PHP

PHP is a server-side scripting language created by Rasmus Lerdorf in 1994, and it still runs a large share of the web: WordPress (powering over 40% of websites), Wikipedia, Slack's early backend, Etsy, and countless business applications. Its early reputation for inconsistency and insecure tutorials lingers, but modern PHP — versions 8.x — is a fast, typed, well-tooled language with a mature ecosystem centered on Composer and frameworks like Laravel and Symfony.

PHP's traditional "shared-nothing" model — each request starts fresh and ends by throwing away all state — makes it simple to deploy and scale horizontally. Newer runtimes also allow long-running workers for high-performance applications.

TL;DR

Quick Example

Modern PHP with strict types, an enum, a readonly value object, match, and a prepared statement:

Core Concepts

The Request Lifecycle

In the classic model, a web server (NGINX or Apache) passes each request to PHP-FPM, which runs your script from the start, handles the request, sends a response, and discards all memory. This shared-nothing design avoids memory leaks and cross-request bugs, and scales by adding processes. OPcache stores compiled bytecode in shared memory so files aren't recompiled on every request; the JIT (PHP 8.0+) helps CPU-heavy workloads.

Long-Running Runtimes

FrankenPHP (worker mode), RoadRunner, and Swoole/OpenSwoole keep the application booted between requests, dramatically reducing bootstrap overhead. Laravel Octane and Symfony Runtime support them. The trade-off: you must avoid leaking state between requests, like any long-running server.

Modern Language Features

Composer and PSR Standards

Composer installs packages from Packagist, resolves versions, and generates an autoloader. PSR (PHP Standards Recommendations) define shared interfaces: PSR-4 autoloading, PSR-12/PER coding style, PSR-3 logging, PSR-7/15/17 HTTP messages and middleware, PSR-11 containers. Frameworks and libraries interoperate through them.

Frameworks and Ecosystem

Best Practices

Turn On Strict Types and Static Analysis

declare(strict_types=1) stops silent type juggling; PHPStan at a high level catches bugs before runtime.

Always Use Prepared Statements

PDO or your ORM's parameter binding prevents SQL injection. Never concatenate user input into queries.

Hash Passwords Properly

Use password_hash($password, PASSWORD_DEFAULT) and password_verify(); never MD5 or SHA1. See Password Security.

Escape Output by Context

Use your template engine's auto-escaping (Blade, Twig) or htmlspecialchars() to prevent XSS.

Keep PHP Updated

Each PHP version receives active support for two years and security fixes for two more. Use Rector to automate upgrades.

Configure Production Correctly

Enable OPcache, disable display_errors, log errors, and set memory and execution limits appropriate to the workload.

Common Mistakes

Running Unsupported PHP Versions

Many servers still run end-of-life PHP versions with known vulnerabilities and much slower performance.

Loose Comparisons

== performs type juggling ("abc" == 0 was true before PHP 8). Use ===.

Mixing Logic and Templates

Putting database queries inside HTML templates makes code untestable and insecure. Use a framework or at least a clear separation.

Committing vendor/ or Ignoring composer.lock

Commit composer.lock for applications to get reproducible installs; install vendor/ during builds.

Storing Secrets in Code

Use environment variables or a secrets manager rather than hard-coded credentials in configuration files.

FAQ

Is PHP still worth learning?

Yes. It powers a large share of the web, has strong job demand around WordPress and Laravel, and modern PHP is fast, typed, and pleasant to work with.

What is Composer?

PHP's dependency manager. It installs packages from Packagist, locks versions in composer.lock, and generates autoloading for your classes.

Is PHP slow?

Not anymore. PHP 7 and 8 made large performance gains, OPcache eliminates recompilation, and long-running runtimes like FrankenPHP and Swoole remove per-request bootstrap costs.

Laravel or Symfony?

Laravel prioritizes developer productivity with conventions and an integrated ecosystem. Symfony offers highly reusable components and flexibility favored in large enterprise projects. Both are excellent.

How do I prevent SQL injection in PHP?

Use prepared statements with bound parameters through PDO or an ORM, and never build queries by concatenating user input.

Related Topics

References