All posts
April 2019·5 min read

Why your WordPress host's PHP version matters more than you think

PHP 5.6 went end-of-life in December 2018. PHP 7.x is two to three times faster for typical WordPress workloads and receives active security updates. Many hosts still run outdated versions. Here's what you need to know.

PHP versions and WordPress

WordPress is written in PHP. When a visitor loads a page on your site, the PHP interpreter on your server executes WordPress's code to generate the HTML response. The version of PHP your hosting provider runs has a direct impact on how fast this happens — and on whether your site is running on software that receives security patches.

The PHP 7 performance difference

PHP 7.0 was released in December 2015 and delivered performance improvements over PHP 5.x that were, for PHP, extraordinary. Independent benchmarks consistently showed PHP 7.0 executing WordPress workloads roughly twice as fast as PHP 5.6. PHP 7.1, 7.2, and 7.3 continued to improve on that.

The improvement comes from fundamental changes to PHP's internal engine, including a new abstract syntax tree representation and improved memory efficiency. These aren't configuration tweaks — they're architectural changes that benefit every PHP application, including WordPress and all its plugins.

In practical terms: a WordPress site on PHP 7.x will generate pages significantly faster than the same site on PHP 5.6, with the same hardware and configuration. The speed gain from upgrading PHP often exceeds what you'd get from optimising your theme or plugin setup.

The security problem with old PHP

PHP 5.6 reached official end of life on 31 December 2018. End of life means no more security patches from the PHP project. Vulnerabilities discovered in PHP 5.6 after that date will not be fixed.

PHP 7.0 reached end of life in December 2018 as well. PHP 7.1 in December 2019. At the time of writing, PHP 7.2 and above remain supported. Running anything below 7.2 means running software with known, unpatched security vulnerabilities.

The risk isn't hypothetical. PHP vulnerabilities can be exploited to execute code on your server regardless of how well your WordPress configuration is secured. A vulnerability in the PHP interpreter itself is underneath all the WordPress-level security you've applied.

Why hosts lag on PHP versions

Upgrading PHP across a shared hosting environment is disruptive. Some customers' older PHP code doesn't work on newer versions. Hosts face support tickets and complaints when they update PHP. The easiest path is to leave old versions available indefinitely, even after they're end-of-life.

Some hosts default new accounts to a current PHP version but leave existing accounts on whatever they were set up on years ago. Check your hosting control panel for the PHP version setting — it may not be what you expect.

What to check and do

  • Check your PHP version in your hosting control panel, or via a plugin like Health Check & Troubleshooting
  • If you're on anything below PHP 7.2, request an upgrade from your host
  • Before upgrading, check your theme and major plugins for PHP 7.x compatibility notices — most current, maintained plugins are fine; older abandoned plugins may not be
  • Test on a staging site or backup first if you have a complex plugin setup

If your host can't or won't provide PHP 7.2 or above, that's a significant signal about the quality of the hosting environment overall. It's a reasonable basis for moving.


DownUnder WP runs current PHP versions across all hosted sites. You're not on end-of-life software, and the performance benefit is built in from the start.

Australian WordPress hosting from $5/month

Your own containerised environment on Australian NVMe servers. Simple, fast, and genuinely cheap.