Merchlint
Available now
Next, in this order
  • DeutschDE
  • EspañolES
  • FrançaisFR
  • ItalianoIT
  • PortuguêsPT
  • NederlandsNL
  • SvenskaSV
  • TürkçeTR

A language shows up here once its pages are actually written. Nothing on this site is machine-translated.

Install free
← All checks

PHP, WordPress or WooCommerce past support

Software past its support window stops receiving security fixes. Nothing about the store changes on that day, which is exactly why it goes unnoticed for years.

Group
Environment
Confidence
H — heuristic
Version
Free
Updated
Code
E1

The symptom

There isn’t one. A PHP release does not stop working on the day its support ends; it keeps serving pages exactly as it did the day before.

You find out sideways. A plugin update refuses to install because it requires a newer PHP. A payment gateway sends a notice about a minimum version. A developer looks at the site and asks a question with a particular tone. By then the version has usually been out of support for a couple of years.

What it costs

Security fixes stop. This is the whole of it, and it is enough. PHP 7.4 stopped receiving security support on 28 November 2022. A vulnerability found in it after that date is simply never patched upstream — there is no notification, because there is nobody left to send one.

Everything else follows from that:

  • The ecosystem moves on. Plugin and theme authors raise their minimum requirements, and at some point an update you need refuses to install. That is usually the moment the upgrade becomes urgent rather than sensible, which is the worst time to do it.
  • You lose real speed for free. Modern PHP is substantially faster than 7.x on the same code — on a store, that is a lower response time on every page, without touching anything.
  • Payment and shipping integrations set their own floors. They are the least willing to support old runtimes, for obvious reasons.

For WordPress and WooCommerce the shape is the same, with one difference: WooCommerce supports the two most recent releases, and its own compatibility declarations assume you are inside that window.

How to check it yourself

wp cli info | grep "PHP version"
wp core version
wp plugin get woocommerce --field=version

Then compare each against its vendor’s published support window — php.net lists supported branches and their end dates, and WordPress and WooCommerce both publish theirs.

For PHP, php -v on the command line is not necessarily the version your site runs: many hosts use one binary for CLI and another for the web server. wp cli info reports the CLI one too. The value that matters is what PHP-FPM serves, which you can read from the WordPress admin under Tools → Site Health → Info → Server.

How to fix it

  1. PHP first. It is the largest gain and usually the smallest task — with most hosts it is a dropdown in the control panel.
  2. On a staging copy, never on production. Switch the version there, click through the store, place a test order, and watch the error log rather than the screen. Fatal errors from an incompatible plugin are loud and immediate; deprecation warnings are quiet and go to the log.
  3. Update WordPress and WooCommerce in that order, and take a backup you have actually restored at least once.
  4. If a plugin blocks the upgrade, that is the finding, not the PHP version. An abandoned plugin holding a whole store on an unsupported runtime is a decision waiting to be made — the Pro add-on has a check for plugins that require newer PHP than you have.

When it is a false positive

  • Hosts that backport security patches. Some enterprise distributions and managed hosts maintain their own patched builds of PHP past its upstream end of life. The version number cannot tell you this — only your host can. If that is your situation, the finding is a fact about the version string and not a statement about your risk.
  • A version that went out of support last week. Real, but not urgent. The check reports the fact; the urgency is yours to judge.
  • Deliberately pinned versions during a migration or a certification process.

How Merchlint finds it

Merchlint reads the running PHP, WordPress and WooCommerce versions and compares them against a table of support windows shipped inside the plugin.

That is the important detail, and it is a consequence of a promise made elsewhere: the plugin makes no outbound connections at all, so it cannot ask php.net anything. The table travels with the release and is updated when the plugin is updated — which means a plugin that has not been updated in a year is working from a table that is a year old. It will not raise a false alarm about a version that is still supported; it may fail to warn about one that has just fallen out.

That is why this check is marked H — heuristic, while almost every other check in the free version is F. The version numbers themselves are fact, read directly. The judgement “past its support window” depends on a table that can age, and a check that depends on something that can age should say so rather than present itself as certainty.

The finding shows each version read, the window it was compared against, and the date of the table.

Run this check on your store

Disagrees with what you see in your store? Write to us — we read every message. contact@merchlint.com