This post contains affiliate links. If you buy something through one of them, Veravix may earn a commission at no extra cost to you.
A plugin update refuses to install and says it needs a newer PHP version than the one you are running. Or a Site Health notice tells you your site is on an outdated version. Either way the next question is the same: which PHP version is this site actually running right now? The answer takes under a minute to find, and it matters more this year than most, because one very common version stops getting security fixes at the end of 2026.
This guide shows the four places that reveal the number, explains why they sometimes disagree, and then covers what the number means and how to change it without taking the site down.
Where WordPress shows your PHP version
The fastest place is inside WordPress itself. Log in to the dashboard and go to Tools, then Site Health. Open the Info tab, expand the Server section, and look for the line labelled PHP version. WordPress’s own upgrade guide points to exactly this screen. The Status tab next to it also raises a warning on its own when your version is old enough to worry about, so a clean Status tab is a useful second signal.
Site Health reports the version the web server uses to serve your pages, which is the one that matters for your visitors and your plugins. The other methods below are worth knowing for when you cannot log in, or when you suspect a mismatch.
The other ways to find it
Your hosting control panel
Every mainstream host shows the PHP version per site, and it is also where you change it. On Hostinger, open Websites, then Dashboard, then PHP Configuration. On SiteGround it is Site Tools, then Devs, then PHP Manager. If WordPress is locked out by a fatal error, the panel is the method that still works.
A temporary phpinfo file
Create a file called phpinfo.php in your site’s root folder containing a single line, <?php phpinfo();, and open it in the browser. The first heading on the page is the PHP version. Delete the file as soon as you have read it. The page prints server paths and configuration details that you do not want sitting on a public URL, so treat this as a one-minute check and not something to leave behind.
WP-CLI from the command line
If you have shell access, run wp --info. The output lists the PHP binary and its version. This one comes with a catch: the command line can use a different PHP binary from the one your website uses. On some hosts the shell defaults to an older or newer version than the web server. If WP-CLI and Site Health give you different numbers, trust Site Health for what your visitors get, and treat the difference as a setting to fix in the hosting panel.
What the number means in 2026
PHP’s own supported-versions table shows four branches with security support right now:
| PHP version | Active support ended or ends | Security fixes end |
|---|---|---|
| 8.2 | 31 Dec 2024 | 31 Dec 2026 |
| 8.3 | 31 Dec 2025 | 31 Dec 2027 |
| 8.4 | 31 Dec 2026 | 31 Dec 2028 |
| 8.5 | 31 Dec 2027 | 31 Dec 2029 |
Anything older, including 8.1, 8.0 and the 7.x line, is end of life and no longer receives fixes of any kind. WordPress’s requirements page now recommends PHP 8.3 or greater, and describes 7.4 as the oldest version it will still run on while warning that the old versions are exposed to known vulnerabilities.
The practical reading: if you see 8.3, 8.4 or 8.5, you are fine and the only job is to remember the dates above. If you see 8.2, the site is safe today but the clock runs out on 31 December 2026, so schedule the upgrade now while nothing is forcing it. If you see 8.1 or lower, you are running software that is no longer patched and the upgrade is overdue.
Upgrading without breaking the site
The risk in a PHP upgrade is never WordPress itself. It is an old plugin or theme that uses a feature the newer version removed. The order below keeps that risk small.
- Back up first. A host-level backup or a backup plugin both work. You want a restore point you can reach even if the dashboard stops loading.
- Update WordPress, your theme and every plugin. Developers fix PHP compatibility in new releases, so most problems disappear before you touch the version.
- Run a compatibility check. WordPress’s guide recommends the PHP Compatibility Checker plugin, which scans your themes and plugins and lists the ones that would break on the target version. Anything flagged either needs an update or a replacement.
- Change the version in your hosting panel. On Hostinger, which this site runs on, open Websites, then Dashboard, then PHP Configuration, choose the version and click Update. The change takes effect within a couple of minutes. Hostinger no longer lists versions below 8.2 as selectable, so the dropdown only shows options that still receive security fixes.
- Test straight away. Load the homepage, a post, the login page, and any checkout or form you rely on. Then open Site Health again and confirm the new version is reported.
Jump to the newest branch only if the compatibility check came back clean. Moving to 8.3 is the safer middle ground for most sites: it is the version WordPress recommends, and it has security support until the end of 2027.
If the site breaks after the change
The usual symptom is a white screen or the message that there has been a critical error on the website. Do not start deleting plugins. Go back to the hosting panel and select the previous PHP version again. The site returns to how it was within minutes, and you can then identify the plugin or theme that caused the error from the compatibility check or your server’s error log before trying again.
Site Health helps here too, because it also reports whether the REST API is reachable. If that check turns red after a change, the guide on WordPress REST API disabled: broken vs. blocked on purpose explains how to tell a real fault from a deliberate block.
Make it a calendar item
PHP versions follow a predictable yearly cycle, so this does not need to be a surprise. Look up your version once a quarter, and check it again whenever a plugin update mentions a new minimum. With 8.2 reaching the end of its security support on 31 December 2026, the next sensible moment to move off it is before that date, not after it.

Etienne Basson works with website systems, SEO-driven site architecture, and technical implementation. He writes practical guides on building, structuring, and optimizing websites for long-term growth.