---
title: "#225 – Milan Petrović on the Risks of Legacy PHP in WordPress and Why Upgrading Matters for Security"
url: https://daily.dev/posts/225-milan-petrovi-on-the-risks-of-legacy-php-in-wordpress-and-why-upgrading-matters-for-security-yezyjzpvs
source_url: https://wptavern.com/podcast/225-milan-petrovic-on-the-risks-of-legacy-php-in-wordpress-and-why-upgrading-matters-for-security
type: article
source: "WP Tavern"
published: 2026-07-15T14:02:36.904Z
updated: 2026-07-16T08:21:51.816Z
tags: ["security", "php", "wordpress"]
reading_time: 34
upvotes: 1
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# #225 – Milan Petrović on the Risks of Legacy PHP in WordPress and Why Upgrading Matters for Security

**[WP Tavern](https://daily.dev/sources/wptavern)** · 34 min read · 1 upvotes · 0 comments

## Summary

Milan Petrović, a WordPress developer with nearly 20 years of experience, discusses the security and performance risks of running outdated PHP versions in WordPress. He highlights that PHP 7 and PHP 5 have 3,000–4,000 open, unfixed bugs — many security-related — making sites running these versions vulnerable to automated exploitation. PHP 8.x not only closes these security holes but also delivers over 50% performance improvement and significant memory reduction compared to PHP 7.4. Milan advocates for WordPress to declare PHP 8.0 as the minimum supported version to push the ecosystem forward, while acknowledging the challenge of millions of sites still on legacy versions. He also introduces his open-source Vulnerability Lab plugin, which lets developers compare how exploits behave across PHP versions, serving as a practical tool for agencies to demonstrate risks to clients.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://wptavern.com/podcast/225-milan-petrovic-on-the-risks-of-legacy-php-in-wordpress-and-why-upgrading-matters-for-security>

## Similar posts on daily.dev

- [PHP support clarification, spring 2026 edition](https://daily.dev/posts/php-support-clarification-spring-2026-edition-vydiinxqh) · Make WordPress Core · 5 upvotes · 1 comments

---

Tags: [#security](https://daily.dev/tags/security), [#php](https://daily.dev/tags/php), [#wordpress](https://daily.dev/tags/wordpress)

[View this post on daily.dev](https://daily.dev/posts/225-milan-petrovi-on-the-risks-of-legacy-php-in-wordpress-and-why-upgrading-matters-for-security-yezyjzpvs)
