PHP 4.4 End of Life
Support dates, vulnerabilities published since end of life, and upgrade guidance — rebuilt from live data.
PHP 4.4 reached end of life on 7 Aug 2008. It no longer receives security fixes.
Support timeline
Official dates, read directly from php.net.
| Milestone | Date | Status |
|---|---|---|
| Initial release | 11 Jul 2005 | 21y 3mo ago |
| Security Support ended | 7 Aug 2008 | 18y 2mo ago |
| Latest release | 4.4.9 · 7 Aug 2008 | final |
The cost of staying: CVEs since end of life
528 PHP vulnerabilities have been published since 7 Aug 2008. All were fixed in supported branches — 4.4 received none of them. Source: NVD.
PHP CVEs published since 4.4's EOL, by year
125 of the 528 are rated critical · data refreshed 2026-10-05
Published 7 May 2010 · rated critical — fixed in supported branches only, never in 4.4. Details
Published 11 May 2012 · rated critical — fixed in supported branches only, never in 4.4. Details
Published 2 Dec 2015 · rated critical — fixed in supported branches only, never in 4.4. Details
Where to go from 4.4
Recommended target: PHP 8.5 (supported until 31 Dec 2029).
The newest actively supported branch is PHP 8.5 (latest release 8.5.11). Review php.net before upgrading. Run composer why-not php 8.5 to check package compatibility.
Frequently asked questions
Is PHP 4.4 still safe to use?
No. PHP 4.4 stopped receiving security fixes on 7 Aug 2008. Since then, 528 PHP vulnerabilities have been published and fixed in supported branches — PHP 4.4 received none of those fixes.
Can I still download PHP 4.4?
Yes — the final release (4.4.9) generally remains available from vendor archives and OS package mirrors, but installing it means running software with known, unpatched vulnerabilities.
What should I upgrade PHP 4.4 to?
Upgrade to PHP 8.5, the newest actively supported branch (supported until 31 Dec 2029).