8,131 plugins still list PHP 5, and WordPress never notices
On 28 August 2026, 8,131 plugins in the WordPress directory named PHP 5 as their minimum, a version that has not had a security fix since the end of 2018. That is not a scandal. It is a signal, though, and you should know how to read it.
The obvious sentence to write about this number is: 8,131 plugins require PHP 5. It is wrong, which is why the census lists it as a common misstatement right next to its key figures on the minimum PHP version. The value is a lower bound. It means: should run from PHP 5.x upwards. It does not mean: needs PHP 5. And it certainly does not mean the plugin fails on PHP 8.
A second look is still worth it. This line is the only hint about PHP you get before installing a plugin, and hardly anyone reads it.
What the number measures, and what it does not
We counted the requires_php field as the public wordpress.org API reported it on 28 August 2026 for all 70,909 listed plugins. Any value starting with “5.” counts as PHP 5, so 5.2 just as much as 5.6. That applies to 8,131 plugins, 11.5% of the directory.
Installs are fuzzier, on purpose. wordpress.org reports active installs with one significant digit: “10,000+” means anywhere from 10,000 to 19,999. Summed honestly, that gives two numbers: all lower bounds (58.0 million) and all upper bounds (82.8 million). And installs are not websites. A site running three such plugins counts three times.
Then there is the larger group: 31,584 plugins (44.5%) state nothing, their field is false, so the directory accepts plugins without this line. For 39,715 plugins, 56.0% of everything listed, the PHP line does not reveal whether anyone has looked at the code with a current PHP in mind.
Why WordPress does not warn you
WordPress reads Requires PHP from the header of the main plugin file and compares it with your server’s PHP. If your server is older, WordPress refuses to activate the plugin; for updates you get a notice that the new version does not work with your PHP, and the “update now” link is missing. Sensible. It is also the only direction anything gets checked.
A value that is too low always slips through. wordpress.org currently recommends PHP 8.3 or greater and names PHP 7.4 as the floor for legacy environments, adding that those older versions have reached their end of life. Anyone on a current WordPress release therefore runs at least PHP 7.4, which satisfies every 5.x value. The check passes, silently, on every site.
There is no field for an upper bound. “Tested up to” on wordpress.org refers to the WordPress version, not PHP. So “5.6 or higher” quietly implies compatibility with everything that came after. Your dashboard’s details window then shows “Requires PHP Version: 5.6 or higher”, which reads like reassurance.
How old that floor is, php.net spells out: PHP 5.6 has had no security support since 31 December 2018, and the list of end-of-life branches now runs up to PHP 8.1.
Self-reported, not tested
Nobody verifies this line, neither the directory nor WordPress. The census says so in its limitations section: self-reported by authors, verified by no one. Still, it is what you have. Before installing you see no code and no test run, only metadata.
Our reading: the PHP line shows when an author last asked “which PHP does this actually run on?” while editing the header. A 5.x value in 2026 means either nobody has touched the line in years, or the author keeps it low on purpose. Both are statements about maintenance. Neither is a statement about security.
Keeping it low can be a fair choice. An author who raises the number cuts sites on older PHP off from future updates, because WordPress stops offering them there. A low number on its own is not negligence, which is also why we name no plugin here.
Security lives in the code and in how quickly holes get fixed. A plugin saying “5.6 or higher” can be perfectly clean, one saying “8.2 or higher” can have an open vulnerability. The line cannot tell them apart.
It gains meaning in combination. In the same dataset, 41,395 plugins (58.4%) had no release for more than a year; for 19,013 (26.8%) the last release came in the year they were added and is over two years old. Only 6,458 (9.1%) were tested against WordPress 7.1, the current core on the reference date. What else the census shows, starting with how many WordPress plugins there are, has its own article.
Where the Cyber Resilience Act comes in
Since 11 September 2026 the reporting obligations in Article 14 of the EU Cyber Resilience Act apply, and the rest of Regulation (EU) 2024/2847 applies from 11 December 2027. Reading a list of PHP 5 plugins as a list of problem cases would be wrong. No vulnerability and no reporting duty follows from the PHP line, and the census draws no conclusion about security or compliance from any of its fields.
The connection is quieter. Since September, a manufacturer has to report actively exploited vulnerabilities and inform affected users. That assumes someone maintains the plugin and reads their mail. A header untouched since PHP 5 does not prove otherwise, but it raises a fair question: is anyone still listening? We have written up what the CRA reporting obligations for plugin vendors require in detail, and the open question of whether a free open source plugin has a manufacturer under the CRA at all.
How to find the value for your plugins
No code, no tool. Start with your own server, because the plugin line only means something by comparison.
- Your PHP version: Tools, Site Health, the Info tab, the Server section, the line PHP version. The Status tab also tells you whether that version meets the wordpress.org recommendation.
- In your dashboard, per plugin: under Plugins, Installed Plugins, every plugin from the directory has a View details link. The window shows a line “Requires PHP Version: … or higher”. If the line is missing, the plugin states nothing. If WordPress does not know a plugin from the directory, the link is missing; if the author set a plugin URI, you see Visit plugin site instead.
- On wordpress.org: every plugin page’s sidebar shows PHP version next to Last updated and Tested up to, three signals at a glance before you install.
- In the file: for premium plugins without a directory listing, open the plugin folder under
wp-content/plugins/via SFTP or your host’s file manager and read the comment header of the main plugin file. You will findRequires PHP:there, often repeated in the header ofreadme.txt. Since WordPress 5.8, only the file header counts for the activation check. - In the census: each of the 466 plugins with 100,000+ installs has a plugin profile showing its PHP floor and the most common value in its size group, as of 28 August 2026.
What to do with what you find
| Finding | What it means | What you do |
|---|---|---|
| PHP 5.x, but a release in recent months and “Tested up to” is current | The header is old, maintenance is ongoing | Nothing. If you like, ask politely in the support forum. |
| PHP 5.x and no release for more than a year | Two signals point the same way | Look for a replacement, try the switch on a staging copy |
| No PHP value at all | No signal, neither good nor bad | Check release date, “Tested up to” and the support forum |
| Value higher than your server’s PHP | WordPress blocks activation and updates | Have your host raise PHP, test on a staging copy first |
| Your server’s PHP is on the php.net end-of-life list | The bigger finding, bigger than any plugin line | Raise the PHP version; it affects every plugin at once |
Which other signals matter is covered in our guide to updating WordPress plugins, in the section on plugins that leave you stranded. And since a poorly maintained plugin can become a risk in its own right, checking the PHP line belongs in the same review as choosing the right WordPress security plugins.
Where we stand ourselves
Our plugins in the directory list PHP 7.4, 8.0 or 8.1 as their minimum, according to the wordpress.org API on 4 October 2026. That is self-reported too, and PHP 7.4 is on the php.net list as well. A minimum is not a recommendation, for us no more than for the other 8,131.
If you maintain a plugin, our advice: set the line to the oldest PHP version you actually test on, and keep header and readme in sync. It is the only hint about PHP a site owner gets before installing. A line that has said PHP 5 for years answers that question for nobody.
Rather have it checked?
With our security check & hardening we look for vulnerabilities in core, theme and plugins, harden the login, verify your backups and give you a written report sorted by urgency. Fixed price from 490 €.
Frequently asked questions
What PHP version does a WordPress plugin need?
The minimum is whatever the Requires PHP line says, in the header of the main plugin file and usually in readme.txt as well. There is no upper limit. You see it under View details in your dashboard and in the sidebar on wordpress.org. On 28 August 2026, 44.5% of listed plugins left it out.
Is a plugin with Requires PHP 5.6 insecure?
Not automatically, because the line is a self-reported lower bound, not a security finding. It does not say the plugin breaks on PHP 8 or contains vulnerabilities. It only becomes meaningful next to the last release date, the tested WordPress version and the support forum.
How do I see which PHP version my WordPress site runs on?
Your server’s PHP version is listed under Tools, Site Health, Info tab, Server section. The Status tab tells you whether it meets the wordpress.org recommendation, which is PHP 8.3 or greater as of 4 October 2026. Usually your host is where you change it.
What happens if my server runs an older PHP than a plugin requires?
WordPress refuses to activate the plugin. If only an update needs the newer PHP, WordPress shows the new version but offers no update link. A value that is too low, on the other hand, never triggers a warning.
Should I delete plugins that list PHP 5 as their minimum?
No, not because of that line alone. A low minimum can be forgotten or deliberate, and neither says anything about the code. Check the last release and the support forum first; only if those show standstill too, look for a replacement and test the switch on a copy of your site.
How many WordPress plugins still list PHP 5?
On 28 August 2026, 8,131 of 70,909 listed plugins (11.5%) gave PHP 5.x as their minimum. Together they carry 58.0 to 82.8 million installs, a range because wordpress.org reports installs in bands. Installs are not websites: a site with several such plugins counts several times.