TERM · SECURITY

End-of-life software (EOL)

What is end-of-life software (EOL)?

End-of-life software is a version whose maker has stopped publishing fixes for it: a PHP release, a database, a content management system or a single plugin that has passed its published end-of-life date. It keeps running, which is the trap, because every flaw found after that date stays open. The dates are announced years ahead, so this belongs in a maintenance calendar rather than in an incident report.

Example

A site built in 2019 runs without complaint and nobody touches it. A look at what it runs on turns up three separate deadlines:

  • PHP 8.1. No security fixes have been published for it since 31 December 2025, and 8.2 reaches the same point at the end of 2026.
  • A gallery plugin. Last updated three years ago and since removed from the official directory. If a flaw is found in it tomorrow, no fix is coming.
  • The theme. Bought once with a year of updates, then edited by hand, so every future update would overwrite those edits.

None of the three breaks anything today. Each of them turns the next published vulnerability into a door that stays open, and sooner or later the host switches the old PHP version off, on its schedule rather than yours.

Why it matters for a business

End of life is the only security risk that arrives with a date on it, which makes it the cheapest to manage and the easiest to forget. Banks, payment providers and larger clients ask whether the software you run is still supported, and insurers ask the same question. Waiting also makes the bill bigger: moving from PHP 8.1 to a current release means crossing several versions at once, with every plugin and every hand-made change checked along the way. Every CMS publishes its own version calendar, and maintenance means working to that calendar.

What to ask

  • Is there an inventory of components with versions and end-of-life dates, and who keeps it current?
  • Which PHP and database versions does the site run on today, and how long are they supported?
  • Is there a copy of the site where an upgrade is tried before it touches the live one?
  • Which plugins have had no update for a year or more, and what replaces them?
  • Have the theme or the core been edited by hand, and is that written down anywhere?

An upgrade on a calendar costs less than an upgrade after a break-in. That calendar is part of the website maintenance we run: versions, dates, and a test on a copy before the change goes live.

A term you do not recognise? Write to us and we will add it.

The glossary grows with the questions we are asked.