ionCube Loader on Ubuntu 24.04 with PHP 8.1 to 8.5
Install the ionCube Loader for PHP-FPM on Ubuntu 24.04, load it before OPcache, and check it worked. Plus why there is no loader for PHP 8.0.
The symptom
A site that worked on the old server shows one line on every page after a move: the file requires the ionCube PHP Loader. Nothing is wrong with the site. Its PHP files were encoded with ionCube, which many commercial scripts are, and the new server has no loader to run them.
The loader is a PHP extension, published by ionCube as a compiled file per PHP version. It is not in Ubuntu's package archive, so apt install will not find it.
Which PHP versions have a loader
ionCube publishes no loader for PHP 8.0. The release KLYRN pins, 15.5.0, carries loaders for PHP 8.1, 8.2, 8.3, 8.4 and 8.5, and for the older 5.6 and 7.0 to 7.4.
A loader for a newer PHP does not make old encoded files run on it. Files are encoded for a range of PHP versions, and the vendor of the script decides that range. If a script was encoded for PHP 7.4, run that site on 7.4 or ask the vendor for a newer build.
Installing it by hand
The steps below are for PHP 8.3 with PHP-FPM, as root. Change the version in every line for another PHP.
cd /tmp
curl -fsSLO https://downloads.ioncube.com/loader_downloads/ioncube_loaders_lin_x86-64.tar.gz
tar xzf ioncube_loaders_lin_x86-64.tar.gz
EXT=$(php8.3 -r 'echo ini_get("extension_dir");')
cp ioncube/ioncube_loader_lin_8.3.so "$EXT/"
echo "; priority=00" > /etc/php/8.3/mods-available/ioncube.ini
echo "zend_extension=ioncube_loader_lin_8.3.so" >> /etc/php/8.3/mods-available/ioncube.ini
phpenmod -v 8.3 ioncube
systemctl restart php8.3-fpm
Two details decide whether this works.
It is a zend_extension, not an extension. With the wrong keyword PHP logs a warning and carries on without the loader.
It must load before OPcache. The loader has to be the first Zend extension PHP opens. Loaded after OPcache, encoded files fail with an opcode error that names neither of them. The priority=00 line is what fixes the order: phpenmod turns it into a file called 00-ioncube.ini, which sorts ahead of OPcache's.
Check that it loaded
php8.3 -v
ls /etc/php/8.3/fpm/conf.d/ | head -3
The version banner should name the ionCube PHP Loader, and 00-ioncube.ini should be the first file listed. Then load the site. The command line and PHP-FPM read separate configuration directories, so a loader that shows up in php -v and not on the site means FPM was not restarted, or the site runs a different PHP version from the one you changed.
One more point for anyone who cares what runs on their server: you just downloaded closed-source code that runs inside every PHP worker. Compare the archive's checksum with a copy you trust before you install it, and note which release you installed.
On KLYRN it is one switch
Since 1.0.2 the ionCube Loader is in KLYRN's list of PHP extensions. Switch it on from the PHP page, or:
klyrn php enable ioncube --version 8.1
KLYRN fetches release 15.5.0 from ionCube's own server, refuses it unless it matches a pinned checksum, and loads it ahead of OPcache. Asking for PHP 8.0 is refused with the reason: ionCube publishes no loader for it.
It is an administrator's decision, like every other extension, and the description in the panel says whose code it is. klyrn php extensions lists what is switched on for each version.
SourceGuardian, the other common encoder, is not in the list yet. It is on the roadmap.