S

SSL Dragon warns 61% of WordPress stores face unsupported PHP after holiday deadline

–

With Adobe forecasting a record $275.1 billion in US online holiday sales this year, the last thing any e-commerce store needs is a security vulnerability lurking in its foundation. Yet for tens of thousands of WordPress-based shops, that is exactly the risk that arrives on December 31, 2026 — the very same day the PHP project officially stops supporting PHP 8.2.

SSL Dragon, a San Jose-based provider of SSL certificates and digital security tools, is sounding the alarm: WordPress stores still running PHP 8.2 face a hard choice between upgrading during the busiest shopping weeks of the year or continuing into 2027 on software that will no longer receive security patches. According to data from WordPress.org’s statistics page, captured on October 6, 2026, 36% of WordPress sites were already running PHP versions that had lost support, and an additional 25% were still on PHP 8.2. If those sites do not upgrade, a total of 61% will be running unsupported PHP by January 1, 2027.

When a PHP version becomes unsupported, the PHP project stops fixing newly discovered flaws — and those have been anything but rare. Between March 2025 and September 2026 alone, seven security releases were issued for PHP 8.2, addressing 34 vulnerabilities. Meanwhile, older versions linger stubbornly: PHP 7.4, which lost support on November 28, 2022, still appeared on 17% of WordPress sites as of early October.

Upgrading is the obvious remedy, but it carries its own set of risks. WordPress’s own guidance on updating PHP acknowledges that while the change “should not be a problem,” it cannot guarantee that it is not. The platform recommends making a full backup and testing all themes and plugins before making the switch.

SSL Dragon offers CodeGuard, a backup service that creates daily copies of a site’s files and database and can restore them in a single step. If an upgrade breaks something, the store owner can revert the PHP version, restore the backup, and resume selling with minimal downtime.

For stores whose plugins are not yet compatible with newer PHP versions, SiteLock provides daily malware scanning and automatic removal, reducing the window in which an infection could go unnoticed. TrustedSite displays a certification badge to shoppers only while its weekly scans return clean results — a feature that matters at checkout. According to Baymard Institute’s 2026 survey of US online shoppers, 19% said they had abandoned a purchase in the previous three months because they did not trust the site with their credit card information.

“Putting the upgrade off until after the holidays is how stores end up on unsupported software for years,” said Roman Munteanu, CEO and Founder of SSL Dragon. “A backup you’ve tested makes the upgrade a small enough risk to take before December 31.”

SSL Dragon advises store owners to check their current PHP version and ask their hosting provider whether it will continue patching PHP 8.2 after the deadline. They recommend testing the new PHP version and a restore process on a staging copy of the site. The live switch — to PHP 8.3 or later, as WordPress recommends — should follow a fresh backup and occur before December 31 but outside Cyber Week, which runs from November 26 to 30.

Why it matters: This is not a hypothetical future problem — the countdown is real, and the consequences of inaction include unpatched vulnerabilities, eroded customer trust, and abandoned carts. For any WordPress-based e-commerce business, the decision to upgrade before the holiday rush could mean the difference between a secure, profitable season and a costly security incident that lingers well into the new year.


David Hall

David Hall

David is the senior editor at TheCyberMag. He has a background in journalism and has worked with various media outlets, covering topics ranging from threat intelligence and data privacy to cybercrime and cloud security. When he is not writing, David enjoys reading, hiking, photography, and exploring new coffee shops.