2.4.0 released 20 July 2020, latest 2.4.0.
Magento 2.4.0 reached end of life on 28 November 2022.
What changed
Magento 2.4.0 made several platform-level changes from earlier 2.3 releases. It required PHP 7.4, moved catalog search to Elasticsearch rather than the MySQL search engine, and added support for Elasticsearch 7.6.x. It also made two-factor authentication mandatory for Admin users, strengthened security controls around Admin access, and included substantial API, GraphQL, checkout, catalog, inventory, and performance fixes and enhancements. These changes made the release a more consequential upgrade than a routine patch: server software, search infrastructure, Admin sign-in procedures, custom extensions, and integrations often needed review.
What staying costs
This cycle has reached end of life, so Magento no longer provides ongoing security fixes or product support for it. Remaining on 2.4.0 leaves known issues corrected in later Magento releases unaddressed and increases exposure when vulnerabilities affect Magento itself, bundled dependencies, or the surrounding PHP, database, and search stack. It can also make PCI-oriented security work, incident response, and vendor support harder to defend. Because 2.4.0 depends on an older platform combination, teams may be forced either to retain aging infrastructure or make unsupported infrastructure changes, both of which raise operational and upgrade risk. Extensions, payment services, shipping carriers, and other SaaS integrations may also cease to test against or support this release line.
What to do
Plan a move to a currently supported Magento release rather than treating a 2.4.0 patch level as a long-term destination. First inventory the installed Magento edition and patch level, PHP version, database engine, Elasticsearch or OpenSearch deployment, themes, custom modules, payment and tax integrations, and operational customizations. Obtain compatibility statements or upgraded versions for every extension and integration, paying particular attention to checkout, payment, search, GraphQL, and Admin customizations. Rehearse the upgrade in a production-like environment with a copy of the catalog and order data, run data and indexer checks, validate search behavior, test storefront and Admin workflows, and perform security and performance testing. Schedule a rollback-capable production deployment with verified backups, then retire or update infrastructure components that are only being retained for 2.4.0 compatibility.
See what moving on from Magento 2.4.0 involves.
See the Magento technology pageNot sure yet? Get my plan
We can tell you what moving off Magento 2.4.0 involves.
What it takes to move off Magento 2.4.0 depends on what you built on it — the version you are on, how much depends on it, and how much of the work is mechanical. Leave your email with this version and we can tell you what that looks like for you.
