CentrioHost Blog

Stories and News from IT Industry, Reviews & Tips | Technology Blog


Why You Should Be Using Supported PHP Versions

  • Category : cPanel Tutorials
  • Posted on : Sep 04, 2018
  • Views : 3,202
  • By : Barton S.

PHP is one of the most popular scripting languages on the web today. According to W3Techs, PHP is used by over 78% of all the websites who use a server-side programming language. This means for almost every 8 out of 10 websites you visit, they are most likely utilizing PHP in some form or another which also means that PHP is not dead. And of course, it plays a very vital role as it pertains to the WordPress ecosystem, as the entire CMS is built on PHP.

A dilemma we are facing today is that many businesses, developers, and hosts have fallen behind when it comes to supporting the latest PHP versions. Some of the statistics below might even shock you. Today we want to discuss some of the reasons why it is so important that everyone uses the latest PHP versions, not only for security reasons but also for better performance and support.

  • Why Are There Old PHP Versions?
  • Reasons Why You Should Update PHP Versions
  • Make Sure Your Host Supports the Latest PHP Versions
  • Check your Current Version of PHP
  • What Should Less Tech-Savvy Users or Those Without a Budget Do?
  • How to Update PHP

Old PHP Versions

As with any piece of software, PHP has a release life cycle in which has to adhere to in order to keep pushing things forward and making improvements.  Each major release of PHP is typically fully supported for two years after its release. During that time, bugs and security issues are fixed and patched on a regular basis.

PHP 5.6 and PHP 7.0 End of Life

As of December 3rd, 2018, PHP 7.0 has reached its end of life. This means it will no longer have security support and could be exposed to unpatched security vulnerabilities. Following suit, as of December 31st, 2018, PHP 5.6 also reached its end of life. This officially marks the end of an era for PHP 5, as the first version, 5.0 was launched 14 years ago.

According to the official WordPress Stats page, as of writing this, over 57% of WordPress users are still on PHP 5.6 or lower. If you combine this with PHP 7.0, a whopping 77.5% of users are currently using PHP versions that is no longer supported as of January 2019.

It’s even scarier if you look at the stats outside of the WordPress community. According to W3Techs, PHP 5 is currently used by 73.1% of all websites who use PHP.

This is not only bad from a security perspective, but also because there is still a large portion of WordPress sites that aren’t taking advantage of the additional performance enhancements with PHP 7.

Why the Slow Adoption of Newer Versions?

The main reason for the lack of faster adoption for new versions most likely comes down a few different factors:

  • The number one reason we see from new customers that migrate to Host SEO is that business owners don’t know or care about their PHP version. This, of course, is understandable in some cases as we don’t expect everyone to know this.  Many times this responsibility falls on the developer, agency, or host.
  • It takes time for developers to update their code to support newer versions of PHP. This includes those that develop websites, themes, plugins, etc.
  • Not only does it require effort and time to update code, it also can require extensive testing to ensure compatibility. The WordPress repository alone has over 49,000 plugins!
  • Many WordPress hosts have been reluctant to push out updated PHP versions because this could end up resulting in additional support tickets if it breaks a site. As a WordPress host we definitely understand this, but from our experience, this is typically the other way around. Many support issues we see are from issues caused by older PHP versions.
  • The developer or agency might be stuck between a rock and a hard place when dealing with a client and other 3rd party applications they are unwilling to spend resources on updating.

However, with all that being said, it is still not an excuse to run on PHP versions that are out of date, not supported, and actually could be slowing your WordPress site down. The good news is that there is some progress being made.  Jordi Boggiano, co-founder of Private Packagist, puts together a report each year on PHP usage statistics. And as you can see below, there is some movement forward. This is of course just a sample subset of Composer installs, but still interesting to see the changes.

Reasons Why You Should Update PHP Versions

Check out some of the reasons below why you should think about updating if you haven’t already.

1. Security

One of the most important reasons to update PHP is to ensure you are running on a version that is fully supported and patched regularly for security vulnerabilities. PHP 5.4 has not been patched since 2015. And PHP 5.5 has not been patched since 2016. It is important to note though, that some operating system vendors still update older versions of PHP if they included it.

According to CVE Details, 2016 was one of the worst years for PHP security vulnerabilities, with over 100 issues reported. These included DoS, code execution, overflow, memory corruption, XSS, directory traversal, bypass, and gain information types. 2017 was the third-worst year since 2,000, with over 40 vulnerabilities.

Even PHP themselves give some feedback about staying current:

2. Performance

With the release of  PHP 7.2 and PHP 7.3 came huge performance gains! So big in fact, that it should be a priority over a lot of the small optimizations you might playing around with on your WordPress site. The following benchmarksd emonstrate significant performance improvements with PHP 7 over its previous iterations. PHP 7 allows the system to execute twice as many requests per second in comparison with the PHP 5.6, at almost half of the latency.

We also ran our own PHP benchmarks. And similarly to the benchmarks above, we saw that PHP 7.3 could execute almost three times as many transactions (requests) per second as compared to PHP 5.6. PHP 7.3 is also on average 9% faster than PHP 7.2.

  • WordPress 5.0 PHP 5.6 benchmark: 91.64 req/sec
  • WordPress 5.0 PHP 7.0 benchmark results: 206.71 req/sec
  • WordPress 5.0 PHP 7.1 benchmark results: 210.98 req/sec
  • WordPress 5.0 PHP 7.2 benchmark results: 229.18 req/sec 
  • WordPress 5.0 PHP 7.3 benchmark results: 253.20 req/sec ?

Christian Vigh also published a PHP performance comparison in which he found that PHP 5.2 was 400% slower than PHP 7.