[wp-trac] [WordPress Trac] #63706: False positive: Site Health flags CentOS Stream 9 backported PHP versions as outdated

WordPress Trac noreply at wordpress.org
Wed Jul 16 13:11:53 UTC 2025


#63706: False positive: Site Health flags CentOS Stream 9 backported PHP versions
as outdated
-----------------------------+------------------------
 Reporter:  calpeconsulting  |       Owner:  (none)
     Type:  defect (bug)     |      Status:  closed
 Priority:  normal           |   Milestone:
Component:  Site Health      |     Version:  6.8.2
 Severity:  minor            |  Resolution:  duplicate
 Keywords:                   |     Focuses:
-----------------------------+------------------------
Description changed by SergeyBiryukov:

Old description:

> WordPress Site Health triggers a critical warning for PHP 8.0.30 on
> CentOS Stream 9, stating that the PHP version is outdated and insecure.
> However, CentOS 9 provides security backports to PHP 8 as part of its
> enterprise support model, maintaining security patches without altering
> the version number.
>
> This results in a false positive warning for users running PHP on CentOS
> 9, despite the PHP installation being actively patched and secure
> according to the distribution’s policies.
>
> It would be beneficial if WordPress Site Health could either:
>
> - Recognise backported PHP versions as supported.
>
> - Provide an option to acknowledge distro-specific patching models.
>
> - Clarify that the PHP version check is based solely on upstream
> versioning, which may not reflect distro backports.
>
> This change would help reduce confusion for users on CentOS and similar
> enterprise distributions.
>
> This issue was raised and ignored in
> https://core.trac.wordpress.org/ticket/41191

New description:

 WordPress Site Health triggers a critical warning for PHP 8.0.30 on CentOS
 Stream 9, stating that the PHP version is outdated and insecure. However,
 CentOS 9 provides security backports to PHP 8 as part of its enterprise
 support model, maintaining security patches without altering the version
 number.

 This results in a false positive warning for users running PHP on CentOS
 9, despite the PHP installation being actively patched and secure
 according to the distribution’s policies.

 It would be beneficial if WordPress Site Health could either:

 - Recognise backported PHP versions as supported.

 - Provide an option to acknowledge distro-specific patching models.

 - Clarify that the PHP version check is based solely on upstream
 versioning, which may not reflect distro backports.

 This change would help reduce confusion for users on CentOS and similar
 enterprise distributions.

 This issue was raised and ignored in #41191.

--

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/63706#comment:3>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list