WordPress Stores on PHP 8.2 Face Holiday Security Deadline, SSL Dragon Warns

Without upgrades, 61% of WordPress sites will run unsupported PHP on January 1, 2027, up from 36%. SSL Dragon offers CodeGuard, SiteLock and TrustedSite.

Putting the upgrade off until after the holidays is how stores end up on unsupported software for years. A backup you’ve tested makes the upgrade a small enough risk to take before December 31.”

— Roman Munteanu, SSL Dragon

SAN JOSE, CA, UNITED STATES, October 8, 2026 /EINPresswire.com/ — Adobe expects US online holiday sales to reach $275.1 billion between November 1 and December 31, 2026. December 31 is also the last day the PHP project supports PHP 8.2, a version of the programming language WordPress is written in. SSL Dragon, a San Jose-based provider of SSL certificates and digital security solutions, warns that WordPress stores on PHP 8.2 must choose between upgrading during the holiday rush and running unsupported software into 2027.

On October 6, 2026, WordPress.org’s statistics page showed 36% of WordPress sites on PHP versions that had already lost support, and another 25% on PHP 8.2. Unless those sites upgrade, 61% will run unsupported PHP on January 1, 2027.

Unsupported means the PHP project stops fixing newly found flaws. Those have not been rare: between March 2025 and September 2026, it issued seven security releases for PHP 8.2, fixing 34 of them. Old versions also linger: PHP 7.4 lost support on November 28, 2022, and the same page showed it on 17% of WordPress sites.

Upgrading is the fix, but it carries its own risk. WordPress’s guidance on updating PHP says the change “should not be a problem, but we can’t guarantee that it’s not.” It advises making a backup and testing themes and plugins first.

CodeGuard, available through SSL Dragon, provides that backup: a daily copy of a site’s files and database that it restores in one step. If an upgrade breaks something, the owner can switch PHP back, restore the copy and get back to selling.

For stores whose plugins aren’t ready, SiteLock scans for malware daily and can remove it automatically, which shortens how long an infection goes unnoticed until they upgrade. TrustedSite shows shoppers a certification only while its weekly scans come back clean. That matters at checkout. In Baymard Institute’s 2026 survey of US online shoppers, 19% said they had abandoned a purchase in the previous three months because they didn’t trust the site with their credit card information.

“Putting the upgrade off until after the holidays is how stores end up on unsupported software for years,” said Roman Munteanu, CEO and Founder of SSL Dragon. “A backup you’ve tested makes the upgrade a small enough risk to take before December 31.”

SSL Dragon advises store owners to check their PHP version and ask their host whether it will keep patching 8.2 after December 31. They should test the new version and a restore on a staging copy. The live switch, to PHP 8.3 or later as WordPress recommends, should follow a fresh backup and come before December 31 but outside Cyber Week, November 26 to 30.

About SSL Dragon:

SSL Dragon is a US-headquartered web security provider dedicated to making digital trust accessible. As a platinum partner of Sectigo and DigiCert, SSL Dragon serves over 13,000 clients globally, providing streamlined SSL management, malware protection, and enterprise PKI solutions. For more information, visit www.ssldragon.com.

Roman Munteanu
SSL Dragon
roman@ssldragon.com
Visit us on social media:
LinkedIn

Legal Disclaimer:

EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Media gallery