djbaxter

Administrator
Administrator
Moderator
Joined
Jun 28, 2012
Messages
3,498
Reaction score
1,633
57% of WP Sites Become Less Secure in December 2018
by Roger Montti, Search Engine Journal
November 7, 2018

PHP 5.6 and 7.0, the scripting language that underlies 57.1% of all WordPress sites will stop receiving security updates in December 2018. No security patches will be issued for those versions of PHP after that date, making those sites less secure moving forward.
That could mean a loss of traffic and a ranking nightmare for WordPress websites still using those old versions of PHP in the event of a vulnerability.

php-used-by-wordpress.png

This graph shows the percentage of sites using PHP 5.6 and 7.0. It is somewhat concerning that more than a third of WordPress sites use 5.6.
  • Security updates for PHP 5.6 is ending on December 31, 2018.
  • Security updates and patches for PHP 7.0 are ending on December 3, 2018.
php-version-support.png
This table shows when

PHP 5.6 and 7.0 will no longer receive security updates.

How Many WordPress Sites are at Risk?
According to WordPress’ official published statistics, 57.1% of WordPress sites run these outdated versions of PHP.

Why is Security Support Ending?
Security support for each version is scheduled to last a limited amount of years until it reaches what’s known as End of Life (EOL). At this point there will be no more security improvements created for it, even if a vulnerability is discovered.

All websites are required to upgrade to the latest version or risk becoming vulnerable to hacking events.

What if You Fail to Update PHP?
All websites that fail to upgrade to the latest version of PHP will be insecure and vulnerable to hacking events once versions 5.6 and 7.0 enter their End of Life (EOL) period. This means that even if security vulnerabilities are discovered, nobody will make a patch to fix the vulnerabilties in versions of PHP.

Additionally, many plugins, themes and WordPress itself will eventually stop working with these versions of PHP.

If you run a WordPress website, the most prudent action to take is to upgrade to the latest version of PHP.
 

djbaxter

Administrator
Administrator
Moderator
Joined
Jun 28, 2012
Messages
3,498
Reaction score
1,633
The only thing it affects for me is a couple of small vBulletin 4 forums that won't run above PHP 7.1. Everything else is already running PHP 7.2, but a lot of people rarely check that sort of thing until there's a problem.
 
Similar threads
Thread starter Title Forum Replies Date
djbaxter WordPress: Contact Form 7 File Upload Vulnerability Websites, Software, and Security 0
djbaxter WordPress: The NoneNone Brute Force Attacks: Currently Active Websites, Software, and Security 0
djbaxter New features in WordPress 5.6 Websites, Software, and Security 0
djbaxter PHP 8: What WordPress Users Need to Know Websites, Software, and Security 0
djbaxter Speed Test for WordPress sites Websites, Software, and Security 1
djbaxter New WordPress Toolkit from cPanel Websites, Software, and Security 0
djbaxter Facebook & Instagram embeds on WordPress will break soon Websites, Software, and Security 1
djbaxter WordPress 5.5 update breaks plugins: Here’s the fix Websites, Software, and Security 6
Andrew Scherer Hacking QDF with WordPress Plugins Local Content 2
djbaxter Bing URL Submissions Plugin For WordPress Websites, Software, and Security 2
A What Wordpress Website Builder & Theme do you use? (Page speed in mind) Organic SEO 4
A What Wordpress Speed Optimizing Plugins do you use? Websites, Software, and Security 7
djbaxter WordPress Sites Targeted in Large-Scale Attacks Websites, Software, and Security 0
C Don’t we all want to develop fast websites? WordPress fastest page speeds using background images <srcset>, <img>, <picture>, @media, @2x retina Websites, Software, and Security 0
djbaxter Ninja Forms WordPress Plugin: High Severity Vulnerability Patched Websites, Software, and Security 0
djbaxter Test your Contact Form 7 on WordPress sites! Recycle Bin 4
djbaxter Critical security flaw in WordPress Jetpack plugin Websites, Software, and Security 0
djbaxter Site Kit by Google WordPress plugin Websites, Software, and Security 11
djbaxter WordPress Rich Reviews Plugin Under Active Attack Websites, Software, and Security 1
djbaxter Malicious WordPress Redirect Campaign Attacking Several Plugins Websites, Software, and Security 1
P New wordpress website Websites, Software, and Security 5
Chris Ratchford Anyone familiar w/ Advanced Custom Fields (for WordPress)? Consultant's Corner 6
brettmandoes Speed Plugin for WordPress sites Websites, Software, and Security 19
Jo Shaer Auto publishing from Wordpress blog to GMB post Google My Business & Google Maps 5
D Google Reviews Widget for WordPress Recycle Bin 0
djbaxter Security vulnerability in WordPress Slick Popup Plugin Websites, Software, and Security 1
djbaxter Stay current with the latest WordPress and Plugins Security Issues with this newsletter Websites, Software, and Security 0
djbaxter Urgent! Serious Security Threat Found in WordPress Plugin Yuzo Related Posts Websites, Software, and Security 1
djbaxter Grammarly Adds Junk Code to WordPress Posts and Pages Websites, Software, and Security 4
djbaxter Vulnerabilities in Two WordPress Plugins Websites, Software, and Security 2
djbaxter WordPress 5.1.1 Patches Critical Vulnerability: Update now Websites, Software, and Security 0
R Free Webinar: Wix, Weebly, Squarespace and WordPress - Which Is Best? Events 0
JoyHawkins Who is Switching to Wordpress 5.0? Websites, Software, and Security 13
djbaxter Google WordPress Plugin to Integrate Analytics, Search Console, AdSense, PageSpeed Websites, Software, and Security 4
Dan Foland Has anyone else been experiencing a rise in Brute Force attacks on WordPress recently? Websites, Software, and Security 4
Josh Gill New Wordpress Plugin to Manage GMB Posts Google My Business & Google Maps 12
P Broadband provider blocks wordpress site: Effect on SEO / local search? Local Search 2
P Guide/suggestions for improving my GMB local listing? wordpress plugins? Local Search 14
djbaxter Google Reviews Widget for WordPress Websites, Software, and Security 8
djbaxter WordPress 4.9.8 Released, May Need to Install the Classic Editor Websites, Software, and Security 8
djbaxter WordPress vulnerability, all versions: Check your Author and higher role permissions Websites, Software, and Security 0
djbaxter How to Disable Gutenberg in WordPress Websites, Software, and Security 3
Caroline Google My Business Website PLUS a WordPress one Local Search 8
P Wordpress template for business company Local Search 7
djbaxter WordPress 4.9.4 Fixes Critical Auto Update Bug in 4.9.3 Websites, Software, and Security 0
djbaxter Check your WordPress plugins! Organic SEO 0
dannanelli WordPress Footer Section as a Page Organic SEO 7
djbaxter Marked jump in brute force attacks against WordPress sites Organic SEO 0
G Are any wordpress themes better for local SEO? Local Search 5
djbaxter Static HTML to WordPress site converter Websites, Software, and Security 0

Similar threads

Login / Register

Already a member?   LOG IN
Not a member yet?   REGISTER

Most UpVoted Answers

LocalU Podcasts

  Promoted Posts

New advertising option: A review of your product or service posted by a Sterling Sky employee. This will also be shared on the Sterling Sky & LSF Twitter accounts, our Facebook group, LinkedIn, and both newsletters. More...
Google Product Exert


Top Bottom