Magento Hosting Guide: What Your Store Needs, and How We Run It
Magento hosting is a server built around Magento's own stack: a supported PHP version, MariaDB or MySQL, OpenSearch, a cache such as Valkey, and Varnish in front, sized for your traffic and kept patched. This page sets out what Adobe requires in 2026, which versions still get security fixes, how to choose a server type, and what to ask any Magento hosting service before you sign. It ends with how EveryHost runs it.
- nginx
- PHP
- MariaDB or MySQL
- OpenSearch
- Valkey or Redis
- Varnish
What Magento 2.4 needs from a host in 2026
Adobe publishes the exact software combinations it supports for each release, and "Adobe supports only the system requirement combinations listed". Any good hosting for Magento 2 starts from that table. These are the on-premises requirements for the latest patch of the three newest release lines (Adobe system requirements, checked 11 October 2026):
| Component | 2.4.9 | 2.4.8-p5 | 2.4.7-p10 |
|---|---|---|---|
| PHP | 8.5 | 8.4, 8.3 | 8.3, 8.2 |
| Composer | 2.10 | 2.10 | 2.10 |
| MySQL | 8.4 | 8.4 | Not supported |
| MariaDB | 12.3 | 11.4, 11.8 | 10.11, 11.8 |
| OpenSearch | 3 | 3 | 2.19, 3 |
| Valkey | 9 | 8.1 | 8.1 |
| Varnish | 8 | 8 | 8 |
| RabbitMQ | 4.3 | 4.3 | 4.3 |
| nginx | 1.30 | 1.30 | 1.30 |
A few points from the same page are worth knowing before you choose a host:
- For 2.4.9, Adobe says to upgrade to MariaDB 12.3 before you upgrade Magento.
- MySQL 8.0 reached end of support on 30 April 2026, and Elasticsearch 7.17 on 15 January 2026.
- Apache is no longer listed for current patches; nginx 1.30 is.
- A search engine is not optional: "all installations must be configured to use Elasticsearch or OpenSearch" (Adobe search engine prerequisites).
- For full page caching, Adobe says: "We strongly recommend you use Varnish in production" (Adobe Varnish guide).
If you want a version-by-version view of what we run, see our Magento 2 hosting page.
Which Magento versions are still supported
Adobe's lifecycle policy sets the support dates for each release line (Adobe lifecycle policy, checked 11 October 2026):
| Release | General availability | End of standard support | End of extended support | End of security-only period |
|---|---|---|---|---|
| 2.4.9 | 12 May 2026 | 31 May 2029 | To be confirmed | Not applicable |
| 2.4.8 | 8 April 2025 | 31 May 2028 | To be confirmed | Not applicable |
| 2.4.7 | 9 April 2024 | 31 May 2027 | 31 May 2028 | Not applicable |
| 2.4.6 | 14 March 2023 | 11 August 2026 | 31 August 2027 | 31 May 2028 |
| 2.4.5 | 9 August 2022 | 12 August 2025 | 11 August 2026 | 31 May 2027 |
| 2.4.4 | 12 April 2022 | 12 April 2025 | 14 April 2026 | 31 May 2027 |
Two things matter for most merchants. First, the policy is written for Adobe Commerce, and the extended and security-only periods are available to Adobe Commerce customers only. Second, for Magento Open Source, Adobe's own knowledge base says "Open Source merchants can only download patches for version 2.4.7 or later" (Adobe KB, APSB26-138). An Open Source store on 2.4.6 or earlier is outside the normal patch stream.
See Magento end of life dates for the full picture, and Magento upgrades and security patching for how to move to a supported release.
Shared, VPS, dedicated or cloud: choosing a Magento hosting service
Adobe gives no minimum hardware and does not mention shared hosting in its hardware guidance. The choice between server types is about control, isolation and how predictable your traffic is.
| Server type | Strengths | Trade-offs |
|---|---|---|
| Shared | Lowest price. Some providers sell shared plans with OpenSearch and a cache included. | Resources are shared with other customers. Magento needs a search engine, Varnish, cron, Composer and command-line access, which shared plans may limit. |
| VPS (virtual server) | Set CPU and RAM, root access, the full Adobe stack, quick to resize. | The physical machine is shared at the host level. |
| Dedicated server | The whole machine, predictable performance, room for the full stack on one box. | Fixed capacity, so growth needs planning; one machine is one point of failure unless you add redundancy. |
| Multi-server or cloud cluster | Several web nodes, replica databases and failover for spiky or high-value traffic. | More cost and more moving parts. Magento needs shared media and session storage to run on more than one web node. |
EveryHost does not sell shared hosting. We offer a managed Magento VPS, a Magento dedicated server for stores that need the whole machine, and high availability Magento hosting for stores where downtime is too costly to risk.
How much CPU and RAM a Magento store needs
Adobe gives a formula rather than fixed tiers (Adobe hardware recommendations):
- CPU: cores = (expected simultaneous requests ÷ 2) + expected cron processes. "One CPU core can serve around two (sometimes up to four) Commerce requests effectively."
- PHP memory: about 2 GB for a single-server store.
- Database memory: "at minimum, close to half the size of the data stored in the database".
- Varnish and the cache: enough memory to hold your most popular pages, and the rest of the caches, in memory.
As an illustration only: a store expecting 20 uncached requests at the same moment at peak, plus 2 cron processes, works out at (20 ÷ 2) + 2 = 12 cores. The hard part is the first number, because it depends on how much of your traffic Varnish serves from cache. Our Magento server sizing guide walks through how to estimate it from your own traffic.
UK data location, UK GDPR and your hosting contract
UK GDPR does not require UK-only hosting. Under the ICO's guidance, a transfer is "restricted" only when the UK GDPR applies, you are initiating the transfer to an organisation located outside the UK, and that organisation is a separate legal entity (ICO brief guide to international transfers). All countries in the European Economic Area have full UK adequacy (ICO adequacy coverage).
What matters more is the contract. A host that processes your customers' data is a processor, and Article 28 of the UK GDPR requires a written contract with eight terms: processing only on your documented instructions, a duty of confidence, appropriate security, rules on sub-processors, help with data subjects' rights, help with your own obligations, end-of-contract provisions, and audits and inspections (ICO contracts guidance).
When you compare hosts, ask where the servers are, where backups and any off-site copies are stored, whether a data processing agreement is available, and who the sub-processors are. A UK data centre keeps things simple and keeps latency low for UK shoppers, but it does not make a store compliant on its own. EveryHost's servers are in our London data centre, and we can work with you to help meet your UK GDPR obligations, depending on the services and extensions you use.
PCI DSS: what a host covers and what stays with you
The merchant stays responsible for PCI DSS. Even on Adobe's own cloud, "Merchants are responsible for the compliance of their custom code, system and network processes, and organization" (Adobe shared responsibility).
Card skimming makes the checkout page the risk to watch. Under PCI DSS v4.0.1, a merchant whose checkout embeds a payment provider's form must confirm that their site "is not susceptible to attacks from scripts". The PCI Security Standards Council's FAQ gives two routes: use protective techniques such as those in Requirements 6.4.3 and 11.6.1, or get confirmation from your PCI DSS-compliant payment provider (PCI SSC FAQ 1588). A good host helps you meet your obligations with a hardened server, timely patches and help with scan findings. It cannot sign off your compliance for you. Confirm your own scope with your payment provider or acquirer.
Security patching: who applies what
Adobe published six Adobe Commerce security bulletins in 2025, and six so far in 2026 including one out-of-band emergency fix (7 September), checked on 11 October 2026. Most fall on the second Tuesday of a month (Adobe security bulletins). Adobe's stated minimum is one security release a year per supported line (Adobe release schedule), so the real cadence is busier than the minimum suggests.
Before you sign, find out exactly who applies each kind of update:
| Layer | What it covers | Who applies it on EveryHost hosting |
|---|---|---|
| Operating system | Kernel and system packages | Us: server-level patches, PHP updates and security hardening |
| Magento core security patches | Adobe's -pN releases | On Fully Managed, us: staging first, then coordinated with your team. On other plans, your developer applies them on staging and we coordinate production |
| Emergency hotfixes | Out-of-band fixes such as September 2026's | The same route as core security patches |
| Extensions and themes | Third-party code | Usually your developer or agency |
Our approach is staging-first, in defined maintenance windows, with a rollback plan. See Magento upgrades and security patching for the detail.
Backups, staging and developer access
Ask three questions about backups: how often they run, where the copies are kept, and who restores them. A copy on the same server protects you from mistakes; a copy somewhere else protects you if the server itself is lost. At EveryHost, backups are held on your server and our engineers handle restores. Bastion, our encrypted off-site backup, is an optional add-on, or included up to 50 GB with Fully Managed.
Staging should be a separate copy of your store on the same versions as production, with its own database, kept out of search engines and without live payment keys. Developers should have SSH, Composer, Git and command-line access, because Magento upgrades and deployments run from the command line. Every EveryHost plan includes a staging environment.
Support: what to ask before you sign
Support is where hosts differ most, and where marketing is vaguest. Ask:
- Who answers: Magento engineers, or a general helpdesk?
- What "24/7" covers: every request, or only outages?
- How do you escalate an incident out of hours?
- What is the uptime commitment, and what counts as downtime?
At EveryHost, support comes with your hosting: 24/7 UK support by ticket, through our support portal, from our Magento engineers, and 99.5% uptime on every plan. We only support stores we host. See Magento support and maintenance for what is included.
What "Magento cloud hosting" can mean
The phrase is used for three different things:
- Adobe Commerce as a Cloud Service: Adobe's software-as-a-service product, where "the continuous delivery of new features and updates eliminates the need for manual patching" (Adobe overview). It is for Adobe Commerce licences.
- Adobe Commerce on Cloud Infrastructure: Adobe's platform-as-a-service, under a shared responsibility model.
- Cloud servers from a hosting company, such as virtual machines on a public cloud.
EveryHost is none of the first two: we are not Adobe Commerce Cloud. For how cloud servers compare with dedicated hardware, see Magento cloud hosting, and for a priced comparison of running Magento on AWS, see Magento hosting on AWS vs managed UK hosting.
Magento hosting cost and pricing
Comparing Magento hosting cost is harder than it should be, because providers show prices in different ways. In the published UK and European Magento hosting prices we looked at on 10 October 2026, entry plans ran from under £40 a month for shared plans to well over €100 a month for single-server cloud plans, shown variously in pounds, euros or dollars, some with VAT and some without, and several providers quote only. That is a sample of published prices, not a market survey.
When you compare Magento hosting pricing, check four things: the currency, whether VAT is included, whether migration and staging cost extra, and whether the price covers management or just the server.
EveryHost prices are monthly, in pounds, and exclude VAT:
| Plan family | What it is | From (ex VAT) |
|---|---|---|
| Managed VPS | An isolated virtual server, managed for you | from £119 a month + VAT |
| Dedicated servers | A single-tenant dedicated server | from £249 a month + VAT |
| High availability | A multi-node web tier with high-availability database options, built to order | from £799 a month + VAT |
See plans and prices for every plan and what it includes.
Questions to ask any Magento hosting provider
Use this checklist with any of the Magento hosting companies on your shortlist:
- Do you run the exact PHP, database, OpenSearch and cache versions Adobe lists for my patch level?
- Is Varnish included and configured, or just possible?
- Is the server shared, virtual or dedicated, and what CPU and RAM is reserved for me?
- Where are the servers, and where are the backups and off-site copies stored?
- Will you sign a UK GDPR Article 28 data processing agreement, and who are your sub-processors?
- Who applies operating system patches, Magento security patches, emergency hotfixes and extension updates?
- Are patches tested on staging before production?
- How often do backups run, where are they kept, and who restores them?
- Is a staging environment included?
- Who answers support, and what does "24/7" cover?
- What is the uptime commitment, and what counts as downtime?
- Is migration included, and what does it cover?
For a side-by-side view, see best Magento hosting in the UK compared.
How EveryHost runs Magento hosting
EveryHost is a Magento Open Source specialist. We are not Adobe Commerce Cloud, and we do not sell shared hosting. Merchants who hold their own Adobe Commerce licence can run it on our servers as self-managed hosting.
- Where: our London data centre.
- Uptime: 99.5% uptime on every plan.
- Stack: nginx by default, built to your setup after ordering, with cPanel if you want it. Redis or Valkey is set to match your Magento version, alongside OpenSearch and Varnish.
- Security: Sentinel, our Magento-tuned security monitoring, on every plan at no extra cost. It reads your server's logs, blocks abusive sources at the server firewall, and our engineers review what it finds. Managed VPS plans include Sentinel Plus, with bot protection, file integrity monitoring and stricter blocking rules at the server firewall. Dedicated and high availability plans include Sentinel Pro, which adds active tuning during an attack and priority response from our engineers. Sentinel is not a web application firewall, a CDN or a proxy, and it does not sit in front of your store. If you want an edge WAF or CDN, we recommend putting Cloudflare in front of your store, alongside Sentinel.
- Patching: operating system and server stack security updates, PHP updates and security hardening are ours on every plan. On Fully Managed, we also apply Magento security patches, staging first, then coordinated to production with you. On other plans, your developer applies them on staging and we coordinate production.
- Support: 24/7 UK support by ticket, included with your hosting. See Magento support and maintenance.
- Management plans: Managed from £85 a month + VAT, or Fully Managed with Magento patching and off-site backup. See our Managed and Fully Managed plans.
- Migration: moving a Magento 2 store to us from another host is free, with minimum downtime, and most stores are live within 24 to 48 hours. See free Magento migration. Still on Magento 1? A Magento 1 to Magento 2 migration is a quoted project: see Magento 2 migration.
We are a Magento hosting UK specialist with UK-based engineers. Talk to us about your store, or see the plans.
Frequently asked questions
Find the right Magento server
See every plan and what it includes, or talk to an engineer about your store.