Airworthy – PHP Compatibility & Upgrade Checker Wordpress Plugin - Rating, Reviews, Demo & Download
Plugin Description
Your host wants you on a newer PHP version. Will your site survive the switch?
Airworthy reads the code of every installed plugin and of your theme (on multisite: every network-enabled theme) and checks it against the PHP version you pick, from PHP 8.0 to PHP 8.5. It also looks each plugin up on WordPress.org to see whether it is still maintained. You get one clear verdict per plugin and theme, before you touch your server settings.
Important: Airworthy helps you plan a PHP upgrade; it doesn’t guarantee one. Always back up your site and test the new PHP version on a staging copy before changing your live site.
What you get
- A verdict for every plugin and theme. Blocker, Unknown, Suppressed, Guarded, Warnings or Ready, each with one plain sentence explaining what it means for you.
- Fewer false alarms. Many plugins carry old code that only runs on old PHP versions, behind a version check. Airworthy recognises those checks and marks that code as guarded instead of broken. In our test of the 30 most popular plugins, this cut the plugins flagged as broken from 4 to 2, and in both the flagged code really would fail on PHP 8.
- Maintenance signals from WordPress.org (if you allow it). Plugins that were closed (removed from the directory), not updated in two years, not tested with recent WordPress versions, or that need a newer PHP version than you picked are called out.
- Know what to do next. Results are grouped into fix before you upgrade, keep an eye on, and all good. Plugins with an update waiting say so, with a one-click update, and Airworthy checks them again once they’re updated.
- Know how long you have. Airworthy shows when your server’s PHP version stops getting security fixes, so you can plan the upgrade before it’s urgent.
- The details when you want them. Every finding shows the file, the line and what changed in PHP. Filter by verdict, rescan one plugin after an update, or download everything as a CSV file for your developer or host.
- Sensible default. Airworthy recommends the oldest PHP version that still gets security fixes: the smallest upgrade that keeps your site protected. It shows every version’s support dates.
- Safe on any host. Scans run in the background in short batches, so they never time out, and they watch memory use. You can leave the page while a scan runs. Nothing is changed on your site.
- Settings that fit your site. Skip inactive plugins, keep a list of plugins and themes never to check, and choose a gentler scan speed for cheap shared hosting.
- In Site Health too. Tools > Site Health shows whether your plugins and themes are ready for the next PHP version, with a link to the full results.
- Multisite ready. On a network, Airworthy is activated network-wide and lives under Network Admin > Settings.
WP-CLI
Everything on the admin screen also works from the terminal:
wp airworthy scan --target=8.4checks every plugin and theme and prints the results. Add--wporgto include the WordPress.org checks.wp airworthy scan --only=my-plugin --fail-on=blockerexits with code 1 if anything would break, for CI.wp airworthy results --verdict=blocker,unknownshows what needs attention.wp airworthy issues <slug>lists one plugin’s findings with file and line.wp airworthy rescan <slug>,wp airworthy export --file=report.csv,wp airworthy status,wp airworthy cancel,wp airworthy resumeandwp airworthy targetsdo what their names say.
Privacy
This plugin reads your plugin and theme files on your own server; it never runs them and never sends them anywhere.
Airworthy only contacts an outside server if you allow it. Before your first scan it asks whether to also check WordPress.org, and remembers your answer; you can change it at every scan (in WP-CLI: --wporg or --no-wporg). If you say no, nothing leaves your server.
If you say yes, it looks up each plugin’s slug (its folder name) in the public WordPress.org plugin directory (api.wordpress.org), one plugin per request, to show whether it is still maintained. Nothing else is sent: not your site’s address (the requests use their own “Airworthy” user agent instead of WordPress’s default, which includes your site URL), not your PHP version. As with any web request, WordPress.org sees your server’s IP address. Answers are cached for 24 hours.
Airworthy sets no cookies, adds nothing to your site’s front end, and has no tracking, account or sign-up.
Source code and build
The full, human-readable source code is public at https://github.com/DigitalKind/airworthy.
The scan engine is built from open-source libraries: PHP_CodeSniffer, PHPCompatibility and PHPCSUtils. Other plugins, or your own tools, may load their own copies of these, possibly different versions. To keep the copies apart, the release build runs them through PHP-Scoper (https://github.com/humbug/php-scoper), which moves their code into Airworthy’s own AirworthyVendor namespace. The scoped code in the vendor/ folder is ordinary, readable PHP; only the namespace names change.
To rebuild the plugin from source, clone the repository and run bin/build.sh. It installs the exact library versions pinned in plugin/composer.lock, scopes them, checks the result and writes dist/airworthy.zip. docs/ENGINE.md explains each step.
Action Scheduler is bundled unscoped, as WooCommerce and other plugins do, because it is designed to share one copy between all plugins that include it.
Bundled libraries and licences
Airworthy’s own code is GPLv2 or later. It bundles:
- PHP_CodeSniffer 4.0.4: BSD-3-Clause. https://github.com/PHPCSStandards/PHP_CodeSniffer
- PHPCompatibility 10.0.0-alpha2: LGPL-3.0-or-later. https://github.com/PHPCompatibility/PHPCompatibility
- PHPCompatibilityParagonie 2.0.0-alpha2: LGPL-3.0-or-later. https://github.com/PHPCompatibility/PHPCompatibilityParagonie
- PHPCompatibilityWP 3.0.0-alpha2: LGPL-3.0-or-later. https://github.com/PHPCompatibility/PHPCompatibilityWP
- PHPCSUtils 1.2.3: LGPL-3.0-or-later. https://github.com/PHPCSStandards/PHPCSUtils
- Action Scheduler 3.9.3: GPL-3.0-or-later. https://github.com/woocommerce/action-scheduler
Because Action Scheduler is GPLv3 and the PHPCompatibility libraries are LGPLv3, the plugin as distributed, taken as a whole, is covered by the GPL version 3. Each library’s licence file is included in its folder. A software bill of materials (sbom.cdx.json, CycloneDX format) lists every bundled component and version.
Screenshots
Pick the PHP version to check against. Airworthy suggests the oldest version that still gets security fixes, and shows how long your server’s current version has left.
Scans run in the background in small batches, so they never time out. You see what’s being checked, how long is left, and each plugin’s verdict as it comes in.
One clear answer for the whole site, a count for each verdict, and which plugins have an update waiting.
Results grouped by what to do next. Details show each finding with its file, line and what changed in PHP, and updates are one click away.
Settings: skip inactive plugins, never check chosen plugins or themes, and pick a scan speed that suits your hosting. Changes save as you make them.
A PHP upgrade check in Tools > Site Health, next to WordPress’s own checks.
