Key facts
- PHP 5.6 run per site in Plesk (our servers run every PHP version from 5.6 through 7.0, 7.1, 7.2, 7.3, 7.4 and 8.0 to 8.5)
- PHP 5.6 security support ended on 31 December 2018, so we isolate and firewall every PHP 5 site
- PHP 5.2 to 5.5 aren't available on modern operating systems; those sites are brought up to 5.6 with small code fixes
- Sites that rely on mysql_connect and mysql_query need PHP 5.6 or a rewrite to mysqli or PDO
- Cloudflare proxy, ModSecurity rules and daily backups on every site
- Price: £1 a day + VAT, with free migration
Who still needs PHP 5?
More businesses than you'd think. PHP 5 was the standard from 2004 until PHP 7 arrived at the end of 2015, so a whole generation of websites was built on it. If your site was made in that window and nobody has upgraded the code, it probably needs PHP 5 to run.
The giveaway is usually a database error or a blank page after your host upgraded. Code that connects with mysql_connect() simply can't run on PHP 7 or 8, because those functions no longer exist there. The same goes for sites using ereg() for form checks or split() for text handling.
PHP 5.6 versus PHP 5.2, 5.3 and 5.4
Not all PHP 5 is equal, and it matters for hosting.
- PHP 5.6 is the last PHP 5 release. Plesk still provides it on current server platforms, so we can run it for an individual site.
- PHP 5.2 to 5.5 were built for operating systems and OpenSSL versions that no longer exist in a supported form. No responsible host can run them on a current server.
The good news is that moving a 5.3 or 5.4 site up to 5.6 is usually a small job. The main fixes are:
- Code that relied on register_globals, which was removed in PHP 5.4
- Code that expected magic_quotes, also removed in 5.4
- Call-time pass-by-reference, such as myFunction(&$value)
- Old session functions like session_register()
- Default timezone warnings, fixed with a date.timezone setting
We scope this before we start and tell you the cost up front.
Keeping a PHP 5.6 site as safe as possible
PHP 5.6 has had no official security fixes since 31 December 2018. We won't pretend otherwise. What we can do is shrink the ways an attacker can reach it:
- The site runs under its own system user, with open_basedir limiting it to its own folder.
- Dangerous functions the site doesn't use, such as exec and system, can be disabled in that site's PHP settings.
- Cloudflare hides the origin server and absorbs a lot of junk traffic.
- ModSecurity rules on the server block common injection attacks.
- Upload folders are set so PHP files can't execute from them.
- Daily backups mean a clean copy is always available.
Old shopping carts that take card details on the page are the one case where we'll push hard for an upgrade, because the payment side has to meet current standards.
From PHP 5 to PHP 8, one step at a time
Once the site is stable on PHP 5.6, upgrading becomes a planned project rather than an emergency. The usual route is:
- Replace mysql_* calls with mysqli or PDO, which also lets us add prepared statements to close SQL injection holes.
- Rename old-style constructors and replace ereg() with preg_match().
- Test on PHP 7.4, then on PHP 8.3 or newer.
- Fix the remaining warnings and switch the live site.
This is quoted work. Many small sites need a few days, not weeks. See legacy PHP hosting for the full version-by-version breakdown, or PHP hosting for modern PHP sites.
Getting your PHP 5 site moved
Before you contact us, it helps to know roughly when the site was built and what it runs on, such as Joomla 1.5, an old osCommerce shop or a hand-coded PHP site. Don't worry if you don't know: we can usually tell from the code within minutes. Then send us what you have: hosting login, FTP details or a backup. If you have nothing but the domain, read abandoned website takeover. If the site is already down, go to website rescue. Otherwise order dijitul Complete Hosting or call 01623 650333.
Frequently asked questions
Can I still get PHP 5 hosting in the UK?
Yes. dijitul runs PHP 5.6 for individual sites in Plesk (our servers run every PHP version from 5.6 through 7.0, 7.1, 7.2, 7.3, 7.4 and 8.0 to 8.5), isolated from other sites, behind Cloudflare and backed up daily. It's included in dijitul Complete Hosting at £1 a day + VAT. Sites built for PHP 5.2 to 5.5 usually need small fixes to run on 5.6.
Can you run PHP 5.3 or PHP 5.4?
Not on a current server. PHP 5.2 to 5.5 depend on old system libraries, including old OpenSSL, that aren't available on supported operating systems. Instead, dijitul brings those sites up to PHP 5.6, which usually means fixing register_globals, magic_quotes and a few old session functions. We quote this before starting.
Why does my site say 'Call to undefined function mysql_connect()'?
Your server is running PHP 7.0 or newer, which removed the old mysql_* functions. The site needs either PHP 5.6 or its database code rewritten to use mysqli or PDO. dijitul can host it on PHP 5.6 straight away and quote for the rewrite so it can move to current PHP.
Is PHP 5.6 a security risk?
Yes, to a degree. PHP 5.6 has had no official security fixes since December 2018. The risk is reduced by running the site in isolation, disabling unused functions, using a web application firewall, hiding the server behind Cloudflare and keeping daily backups. Long term, the site should be upgraded.
How long does it take to upgrade a site from PHP 5 to PHP 8?
It depends on the size and quality of the code. A small brochure site with a contact form may take a day or two. A bespoke system with lots of database code takes longer. dijitul audits the code first and gives you a fixed quote, while the site keeps running on PHP 5.6 in the meantime.
Related
Set it up and forget about it
Managed hosting, Plesk, Cloudflare DNS, daily backups and your domain for £1 a day + VAT. We move your site for you.