WordPress (wp) End of Life
The WordPress Project
| Version | Released | Security updates (backported as a courtesy) | Status |
|---|---|---|---|
| 7.x | 20 May 2026 | Not announced | Not Announced |
| 6.x | 24 May 2022 | Not announced | Not Announced |
| 5.x | 6 Dec 2018 | Not announced | Not Announced |
| 4.7〜4.9 | 6 Dec 2016 | Not announced | Not Announced |
| 4.1〜4.6 | 18 Dec 2014 | Jul 2025 | End of Life ~416 days ago |
| 3.7〜4.0 | 24 Oct 2013 | 1 Dec 2022 | End of Life 1,359 days ago |
Dates are published to month precision upstream, so day counts are approximate
Support policy
WordPress does not publish end-of-life dates for individual versions. Officially only the most recent release is supported; the Security Team backports security fixes to older branches "as a courtesy" and ships them through automatic background updates. Support for a group of old branches ends by announcement rather than on a fixed schedule — this has happened twice, for 3.7-4.0 in December 2022 and for 4.1-4.6 in July 2025.
Notes
WordPress publishes no end-of-life dates for individual versions. This is not missing information — the project simply does not define them. The official download page states that only the most recent release in the current series is safe to use and actively maintained, and exactly one version is officially supported at any time.
Receiving updates is not the same as being supported
The Security Team backports security fixes to older, officially unsupported branches as a courtesy, and ships them through automatic background updates. That is why, in August 2026, every branch back to 4.7 (released in 2016) still receives fixes on the same dates. The blank date columns for 4.7 and newer on this page reflect that absence of a published deadline — not a distant one.
What gets backported is critical security fixes only. Bug fixes, feature work, and compatibility with newer PHP releases are not. "Still getting updates" should not be read as "still supported".
About the grouping used here
Every branch from 4.7 onward receives the same fix on the same day, so listing them individually would fill thirty-odd rows with identical content. This page therefore groups branches by shared support status (major series). The boundaries follow WordPress's own retirement announcements (4.1-4.6 and 3.7-4.0) rather than any choice of ours, and each row names the branches it covers. See the official Release Archive for the full branch list.
Branches are retired by announcement, not by calendar
Retirement happens through a one-off announcement rather than a scheduled date. It has happened twice.
| Branches | Announced | Effective |
|---|---|---|
| 3.7-4.0 | 7 September 2022 | 1 December 2022 |
| 4.1-4.6 | 19 June 2025 | July 2025 |
Both times the notice period was one to three months. If you are running an old branch, assume you will get only a few months of warning. The stated criteria are that the versions are eight or more years old and account for less than 1% of installations.
The real risk is plugins and themes, not core
- Plugins and themes account for the majority of WordPress vulnerabilities. Extensions pinned to an old core stop being updated along with it.
- PHP compatibility: old WordPress releases may not run on current PHP. The upstream PHP EOL and the WordPress version can deadlock each other.
- Automatic updates cover minor (security and maintenance) releases by default. Major upgrades are manual, which is why neglected sites stay on old branches.
3.6 and earlier
Branches up to 3.6 have received no releases since 2013. Courtesy backports only ever covered 3.7 and newer.
Practical guidance
Because no deadline is published, remaining lifetime cannot be determined in advance. Stay on the current major version, or at most one behind. Continued updates on an old branch are not a reason to defer an upgrade.
Sources
- https://wordpress.org/download/releases/
- https://wordpress.org/about/security/
- https://wordpress.org/documentation/article/wordpress-versions/
Last verified: 2026-08-21