It is a strong indication, because we are talking about non-packaged versions. PHP 5.3 is still maintained in Ubuntu, so those hosters aren't on the blame list. Only if PHP 5.3 / 5.2 / 5.1 is used without package manager.
It might be a strong enough indication to investigate further, but it is not a strong enough indication to out a company. You need to actively test the vulnerability to be sure (or relabel your page with a heavy disclaimer).