PHP
PHP is a server-side scripting language created by Rasmus Lerdorf in 1994, and it still runs a large share of the web: WordPress (powering over 40% of websites), Wikipedia, Slack's early backend, Etsy, and countless business applications. Its early reputation for inconsistency and insecure tutorials lingers, but modern PHP — versions 8.x — is a fast, typed, well-tooled language with a mature ecosystem centered on Composer and frameworks like Laravel and Symfony.
PHP's traditional "shared-nothing" model — each request starts fresh and ends by throwing away all state — makes it simple to deploy and scale horizontally. Newer runtimes also allow long-running workers for high-performance applications.
TL;DR
- Use PHP 8.2+ with
declare(strict_types=1), typed properties, and return types. - Modern features: enums, readonly properties and classes,
match, named arguments, attributes, constructor promotion, first-class callables. - Manage dependencies with Composer; follow PSR standards (autoloading, coding style, HTTP interfaces).
- Enable OPcache in production; each request is isolated under PHP-FPM.
- Use PDO prepared statements,
password_hash(), and output escaping to prevent the classic vulnerabilities. - Build on Laravel or Symfony; add static analysis with PHPStan or Psalm.
Quick Example
Modern PHP with strict types, an enum, a readonly value object, match, and a prepared statement:
Core Concepts
The Request Lifecycle
In the classic model, a web server (NGINX or Apache) passes each request to PHP-FPM, which runs your script from the start, handles the request, sends a response, and discards all memory. This shared-nothing design avoids memory leaks and cross-request bugs, and scales by adding processes. OPcache stores compiled bytecode in shared memory so files aren't recompiled on every request; the JIT (PHP 8.0+) helps CPU-heavy workloads.
Long-Running Runtimes
FrankenPHP (worker mode), RoadRunner, and Swoole/OpenSwoole keep the application booted between requests, dramatically reducing bootstrap overhead. Laravel Octane and Symfony Runtime support them. The trade-off: you must avoid leaking state between requests, like any long-running server.
Modern Language Features
Composer and PSR Standards
Composer installs packages from Packagist, resolves versions, and generates an autoloader. PSR (PHP Standards Recommendations) define shared interfaces: PSR-4 autoloading, PSR-12/PER coding style, PSR-3 logging, PSR-7/15/17 HTTP messages and middleware, PSR-11 containers. Frameworks and libraries interoperate through them.
Frameworks and Ecosystem
- Laravel — expressive, batteries-included (Eloquent ORM, queues, Blade, Livewire). See Laravel.
- Symfony — reusable components and a flexible full-stack framework; many other projects (including Laravel) use its components.
- WordPress, Drupal — content management systems with huge plugin ecosystems.
- Tooling: PHPStan/Psalm (static analysis), PHPUnit/Pest (testing), PHP-CS-Fixer (style), Rector (automated upgrades).
Best Practices
Turn On Strict Types and Static Analysis
declare(strict_types=1) stops silent type juggling; PHPStan at a high level catches bugs before runtime.
Always Use Prepared Statements
PDO or your ORM's parameter binding prevents SQL injection. Never concatenate user input into queries.
Hash Passwords Properly
Use password_hash($password, PASSWORD_DEFAULT) and password_verify(); never MD5 or SHA1. See Password Security.
Escape Output by Context
Use your template engine's auto-escaping (Blade, Twig) or htmlspecialchars() to prevent XSS.
Keep PHP Updated
Each PHP version receives active support for two years and security fixes for two more. Use Rector to automate upgrades.
Configure Production Correctly
Enable OPcache, disable display_errors, log errors, and set memory and execution limits appropriate to the workload.
Common Mistakes
Running Unsupported PHP Versions
Many servers still run end-of-life PHP versions with known vulnerabilities and much slower performance.
Loose Comparisons
== performs type juggling ("abc" == 0 was true before PHP 8). Use ===.
Mixing Logic and Templates
Putting database queries inside HTML templates makes code untestable and insecure. Use a framework or at least a clear separation.
Committing vendor/ or Ignoring composer.lock
Commit composer.lock for applications to get reproducible installs; install vendor/ during builds.
Storing Secrets in Code
Use environment variables or a secrets manager rather than hard-coded credentials in configuration files.
FAQ
Is PHP still worth learning?
Yes. It powers a large share of the web, has strong job demand around WordPress and Laravel, and modern PHP is fast, typed, and pleasant to work with.
What is Composer?
PHP's dependency manager. It installs packages from Packagist, locks versions in composer.lock, and generates autoloading for your classes.
Is PHP slow?
Not anymore. PHP 7 and 8 made large performance gains, OPcache eliminates recompilation, and long-running runtimes like FrankenPHP and Swoole remove per-request bootstrap costs.
Laravel or Symfony?
Laravel prioritizes developer productivity with conventions and an integrated ecosystem. Symfony offers highly reusable components and flexibility favored in large enterprise projects. Both are excellent.
How do I prevent SQL injection in PHP?
Use prepared statements with bound parameters through PDO or an ORM, and never build queries by concatenating user input.
Related Topics
- Laravel — The most popular PHP framework
- SQL Injection — The vulnerability prepared statements prevent
- Password Security — Hashing credentials correctly
- REST API Design — Building APIs with PHP frameworks
- Package Managers — Composer and dependency management