PHP 8.2 End of Life Date: December 31, 2026 — What You Need to Know

By Scott Bissett Updated: May 24, 2026 Security only — ends December 31, 2026
Dec 31, 2026
PHP 8.2 official end of life
Counting down to December 31, 2026

PHP 8.2 is currently in security-only support. Active support ended December 8, 2024. You are receiving critical CVE patches only until December 31, 2026 — after which PHP 8.2 receives nothing. If your application depends on PHP 8.2, migration or an extended support contract needs to start now.

Key Dates at a Glance

PHP 8.2 lifecycle dates

Active support
Nov 2022 – Dec 2024
Security only
Dec 2024 – Dec 2026
EOL
Dec 31, 2026 ✕
PhaseDateStatus
Initial releaseNovember 8, 2022Released
Active support endsDecember 8, 2024Passed
Security support ends (EOL)December 31, 2026Upcoming
Running PHP 8.2 past end of life?
Extended support past the official EOL date exists for many products in this position — whether it covers PHP 8.2 is exactly what we check. Tell us where to reach you and we’ll reply with matched options and pricing guidance — or an honest “no vendor covers this.” Free, no obligation.

Free · No obligation · Independent — we track the dates, vendors don’t pay for placement · dates verified against vendor sources. See all support options →

Is PHP 8.2 still supported?

PHP 8.2 is still receiving security patches in 2026 — but only security patches. The PHP project entered security-only maintenance on December 8, 2024. This means:

For most production environments, being on security-only support is acceptable — but the hard deadline of December 31, 2026 means migration work needs to begin in mid-2026 at the latest.

What PHP version should you migrate to?

PHP 8.3 is the primary recommended migration target. Active support runs until December 2026, with security support extending to December 31, 2027. Migration from PHP 8.2 to 8.3 is typically low-friction — no major breaking changes affect most applications.

PHP 8.4, released November 2024, is also a valid target if you want to stay current longer. Active support runs to November 2026, with security support through November 30, 2027.

Avoid migrating to PHP 8.1 — it reached end of life on December 31, 2025 and is already unsupported.

Which vendors offer extended support for PHP 8.2 after EOL?

If migration cannot be completed before December 31, 2026, commercial vendors offer extended CVE patching and compliance coverage:

Third-Party ELS Vendors

Extended Lifecycle Support

Specialist ELS vendors provide continued CVE patching for PHP after official EOL — typically covering PHP 8.2, 8.1, 7.4, and earlier versions. Multi-year contracts available, commonly at a CVSS 7+ threshold.

View via endoflife.ai →

Check your PHP exposure alongside other EOL components

See the full CVE risk profile for PHP 8.2 and every other EOL component in your stack.

PHP 8.2 Risk Score →
What to do about it

PHP currently carries an EOL Risk Score™ of 80/100 — Grade D, high risk, recalculated at every site build from EOL recency, attack surface, CISA KEV exposure, and extended-support availability. Per-version scores and dates are on the PHP lifecycle page.

The right response comes down to one question: how many more years does this system need to run? Under a year, extended support (where it exists) is usually cheaper than an emergency migration. One to three years, migrate — support fees paid repeatedly cost more than doing the project once. Indefinitely, migrate now and plan the next one before it surprises you. Extended support is often the more expensive choice over a multi-year horizon — a bridge, not a destination. And if this deadline feels like vendor caprice, it isn’t — why end of life is inevitable for every version, with the receipts.

Guides: PHP 7: upgrade, or buy extended support?  ·  PHP 7 migration guide

What PHP 8.2 end of life means for Laravel applications

Laravel applications are one of the largest PHP 8.2 populations. Whether the December 31, 2026 deadline forces a framework upgrade or just a PHP bump depends entirely on which Laravel major you run — the framework’s own support windows (verified against laravel.com) are:

Laravel versionSupported PHPFramework security fixesYour move before PHP 8.2 EOL
Laravel 13PHP 8.3 – 8.5Laravel 13: security fixes until 2028-03-17Nothing — Laravel 13 cannot run on PHP 8.2, so you are already clear.
Laravel 12PHP 8.2 – 8.5Laravel 12: security fixes until 2027-02-24Upgrade PHP in place to 8.3, 8.4 or 8.5 — no framework jump needed. This is the cheapest exit anyone gets from PHP 8.2.
Laravel 11PHP 8.2 – 8.4Laravel 11: security fixes ended 2026-03-12The framework is already end of life. On PHP 8.2 you face double exposure after March 12, 2026 — an unpatched framework on an unpatched runtime. Move to Laravel 12 or 13.
Laravel 10 and olderPHP 8.1 – 8.3 (max)Laravel 10: security fixes ended 2025-02-04Same double exposure, longer upgrade path. If the app cannot be upgraded this year, extended support for the PHP runtime is the stopgap while you plan the framework migration.

The practical takeaway: Laravel 12 users on PHP 8.2 have a one-day fix (bump the runtime to PHP 8.3+ — Laravel 12 supports it natively), while Laravel 11-and-older apps pinned to PHP 8.2 carry compounding risk on two layers at once. Check where every one of your apps stands on the Laravel lifecycle page.

Frequently asked questions

When is PHP 8.2 end of life?
PHP 8.2 reaches its official end of life on December 31, 2026. Active support ended December 8, 2024. It is currently in security-only maintenance. After December 31, 2026, no patches of any kind will be released.
Is PHP 8.2 still supported in 2026?
Yes — PHP 8.2 receives security patches only through December 31, 2026. Only high and critical CVEs are patched. After that date, all support ends permanently.
What is the PHP 8.2 end of life date?
December 31, 2026 is the PHP 8.2 EOL date — the last day any patch will be released. This is the date after which running PHP 8.2 means running permanently unpatched software.
What PHP version should I upgrade to from PHP 8.2?
PHP 8.3 is the recommended target — security support runs until December 31, 2027. PHP 8.4 is also a valid option. Both offer minimal breaking changes from PHP 8.2. Avoid PHP 8.1, which is already end of life.
Which vendors offer extended support for PHP 8.2 after EOL?
Commercial vendors offer extended lifecycle support for PHP 8.2 past December 31, 2026. Each provides ongoing CVE patching and compliance documentation for organizations that cannot migrate immediately.
What happens if I keep running PHP 8.2 after end of life?
After December 31, 2026, any vulnerability discovered in PHP 8.2 will never be patched. This creates permanent, accumulating exploit paths in your production environment. For regulated environments (PCI DSS, HIPAA, SOC 2), running EOL PHP creates immediate compliance gaps.
Can Laravel applications stay on PHP 8.2?
Only until December 31, 2026. Laravel 12 supports PHP 8.3–8.5, so Laravel 12 apps can upgrade the PHP runtime in place with no framework change. Laravel 11 and older are already past their own end of life — running them on PHP 8.2 after its EOL means both the framework and the runtime are unpatched. Laravel 13 requires PHP 8.3 or newer and is unaffected.

The Monthly EOL Digest™

Once a month — critical EOL dates, CVE blind spots, and lifecycle changes worth knowing about.