Risk · Security

Is Visual FoxPro Still Safe to Run a Business On?

Your Visual FoxPro application still opens every morning and still does the job. That is exactly why the risk is so easy to ignore. "It works" and "it is safe" are two different statements, and the gap between them widens every year Microsoft leaves the product untouched.

Here is the plain version, with the dates that matter.

The support timeline is not ambiguous

Microsoft shipped the last version of Visual FoxPro, VFP 9.0 Service Pack 2, in 2007, and announced the same year that there would be no version 10. Per Microsoft's published product lifecycle, extended support for Visual FoxPro 9.0 ended on January 13, 2015. Since that date there have been no security patches, no bug fixes, and no official support of any kind. That is more than a decade of an internet-connected world moving on while the runtime stood still. Our own end-of-life guide walks the full timeline.

What "unpatched" actually means

A supported product gets a fix when a vulnerability is found. An end-of-life product does not. When a flaw is discovered in the FoxPro runtime, its ODBC and OLE DB drivers, or a common ActiveX control your forms depend on, no fix is coming. The window never closes. Attackers know which software is abandoned, and abandoned software is a preferred target precisely because the defender cannot respond.

The compliance problem you may not see coming

Even if nothing is ever exploited, running end-of-life software is increasingly a finding in its own right. Auditors for PCI DSS, HIPAA, SOC 2, and cyber-insurance renewals routinely flag unsupported software as an unacceptable control gap. "It has not been breached yet" is not an answer an auditor accepts. More companies are discovering the cost of VFP not through an incident, but through a failed audit or a declined insurance policy that stops a deal.

The quiet risk: the most common way a FoxPro system finally forces a decision is not a dramatic hack. It is a compliance questionnaire, an insurer's checklist, or a customer's security review that will not sign off on unsupported software.

The single-expert risk sits on top of all of it

Security is not only software. It is people. Most FoxPro systems are understood by one or two developers, often nearing retirement. If that person is unavailable when something breaks, you are exposed on two fronts at once: an unpatchable runtime and no one who can safely touch it. That combination is how a manageable modernization turns into an emergency.

What to do instead of waiting

You do not have to replace everything overnight, and you should not. The lowest-risk first move is to get the application honestly assessed and to start with a read-only data layer, so modern, supported systems can reach your data while the FoxPro front end keeps running. From there the work phases in deliberately, on your schedule, instead of under duress.

Bottom line: Visual FoxPro running is not the same as Visual FoxPro being safe. The runtime has been unsupported since 2015, the compliance pressure is rising, and the expertise is thinning. The safe move is to start the transition while it is still your choice.

Want to know exactly where your application stands? Our free assessment gives you a clear-eyed risk and modernization picture, with no obligation.

FAQ

Common questions

Is Visual FoxPro still supported by Microsoft?
No. Microsoft ended extended support for Visual FoxPro 9.0 on January 13, 2015, and the last release, VFP 9.0 SP2, shipped in 2007. There have been no security patches or fixes since. The product still runs, but it is fully end-of-life.
Is it dangerous to keep running a FoxPro application?
It carries growing risk. The runtime and its data drivers are unpatched, so any newly discovered vulnerability stays open permanently. On top of that, auditors and cyber-insurers increasingly flag unsupported software as a compliance gap, which can block deals independent of any actual breach.
Does running FoxPro affect PCI, HIPAA, or SOC 2 compliance?
It can. Security frameworks such as PCI DSS, HIPAA, and SOC 2, as well as many cyber-insurance renewals, treat unsupported software as a control weakness. A FoxPro system with no available patches is a common finding, and the fact that it has not been exploited is not an accepted defense.
What is the safest first step off FoxPro?
Start with an honest assessment and a low-risk, read-only data layer that lets modern supported systems reach your data while FoxPro keeps running. That removes the highest-risk dependency first and lets the rest of the migration phase in on your schedule rather than during an emergency.

Get a real number for your application

A free assessment turns "it depends" into a scope, a phased timeline, and a plain-English plan. No obligation, no sales pressure.

Get a Free Migration Assessment