Skip to content

Exposure and discovery

End-of-life software checker

See whether a site's home page advertises a version of PHP, Apache httpd, IIS, nginx or OpenSSL that no longer receives security fixes. A match is reported as a potential finding: an advertised version is a lead to check on the server, not proof.

Checked from Ironfang Security's scanner address with the same low-impact limits as a scan. Nothing you enter is kept.

What this checks

What the result means

Software past its end of life gets no fixes for vulnerabilities found after that date. A server running it stays exposed to each new one, and an advertised version tells anyone scanning the internet which ones to try.

A pass means no advertised version matched the list. Often that is because the site advertises no versions at all, which is good practice, but it says nothing about software that stays quiet. Only the five products listed are judged; other software is shown by the technology detector but not compared with any end-of-life date.

A finding is always marked potential. The version was inferred from what the server sends, and vendors and Linux distributions often backport security fixes without changing it. Someone who knows the server should confirm the installed version and its support status before acting.

How to fix common issues

Potentially end-of-life software

Confirm the installed version on the server. If it is genuinely end-of-life, upgrade to a supported release.

More in the End-of-life software check reference

Cyber Essentials and ISO 27001

An end-of-life version on an internet-facing server bears on the security update management theme of Cyber Essentials and on ISO/IEC 27001:2022 Annex A 8.8 Management of technical vulnerabilities. This check is technical evidence for a small part of either: what one public page advertises.

The organisation still has to know what it runs from the inside, assign who tracks support dates for each product, and decide how unsupported software is upgraded, replaced or removed. A pass here does not show that any of that is in place.

Scope and limitations

Related guides

Questions

Why is an end-of-life finding only potential?
Because the version was read from what the server advertises, not from the software itself. Vendors and Linux distributions often backport security fixes to an old version number, so confirm what is installed and whether it is still supported before acting.
Which PHP versions are end of life?
As of October 2026, PHP releases before 8.2 no longer receive security fixes from the PHP project. Some Linux distributions support older versions for longer in their own packages.
Is hiding the version number enough?
No. It removes an easy clue for attackers, but the software is just as unsupported. Upgrade to a supported release, then stop advertising versions.

Related security tools