Every web host has a quiet corner of its WordPress fleet that never moved. Sites still running PHP versions that stopped receiving security fixes years ago. Most hosts have a product for them: extended PHP support, a monthly fee to keep an old runtime patched while the customer figures out what to do next.
The trouble is that next rarely arrives. The customer keeps paying. The host keeps patching. The site never gets modernized. Some of these sites have been on extended support for five years or longer. Extended PHP was designed as a bridge, and for a lot of customers it became a permanent address.
Today we are announcing the WP Care + PHP Upgrade Bundle, a way to turn that recurring relationship into the thing it should have been all along: a path to a current, maintained site, at the price the customer already pays.
The holding pattern
Look at what the money buys today. The customer pays to remain on an old version of PHP. The host spends engineering time backporting security fixes into runtimes the PHP project no longer supports, or pays a vendor to do it, and its support team absorbs the compatibility tickets that legacy sites generate. Nobody in the arrangement is paid to make the site current.
That would be a manageable problem if the pool stayed the same size. It does not. PHP 8.1 stopped receiving security fixes at the end of 2025. PHP 8.2 stops on December 31, 2026. Every January a new wave of sites becomes legacy, and a program that only patches never gets smaller.
The switch
Here is the offer. Take the customer who is paying you for extended PHP and give them WP Care instead, at the same price, with the PHP upgrade included.
Enroll your legacy fleet on WP Maintain. We audit every site and sort it into a lane before anyone touches production: upgrades cleanly, needs a quick fix, needs code patches, or should be rebuilt. Sites that can be upgraded in place get upgraded, with a compatibility scan, code fixes, a staged test upgrade and a safe migration with rollback standing by. As each site comes current, you change the billing SKU from extended PHP to WP Care.
The customer pays what they paid before. Instead of a patched old runtime, they get a site on current PHP with safe core, plugin and theme updates, malware scanning, backups with rollback, uptime and PHP monitoring, and a monthly Proof-of-Care report that shows the work. Nothing is required from them. You send one notice: your site is now on current PHP, and your plan got better.
For hosting partners on WPM+ under a volume agreement, the upgrade is included for every enrolled legacy site. Minor fixes on WP Care, code patches on WP Care+. The edge cases, a site built on an abandoned plugin that holds its business logic or a site that should be rebuilt rather than patched, are quoted through Pro Services before any work starts, and can be sold a la carte or folded into WP Care Pro, Pro+ and VIP, where PHP upgrades are already part of the plan.
| Extended PHP today | WP Care after the switch | |
|---|---|---|
| What the customer pays | The same monthly fee | The same monthly fee |
| What the customer gets | An old PHP version, patched | Current PHP, safe updates, malware scanning, backups, monitoring, a monthly care report |
| What the site runs on | An end-of-life runtime, indefinitely | A supported runtime, kept current from here on |
| What the host does | Backports patches or pays a vendor to | Changes the SKU, sends one notice |
| What the host keeps | The revenue, plus the support load | The revenue, minus the support load |
| Where it ends | Nowhere | A version you can retire |
Nothing waits unprotected
An enrolled site that is still in the queue is not sitting exposed. It is on the same WP Care plan as the rest of your fleet, hardened at the application layer, plugins and themes, which is where the overwhelming majority of WordPress compromises actually enter. WP Care+ adds virtual patching and malware removal for the sites that need it most. The monthly report carries a legacy PHP section showing exposure, what blocks the upgrade and where the site sits in the queue. The day the site comes current, that section disappears and the plan continues as it was.
We do not manufacture security patches for dead runtimes. That model gets paid when sites stay old. Protection is the waiting room. The upgrade is the destination.
| Lane | What the audit found | What happens |
|---|---|---|
| Upgrades cleanly | Passes on staging with no fatal errors | Flipped to current PHP, SKU switched |
| Quick fix | A utility plugin, an expired license, deprecation warnings | Swapped or fixed, included with WP Care |
| Code patches | An abandoned theme or non-critical plugin breaking on PHP 8 | Patched via child theme or overrides, included with WP Care+ |
| Heavy refactor | A mission-critical abandoned plugin holding business logic | Quoted through Pro Services, or included in Pro+ and VIP |
| Rebuild | Cheaper to rebuild than to patch | WP Rebuild through Pro Services; never-changing sites recommended for Managed Static |
What changes for the host
Revenue stays. The recurring line you already bill continues, renamed from a legacy support fee into a care plan.
Cost falls where it actually sits. The compatibility tickets legacy sites generate stop, and when a version is fully retired, whatever you were paying to keep it alive, engineering time or a vendor line, goes with it.
Visibility arrives. PHP Lifecycle in WP Maintain gives you a fleet-wide view by PHP version, tracks every upgrade and rebuild, and shows the legacy count falling month by month.
Upsells follow. A customer who just received a current site and a care report is the easiest customer you will ever move to WP Care Pro.
A new number for your QBR
Extended PHP programs are usually measured by one figure: how many customers are paying. The better figure is how fast the fleet is leaving.
Legacy PHP Sites. Upgraded. Rebuild Candidates. Remaining Opportunity.
One funnel per PHP version, reviewed every quarter, trending to zero. It tells your leadership that the legacy problem is shrinking on a schedule, and it tells your customers that the plan they pay for is taking them somewhere.
No new billing motion
The part we like most is what the bundle does not require. No new product launch. No new sales motion. No customer to convince. The billing line the customer already sees changes its name and delivers more. Whatever you pay a vendor to patch old PHP is pennies per site and never ends; the number that matters is the $5 to $25 a month you bill for it. The host pays WP Maintain a per-site platform fee that is a fraction of that line.
Extended PHP does not have to be the destination. It can be the starting point.
Start with the list
Send us your legacy PHP site list. We will audit a sample free and tell you what share upgrades cleanly, what share needs code patches, what share should be rebuilt, and what the program looks like for your fleet, with projected hours. That report is yours whether or not you go further.
See the Legacy PHP Fleet Program or request your fleet audit.



