> sometimes see that their front page has outdated PHP, as in 5.3 old. EOL for 11 months. That really bothers me. How can I rely on their security when their frontpage isn’t even up-to-date.
Errr... are you determining that the software is vulnerable through the version number alone? That won't work, some vendors backport security patches.