? Tell me what you know, and I'll tell you honestly what it means.
Book a free conversationLegacy System Assessment, from £2,500