PHP 4.2 End of Life
Support dates, vulnerabilities published since end of life, and upgrade guidance — rebuilt from live data.
PHP 4.2 reached end of life on 6 Sept 2002. It no longer receives security fixes.
Support timeline
Official dates, read directly from php.net.
| Milestone | Date | Status |
|---|---|---|
| Initial release | 22 Apr 2002 | 24y 5mo ago |
| Security Support ended | 6 Sept 2002 | 24y 1mo ago |
| Latest release | 4.2.3 · 6 Sept 2002 | final |
The cost of staying: CVEs since end of life
731 PHP vulnerabilities have been published since 6 Sept 2002. All were fixed in supported branches — 4.2 received none of them. Source: NVD.
PHP CVEs published since 4.2's EOL, by year
129 of the 731 are rated critical · data refreshed 2026-10-05
Published 10 Mar 2007 · rated critical — fixed in supported branches only, never in 4.2. Details
Published 10 Mar 2007 · rated critical — fixed in supported branches only, never in 4.2. Details
Published 5 May 2008 · rated critical — fixed in supported branches only, never in 4.2. Details
Where to go from 4.2
Recommended target: PHP 8.5 (supported until 31 Dec 2029).
The newest actively supported branch is PHP 8.5 (latest release 8.5.11). Review php.net before upgrading. Run composer why-not php 8.5 to check package compatibility.
Frequently asked questions
Is PHP 4.2 still safe to use?
No. PHP 4.2 stopped receiving security fixes on 6 Sept 2002. Since then, 731 PHP vulnerabilities have been published and fixed in supported branches — PHP 4.2 received none of those fixes.
Can I still download PHP 4.2?
Yes — the final release (4.2.3) generally remains available from vendor archives and OS package mirrors, but installing it means running software with known, unpatched vulnerabilities.
What should I upgrade PHP 4.2 to?
Upgrade to PHP 8.5, the newest actively supported branch (supported until 31 Dec 2029).