PHP 5.0 End of Life
Support dates, vulnerabilities published since end of life, and upgrade guidance — rebuilt from live data.
PHP 5.0 reached end of life on 5 Sept 2005. It no longer receives security fixes.
Support timeline
Official dates from the PHP release process.
| Milestone | Date | Status |
|---|---|---|
| Initial release | 13 Jul 2004 | — |
| End of life | 5 Sept 2005 | 20.9 years ago |
| Latest release | 5.0.5 · 5 Sept 2005 | final |
The cost of staying: CVEs since end of life
696 PHP vulnerabilities have been published since 5 Sept 2005. All were fixed in supported branches — 5.0 received none of them. Source: NVD.
PHP CVEs published since 5.0's EOL, by year
129 of the 696 are rated critical · data refreshed 2026-08-09
Published 10 Mar 2007 · rated critical — fixed in supported branches only, never in 5.0. Details
Published 10 Mar 2007 · rated critical — fixed in supported branches only, never in 5.0. Details
Published 5 May 2008 · rated critical — fixed in supported branches only, never in 5.0. Details
Where to go from 5.0
Recommended target: PHP 8.5 (supported until 31 Dec 2029).
The newest actively supported branch is PHP 8.5 (latest release 8.5.9). Review php.net before upgrading. Run composer why-not php 8.5 to check package compatibility.
Frequently asked questions
Is PHP 5.0 still safe to use?
No. PHP 5.0 stopped receiving security fixes on 5 Sept 2005. Since then, 696 PHP vulnerabilities have been published and fixed in supported branches — PHP 5.0 received none of those fixes.
Can I still download PHP 5.0?
Yes — the final release (5.0.5) generally remains available from vendor archives and OS package mirrors, but installing it means running software with known, unpatched vulnerabilities.
What should I upgrade PHP 5.0 to?
Upgrade to PHP 8.5, the newest actively supported branch (supported until 31 Dec 2029).