PHP 5.6 went end-of-life in December 2018. PHP 7.x is two to three times faster for typical WordPress workloads and receives active security updates. Many hosts still run outdated versions. Here's what you need to know.
WordPress is written in PHP. When a visitor loads a page on your site, the PHP interpreter on your server executes WordPress's code to generate the HTML response. The version of PHP your hosting provider runs has a direct impact on how fast this happens — and on whether your site is running on software that receives security patches.
PHP 7.0 was released in December 2015 and delivered performance improvements over PHP 5.x that were, for PHP, extraordinary. Independent benchmarks consistently showed PHP 7.0 executing WordPress workloads roughly twice as fast as PHP 5.6. PHP 7.1, 7.2, and 7.3 continued to improve on that.
The improvement comes from fundamental changes to PHP's internal engine, including a new abstract syntax tree representation and improved memory efficiency. These aren't configuration tweaks — they're architectural changes that benefit every PHP application, including WordPress and all its plugins.
In practical terms: a WordPress site on PHP 7.x will generate pages significantly faster than the same site on PHP 5.6, with the same hardware and configuration. The speed gain from upgrading PHP often exceeds what you'd get from optimising your theme or plugin setup.
PHP 5.6 reached official end of life on 31 December 2018. End of life means no more security patches from the PHP project. Vulnerabilities discovered in PHP 5.6 after that date will not be fixed.
PHP 7.0 reached end of life in December 2018 as well. PHP 7.1 in December 2019. At the time of writing, PHP 7.2 and above remain supported. Running anything below 7.2 means running software with known, unpatched security vulnerabilities.
The risk isn't hypothetical. PHP vulnerabilities can be exploited to execute code on your server regardless of how well your WordPress configuration is secured. A vulnerability in the PHP interpreter itself is underneath all the WordPress-level security you've applied.
Upgrading PHP across a shared hosting environment is disruptive. Some customers' older PHP code doesn't work on newer versions. Hosts face support tickets and complaints when they update PHP. The easiest path is to leave old versions available indefinitely, even after they're end-of-life.
Some hosts default new accounts to a current PHP version but leave existing accounts on whatever they were set up on years ago. Check your hosting control panel for the PHP version setting — it may not be what you expect.
If your host can't or won't provide PHP 7.2 or above, that's a significant signal about the quality of the hosting environment overall. It's a reasonable basis for moving.
DownUnder WP runs current PHP versions across all hosted sites. You're not on end-of-life software, and the performance benefit is built in from the start.
Australian WordPress hosting from $5/month
Your own containerised environment on Australian NVMe servers. Simple, fast, and genuinely cheap.