PHP 5.5 End of Life
Support dates, vulnerabilities published since end of life, and upgrade guidance — rebuilt from live data.
PHP 5.5 reached end of life on 21 Jul 2016. It no longer receives security fixes.
Support timeline
Official dates from the PHP release process.
| Milestone | Date | Status |
|---|---|---|
| Initial release | 20 Jun 2013 | — |
| End of life | 21 Jul 2016 | 10.1 years ago |
| Active support ended | 10 Jul 2015 | security fixes only after this |
| Latest release | 5.5.38 · 21 Jul 2016 | final |
The cost of staying: CVEs since end of life
240 PHP vulnerabilities have been published since 21 Jul 2016. All were fixed in supported branches — 5.5 received none of them. Source: NVD.
PHP CVEs published since 5.5's EOL, by year
82 of the 240 are rated critical · data refreshed 2026-08-09
Published 25 Jul 2016 · rated critical — fixed in supported branches only, never in 5.5. Details
Published 25 Jul 2016 · rated critical — fixed in supported branches only, never in 5.5. Details
Published 25 Jul 2016 · rated critical — fixed in supported branches only, never in 5.5. Details
Where to go from 5.5
Recommended target: PHP 8.5 (supported until 31 Dec 2029).
The newest actively supported branch is PHP 8.5 (latest release 8.5.9). Review php.net before upgrading. Run composer why-not php 8.5 to check package compatibility.
Frequently asked questions
Is PHP 5.5 still safe to use?
No. PHP 5.5 stopped receiving security fixes on 21 Jul 2016. Since then, 240 PHP vulnerabilities have been published and fixed in supported branches — PHP 5.5 received none of those fixes.
Can I still download PHP 5.5?
Yes — the final release (5.5.38) generally remains available from vendor archives and OS package mirrors, but installing it means running software with known, unpatched vulnerabilities.
What should I upgrade PHP 5.5 to?
Upgrade to PHP 8.5, the newest actively supported branch (supported until 31 Dec 2029).