PHP Releases Explained: Release Cycle, Version History and What’s Next
How PHP releases work: the yearly release cycle, how long each version is supported, every release since PHP 7.0, and when PHP 8.6 arrives.
7 min read
The short version
- A new PHP version ships every year in late November. The next one, PHP 8.6, is due on 19 November 2026.
- Each version gets four years of support: two years of bug and security fixes, then two of security fixes only.
- Patch releases (8.5.10, 8.5.11…) come out about every four weeks. Install them: they carry the security fixes.
- Four versions are supported today: PHP 8.2, 8.3, 8.4 and 8.5. PHP 8.2 drops off on 31 December 2026.
How the PHP release cycle works
PHP has followed a yearly release process for over a decade, and every release since PHP 7.1 has landed in late November or early December. Each year follows the same pattern:
| When | Stage | What it means for you |
|---|---|---|
| Spring | Release managers elected | Nothing to do yet. |
| July | Alpha releases | New features still landing. Interesting, not useful. |
| August | Feature freeze, then betas | The feature list is now fixed. Read the upgrade notes. |
| September to November | Release candidates every two weeks | Start running your test suite against it. |
| Late November | General availability (GA) | Stable release. Wait for your dependencies before production. |
| Following months | x.y.1, x.y.2… | Early bugs shaken out. A sensible time to upgrade production. |
The version number tells you what to expect. A minor release such as 8.5 to 8.6 adds features and deprecations but keeps breaking changes to a minimum. A major release such as 7.4 to 8.0 is where deprecated behaviour finally becomes an error, which is why PHP 7.4 upgrades take far more work than moving between 8.x versions. A patch release such as 8.5.10 to 8.5.11 is bug and security fixes only.
How long each release is supported
Under the policy the PHP project adopted in 2024, every release gets:
- Two years of active support, with regular bug fixes and security fixes.
- Two years of security support, with fixes for security issues only.
Both phases end on 31 December, which makes planning simple: a version released in November 2025 is supported until the end of 2029. Older versions had three-year windows that ended on their release anniversary, which is why dates before PHP 8.1 look irregular.
PHP release history
Every PHP release since 7.0, newest first, with its status today:
| Version | Released | Security fixes until | Status |
|---|---|---|---|
| PHP 8.6 | Due 19 Nov 2026 | 31 Dec 2030 | Release candidate |
| PHP 8.5 | 20 Nov 2025 | 31 Dec 2029 | Active support |
| PHP 8.4 | 21 Nov 2024 | 31 Dec 2028 | Active support |
| PHP 8.3 | 23 Nov 2023 | 31 Dec 2027 | Security fixes only |
| PHP 8.2 | 8 Dec 2022 | 31 Dec 2026 | Security fixes only |
| PHP 8.1 | 25 Nov 2021 | 31 Dec 2025 | End of life |
| PHP 8.0 | 26 Nov 2020 | 26 Nov 2023 | End of life |
| PHP 7.4 | 28 Nov 2019 | 28 Nov 2022 | End of life |
| PHP 7.3 | 6 Dec 2018 | 6 Dec 2021 | End of life |
| PHP 7.2 | 30 Nov 2017 | 30 Nov 2020 | End of life |
| PHP 7.1 | 1 Dec 2016 | 1 Dec 2019 | End of life |
| PHP 7.0 | 3 Dec 2015 | 10 Jan 2019 | End of life |
Source: php.net releases and supported versions. For PHP 5.6 and every end-of-life date, see our PHP end-of-life dates page.
What the recent releases brought
The headline changes in each release, and the things most likely to need attention when you upgrade:
PHP 8.6 (due November 2026)
- New: partial function application (
str_replace(' ', '-', ?)creates a callable with one argument left open), aclamp()function, aTime\Durationclass, aSortDirectionenum and default values for readonly properties. - Watch out for: safer session defaults. Strict mode, HttpOnly and
SameSite=Laxsession cookies are now on by default, which can break flows that rely on the session cookie during a cross-site POST, such as some payment gateway callbacks. Also deprecated:returninsidefinally, the mbstring regex functions (mb_ereg*) and old aliases such asis_integer()andis_double().
PHP 8.5 (November 2025)
- New: the pipe operator (
|>),array_first()andarray_last(), the#[\NoDiscard]attribute, a standards-compliant URI extension and “clone with” for modifying properties while cloning. - Watch out for: deprecation of the backtick operator and non-standard casts such as
(integer)and(boolean).
PHP 8.4 (November 2024)
- New: property hooks, asymmetric visibility (
public private(set)),newwithout extra brackets, and an HTML5-compliant DOM parser. - Watch out for: implicitly nullable parameters are deprecated, and the IMAP, OCI8, PDO_OCI and Pspell extensions moved out of core.
PHP 8.3 (November 2023)
- New: typed class constants,
json_validate()and the#[\Override]attribute. - Watch out for: very little. One of the easiest upgrades in years.
PHP 8.2 (December 2022)
- New: readonly classes, standalone
true,falseandnulltypes, and the Random extension. - Watch out for: dynamic properties are deprecated. Older code is full of them, and they will become an error in PHP 9. PHP 8.2 itself reaches end of life on 31 December 2026: see PHP 8.2 end of life.
Don’t ignore patch releases
Most security fixes reach you through patch releases, not new versions. If you upgraded to PHP 8.5 a year ago and haven’t updated since, you are running a version with known, published vulnerabilities, even though 8.5 itself is fully supported.
On your own servers, make patch updates routine:
# Debian/Ubuntu with the ondrej/php packages
sudo apt update && sudo apt install --only-upgrade 'php8.5-*'
sudo systemctl reload php8.5-fpm
# Docker: pin the minor version, let the patch float, rebuild regularly
FROM php:8.5-fpm On shared or managed hosting, the host usually applies patch releases for you. It’s worth checking that they do, and how quickly.
Planning around the release calendar
Because the calendar is predictable, upgrades don’t have to be emergencies. A sensible rhythm for a business or agency:
- Every month: apply patch releases.
- Every autumn: run your tests against the new release candidate and look at the upgrade notes, so nothing comes as a surprise.
- Every year or two: move to a newer minor version, well before your current one reaches end of life. Moving one or two minor versions at a time is far cheaper than the big jumps from PHP 5.6 or 7.4 that we are often asked to rescue.
Adding the next PHP version to your CI as an allowed failure costs nothing and tells you early what will break:
# .github/workflows/tests.yml: test the next release early,
# without letting it fail your build
strategy:
matrix:
php: ['8.5']
experimental: [false]
include:
- php: '8.6'
experimental: true
continue-on-error: ${{ matrix.experimental }} Wondering which version you should be on right now? See what the latest PHP version is and whether to use it.
Frequently asked questions
How often is a new version of PHP released?
Once a year. A new minor version (8.4, 8.5, 8.6 and so on) ships in late November, occasionally slipping into early December. Patch releases with bug and security fixes come out roughly every four weeks for each supported version.
When is the next PHP release?
PHP 8.6 is scheduled for general availability on 19 November 2026. Release candidates are coming out every two weeks until then. Patch releases for PHP 8.2 to 8.5 continue on their usual four-weekly cycle.
When will PHP 9 be released?
No release date has been set for PHP 9. Several changes have already been agreed for it, such as turning some long-standing warnings into errors, but the next scheduled release is PHP 8.6 in November 2026.
Should I upgrade as soon as a new PHP version comes out?
Not for production. Wait until your framework, CMS and key Composer packages officially support it, and ideally for the first one or two patch releases. Do start testing against the release candidates, though, so you know what will break before you need to move.
How we can help
- White-label upgrades for agencies Overflow capacity for agencies: we upgrade your client estate under your name, in your repos, under NDA.
- PHP 7.4 upgrade Still on PHP 7.4? Get to PHP 8.5 in tested, reviewable steps, past the PHP 8.0 and 8.1 changes that break most sites.
- Laravel upgrades Laravel 5 to 8 apps stepped through each major version to a supported release on PHP 8.5.
- Symfony upgrades Deprecation-driven upgrades from Symfony 3, 4 and 5 to a supported LTS on PHP 8.5.