Product overview
PHP is tracked by BlackTree as a programming language implementation or runtime. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.
Main capabilities
- Application and script execution
- Standard language tooling and libraries
- Versioned compatibility and security maintenance
Typical use
Used to develop and execute software, automation and data-processing workloads.
Deployment
Installed as a runtime, development toolchain, application dependency or managed platform component.
This category-level context is generated from the registered product identity. Confirm exact product capabilities on the publisher's page ↗.
Collected lifecycle data
| Product | PHP |
|---|
| Release | Lifecycle policy |
|---|
| Start or release | Not extracted |
|---|
| Lifecycle boundary | Continuous or not dated in the source |
|---|
| Date precision | Unknown |
|---|
Known exploited vulnerabilities
Catalogue updated 1 Oct 2026These are product-family matches in the CISA Known Exploited Vulnerabilities catalogue. Confirm the affected product version in the vendor advisory.
No CISA known-exploited entries currently match this mapped product family.
This does not mean the product has no vulnerabilities.
Package vulnerability advisories
Checked 1 Oct 2026OSV advisories are matched through the registered package URL. A package-family match does not prove that the installed release is affected. Check the affected and fixed versions before remediation.
No package advisories have been linked for this product identity.
This is not evidence that the product has no vulnerabilities.
Source evidence
PRIMARYManual
PHP official lifecycle source
Supported Versions | Each release branch of PHP is fully supported for two years from its initial stable release. During this period, bugs and security issues that have been reported are fixed and are released in regular point releases. | After this two year period of active support, each branch is then supported for two additional years for critical security issues only. Releases during this period are made on an as-needed basis: there may be multiple point releases, or none, depending on the number of reports. | Once the four years of support are completed, the branch reaches its end of life and is no longer supported. A table of end of life branches is available. | Currently Supported Versions | Or, visualised as a calendar: | Key
Publisher identity used by product-specific official-source collectors.
First collected 12 Sep 2026 · Last collected 24 Sep 2026 · Review state accepted
Open official vendor source ↗