PHP Sucks
evertpot.com
evertpot.com
More work was available locally with PHP. Clients were more willing to pay. I've done a ton of things in WordPress that shouldn't have been, "to save money". And I've done greenfield development with CodeIgniter, Laravel (v3 and v5), and a customized set of the Symfony components. I've also maintained and improved brownfield projects that were outsourced.
I'm very tired of hearing that PHP sucks. PHP is a good language. And in my opinion, it has fewer ways to sabotage your own project than any language with monkey patching. PHP7 looks really awesome, and the community has been upgrading quickly toward it. PHP has always had best-in-class documentation in my opinion.
More often it's the programmer who sucks, not the language.
It's not like rails is the only alternative.
My reference for what you quoted was a Rails project written by a Python dev who thought he needed to make Ruby more like Python. The resulting code was so horrendous that I literally cannot tell which of 2-3 parts that compose one feature (all heavily monkey-patched together) is responsible for what. It's like 2-3 complete implementations, but depending on load order any piece of the 2-3 implementations could be handling it. The client didn't have the time required for me to fix it.
... to quote myself:
> More often it's the programmer who sucks, not the language.
Give me a break, it's not like there are only PHP jobs out there. If you can't find anything else then it's because you're not capable of coding something that is outside PHP domain, IE basic CRUD apps ..
In many ways, if a "coder" comes in and starts wanting to change a bunch of things purely because they are opinionated about languages, then that person is not going to go very far.
PHP: 30%; .NET for finance/enterprise: 25%; Java for finance/enterprise: 20%; Java for android: 10%; iOS: 10% (~5% overlap); Everything else: 10%.
And as far as payscales go, PHP is nearly always > the "Everything else" unless it's super specialized. But clearly everyone paying median or above for PHP is getting conned and they should convert their entire business to [flavor of the month] language.
[edit]And I'm leaving js off there on purpose as there are very few web devs who are expected to only work in PHP and never touch the js. And in those other orgs, you usually have a specific "front end" developer that probably doesn't deal with any other kind of code and makes less than the "full stack" devs.
citation needed, I don't believe one second these figures are accurate.
Or the client sucks.
Older projects will suffer till they're brought up to spec, true.
I think traits, and their Java equivalent, are OK to touch up legacy APIs (as they did with the Java collections API) but I have found no good place to stick them in a new project.
Not to say PHP hasn't been introducing functionality for writing good, stable code bases (type hinting in function signatures, namespaces, better garbage collection, an actual AST — as an aside: how ON EARTH did they do without an AST pre-PHP7?) but traits don't strike me as the feature to think of when designing a new code base.
They're not extendable, they're not overridable, they're monolithic, and classes expose their implementation details to them, which makes traits super fragile.
https://github.com/symfony/symfony/tree/master/src/Symfony
or you can look at simpler sample codes I wrote for a class in design patterns with php
OTOH RoR has its own bunch of problems, and exploits a number of anti-patterns "in the name of simplicity", and Ruby as an ecosystem has its own set of pain points (e.g. deployment).
I've felt for quite some time that most of the anti-PHP sentiment is an effort of other developers to justify the language they've selected to focus on. "Yeah, I'm doing Javascript and Node.js and yeah it's got it's sharp edges, but at least it's not PHP!"
The problem is, if the negativity continues, the next step is that business WONT want PHP in their ecosystem... And not because it can't get the job done for them, but just because "ew PHP. I heard that was bad."
Version control, documentation, checking their work before committing and sending to QA, documentation, and learning how little they actual know about development on a real timescale >> which language they use. I'd rather start out in a well run IT shop that uses PHP than a quirky single dev small shop (or god-forbid an academic ivory tower of babel) with the most cutting edge startup blessed tool set.
Would you be surprised if I told you that pro-PHP sentiment looks exactly like that as well?
When was the last time we saw a "PHP is Great!" article make it to the front page of HN? Most of the time, PHP developers are on their heels because it seems others are constantly on the offense. I've not figured out what value this constant aggression provides to these developers making the arguments. My only conclusion is that they're just trying to make themselves seem more important. To that note, the pro-PHP camp becomes more of a "non-anti-PHP." :)
Catchphrase so ironic I laugh every time I hear it. The language also is written by a programmer, who sucked in PHP's case IMO.
Yes, I am a terrible coder, but I am probably still better than you :)
- Rasmus Lerdorf
Modern PHP is written and maintained by a team of programmers. It hasn't been the language Rasmus wrote (badly, as a hack he never intended anyone else to use) for years. "For all the folks getting excited about my quotes. Here is another - Yes, I am a terrible coder, but I am probably still better than you :)"
That is, unless there is actually a prior instance of him saying it but there could well not be.I have 20 yrs of programming experience in various languages than I care to count, as much as 20! So I do know my languages. From an academic perspective, PHP blows! But from a practical standpoint, it's a tool. It get's the job done, so long as you know it's quirks, you can avoid them. It's much better now with the OOP support and with PHP7 supporting scalar type and return types declaration. It's going to even make it possible to develop more robust software.
I'm indifferent to hearing about PHP sucking. So people say it as a put down. Perhaps they groovy or scala. I really don't care. It pays and that's all I care about. When I engage in my own personal projects, I never use PHP. PHP's documenation is not bad, but best-in-class? Please! With that said, I agree with your last sentence, in the sense that a good programmer can get more done with a bad language like PHP than a bad programmer can get done with whatever the hell one chooses to consider a good language.
There's seriously wonky things in there like the associativity on ?: being wrong, and == being even more broken than in js. There's order of arguments on array_map and array_filter being inconsistent. It's not that there's a massive flaw in there that kills it, it's death by a thousand paper cuts.
Threading/asynchronicity comes to mind. I've worked on a few projects that started out as a web-front end, but then needed to do some background processing. Eventually the background process needs to be multi-threaded and the choices are: rewrite your code to support pthread's wrappers classes, use fork and shared memory segments, asynchronous web requests. All those solutions work, but they are much more complicated than the same task would be in most other languages with native threading support.
The real annoying part is that by nature it will never have the same amount of IDE niceties you'd get with more typed languages
I understand JS having its place as being ubiquitously supported in browsers but, just as PHP, it's bad and its problems are not about niceties from IDEs or static typing.
It's not quite bad enough to count as a Turing tarpit like INTERCAL or brainf*ck, but it's one of the closest mainstream languages to the tarpit.
I find it quite sad that most PHP developers seem to think that writing code that looks more like Java is the "correct" thing when its greatest features have always allowed loose types and first class functions. After all that's what makes it so easy to work with?
Perhaps PHP could have been more like Scala a few years back already.. the perfect combination of Objects and Functions...
I like PHP and JavaScript a lot. They are not perfect but these organically grown languages tend to be better from my experience.
And yeah I HATE inclusion in PHP... it's a mess
You're using Apache Groovy as a counter-example to PHP blowing? Groovy's the PHP equivalent in the JVM world, the sloppy partner to the more exacting Scala, Clojure, and Kotlin.
Since its first release in late 2003, Groovy's been extended and repurposed so many times it's not really one unified language anymore. The MOP stuff was added for Grails in 2006, the half-baked types when generics were added in v 1.5, the pluggable annotations in v 1.6, the command syntax in v 1.7 to appeal make Gradle builds look nicer, the static typing in 2.0, traits in 2.2, the unsuccessful switch to Android deliverables after that, with backwards incompatibilities between minor versions. And then there's the stuff that silently got dropped, like interceptors and empty try statements.
Groovy's OK for quick'n'dirties scripting Java classes and defining builds, but for actually building systems use a language built from the ground up for that purpose, e.g. Java, Scala, or Kotlin.
And I'm quite tired of hearing this silly, totally meritless defense in every single thread that discusses PHP. Can't we just agree that it's not a very good language, but people are still doing cool stuff and lots of money with it? So many pointless fights could be averted like this.
Personally, I'd rather everyone just stop the good/bad language debates entirely.
So really I don't think "good language" is subjective. PHP is not fast, it's not well-designed, it's not particularly terse, it doesn't have particularly great tooling (Facebook has made that better with their HHVM initiative in all fairness), it isn't consistent and easy to reason about and the worst offender of all, it doesn't offer a dramatically different or original model of thinking about programs.
What is has going for it has nothing to do with the language itself: jobs, ecosystem and easy hosting. I totally agree that a good language is whatever works for you, but in the meantime, "whatever is good enough" is a mindset that doesn't help us strive for something better, which does matter if we're going to collectively spend decades in this line of work.
Actually, it is.
In PHPs niche this should be in the advantages section.
Wrong, otherwise we would have this discussion in Esperanto.
Sometimes Real Life (TM) experience beats clever design. PHP was first, has iterated, always had a niche and is now better than ever. Not good but good enough to save people a lot of work.
I usually recommend that new developers start with Python. It teaches structure and consistency without as much variation or room to screw up.
Advantage: they'll never create a mess that you'll have to maintain.
/s
Yes, I totally agree with you: the advantage of PHP is that anyone can pick ut up, and they have done.
The question was often never if it should be coded in PHP or Java but if it should be coded at all and, if so: if it should be an excel file on a file share or sent in email or a php script.
Disclaimer: PHP and Java coder. I can get stuff done quickly in Java, but it takes some practice.
In the context, it's also a common occurrence that I can tell when developers came from the php (non framework) world. When I see them move to Rails (or in javascript), I often see an obvious lack of understanding / adaptation of MVC, Single Responsibility, asynchronicity, testing, and variable scoping - I've seen Senior PHP Developers come out with less of these concepts than codeschool graduates.
That's not to say that PHP has this, or that every Rails/JS developer writes tests and understands these things (it still confounds me how companies choose rails and don't implement any tests, despite testing being a core idea)..
If I have to do a beauty contest of the programming languages I used a lot, from uglier to most beautiful, I'd sort them like this: PHP, Perl and C (no ++), Java, JavaScript, Ruby.
I didn't use Python a lot and I'm undecided if it should be placed before or after JS. That silly method(self) looks as useless as PHP's silly $this->attribyte. They're just bad designs and other languages knew better. I'm starting to use Elixir and it goes between JS and Ruby so far. Java has its own way to make me feel like wanting to wash my hands at the end of the day (the language and the tooling) but not as much as PHP, even if I agree that PHP7 is somewhat more sane than it used to be. Why didn't they do it at version 2?
And if I have to sort them about what pays more... We could sort them by looking at the salary stats but eventually it's a matter of where we live and which opportunities we have. Any language will earn us money. No hard feelings.
Anyway, that is the way of Python. A lot of people is happy with that and will never be changed. It's beauty contest matter :-)
"Explicit is better than implicit" -- PEP 20
Python was the first language I ever learned and I just took it for granted that you had to manually specify "self" like that. When I see code with implicit self, it reads strangely to me. Like, "Where does 'this' come from? Oh yeah."
My first serious language was C, which is way more lower level than Python. Still Python has something that reminds me of C. Those wierd __xyz__ methods, looking like what we used sometimes in #define; the useless : instead of some { (I know where the : comes from but it should be deprecated or made optional) and that self, which is the pointer to the C struct we were using to implement OOP in C. It's a strange mix of low and high level constructs, not fully OO and definitely not functional. Being at midway on many axis maybe it's the reason why it appeals so many people: it's a little bit familiar to everybody and this is important for the success of a language. Think of Elixir which was designed to look similar to Ruby, even if they have nothing in common.
But I quickly moved away from it and I'll explain why.
I think that many programmers are starting to realize that the less "cognitive load" your language demands of you as a programmer, the better (the fewer bugs, etc.) Simple example, the recently-maligned "==" comparison operator has a very complex table of possible outputs (note that Javascript is also implicated here): http://stackoverflow.com/questions/7615214/in-javascript-why...
I mean, as a PHP programmer debugging code that used ==, you'd have to basically have that table memorized in order to successfully debug it. Contrast this with, say, Ruby, where only nil and false evaluate to false and everything else evaluates to true.
While there are of course "PHP best practices" that suggest === (which has a MUCH more sensible truth table), I find that much of the language is still simply not well thought-out and therefore is unsuitable for any large codebase. Sure, you can "get by" (see: Facebook), but you'd "get by" a hell of a lot better in a different (possibly a functional) language.
If you can't grasp all the cognitive load mentally, then you are invariably going to introduce unexpected states into your code (read: "bugs").
Lastly, a language should be 100% deterministic. Last time I checked, PHP didn't even consistently pass its own test suite. It literally has so-called "flagging" and "known-fail" tests which are just marked as such (and not fixed). I cannot explain how bad this is to build something else on top of.
So, yeah. If you're a great programmer, you can code almost anything in PHP (since you can handle the cognitive loads it introduces), just like you could code almost anything in, say, Brainfuck, or assembly. But as a great programmer, you'd be far better served by another high-level language (speaking as someone who knows and has worked with dozens of computer languages) which demands less cognitive load and therefore naturally reduces the number of bugs you will introduce.
I'll also plug John Carmack's piece on functional programming in object-oriented languages, because it's relevant: http://www.gamasutra.com/view/news/169296/Indepth_Functional...
Do you realize what a ridiculous statement that is?
Either that, or I'm just a really good programmer under pressure (I pulled an all-nighter for that one), which I would not disagree with, I've basically been coding since I was 12 in 1984, so I would HOPE that I'm somewhat of a force to be reckoned with at this point. ;)
The real problem is that so many people who use it are utterly incompetent.
When someone says they work in/with PHP you immediately wonder if they're in the "let's duplicate a 900-line function across dozens of files just to give various pages a different icon" camp, the "I call myself a PHP Developer, but all I really do is Drupal Templates" camp, or in the "using Composer and everything is pretty much like you'd expect it to be in any web app built with Ruby or Python or Node" camp.
Until you know, you fear acknowledging them or associating with them. But you can't really ask them up front. So it's easier to just avoid them.
And I say this as someone who occasionally works in PHP.
My customers and users of my applications don't care what it's written in.
But, you should definitely learn more languages as a programmer.
> And to anyone considering programming as a career, or trying to get into it... stay away from PHP.
This is the part I disagree with the most. The language is getting better and better with every release. It's incredibly fast, much safer to use (the Error exception type, scalar static type hints, all the garbage from the early 2000's has been removed), and easy to work with. The ecosystem (with the introduction of Composer) has _completely_ changed and reinvigorated the language. It's easily one of the best package managers out there. I definitely recommend giving PHP a look or a second change if you've written it off.
Take a glance at http://www.phptherightway.com/ to get started
Also, having had to maintain a Wordpress site the past few months, may God have mercy on all daily Wordpress devs. I truly admire your stalwartness now in putting up with that.
Before anyone says it; sure some users use WP for the themes and plugins; we use some of them but we are very careful using plugins. They have to be rocksolid for many years, actively supported and we have to have reviewed the code. Next to that they have to add something significant; installing a plugin for some social buttons is very much not worth the pain of updates / security breaches on a 100k+ (+ SLA) project. And so in the end we end up using 4-5 the same plugins for projects and the rest is either not needed or easy to implement anyway. So the hero implementing those guts in Django/Rails could also implement those plugins. I believe you would have something safe for the enterprise. Until then, they'll just use WP and trust admins/coders to fix the issues.
I would love for WP to exist as only an admin interface to a clean, backend data store. Unfortunately, the problem is the database schema that WP ships with and the way WP handles data. It's almost impossible to get data out of WP press without using its lackluster DB "abstraction" layer and running the fetched data through its many obscure filtering mechanisms. To top it off, WP smashes everything into a handful of tables and makes doing normal, straightforward relational looks up (as any sane schema would allow for) a complete nightmare. Alas, when you go the WP route, your data is very much dependent on WP (and by default PHP).
Any organization that uses WP for an extended period of time and builds up a non-insignificant amount of data will run into this wall, guaranteed. If you truly value your data and your project is anything beyond a personal blog that you'll give up on in 6 months time, do yourself and your organization a favor and find an alternative solution. If you must use WP, use it as what it was originally intended for: a blog. It's not a framework to develop a complex application off of.
[2] An example of a front end powered by the WP REST API https://github.com/ustwo/ustwo.com-frontend
This. I can waste my breath talking about another CMS which is better suited for the task, has cleaner data representation (good for 5 years' time) etc, and try to get stakeholders to buy into it. Or I can mention WordPress and have brand recognition do the work for me.
> The thing is, users seem to love it.
In my experience, the users find the admin confusing. It's the managers and above who love it. They know what they're getting and it feels safe.
It used to be "You're never fired for buying IBM". Now it's "You're never fired for buying WordPress".
My 'entry' into the enterprise world was web CMSs; my previous company used to make/sell a respected web CMS. If you talk about 'confusing admins' then the web CMS world is where you should look. Boot up a Liferay (oh and check out that code by the way) or Alfresco or Sitecore or Oracle CMS and stare in disbelief.
This is what these users are used to and compared with those, WP is really very simple. That's why no (?) enterprise will replace an international corporate roll-out with WP, but regional, if allowed (and it usually is as marketing simply doesn't work the same way worldwide), they will. Because of the ease and less friction; create a new content writer? Fill in paper work and ask the main IT dep vs do it yourself in 5 seconds and that kind of thing.
I totally agree with "But, you should definitely learn more languages as a programmer." In my current position I led a ground up build in Python/Django after 10 years of personally using PHP. I learned so much that I wanted to bring back to the PHP stack, only to find that the PHP community is already working on those things. It's really fun to see the parallels.
I am a strong believer in coding fundamentals and try to preach language agnosticism to my team. Yes there is often a right tool for the job, but in many cases the major platforms will be able to achieve the problem at hand – at least for typical problems.
PHP is actually the language I do recommend people learn if they're interested in web development (obviously along with JavaScript), because PHP developers are in high demand. PHP developers can always find work, precisely because there is so much PHP out there.
The stigma remains. All other things being equal, choose a language where you're not going to have to fight this fight.
When you step outside these mini ecosystems and look at PHP as a vanilla tool to work or to use a proper micro/full framework you start to question why use PHP at all? One possibly acceptable framework, in my opinion, is Laravel. The problem is PHP outside of these mini ecosystems isn't nearly as popular. It looks like people migrate to an entire new language like Python, Ruby, Node, etc. If we're talking about sheer people hiring Ruby, Node and Python typically trump PHP every time and are using frameworks - not Drupal or WordPress. Granted there are custom PHP apps out there and some very good ones but they're not the norm.
I switched full-time to Python using Flask and Django. It's like a breath of fresh air. My 2 cents is if you're on the fence, figure out how to work on one project using this new language full-time. Then you can make a better decision.
I like Laravel Elixir (the npm package) and Eloquent (the ORM). Laravel itself is overly complex and the learning curve keeps getting higher. I'm much happier with Slim 3
It works pretty well.
The flip side of that question, though, is "where would Laravel be if it were built by committee rather than benevolent dictator?" I'd wager Taylor's "I'm doing shit my way" has been at least part of what has made Laravel so successful.
In my most recent (side) project, I'm doing a Yii2 website and I'm feeling like it's not enterprisey enough. I have to go out of my way to figure out the best way to split things apart (which, I guess is good because it doesn't actually make that difficult for me at all - it's just something I have to choose to do)
I'm sure at least some part of that was the previous developer who built the application. But there is absolutely no reason for documentation to not answer the basic questions that seem to come up many times per day in their IRC channel.
I commonly recommend Yii and laud it's extensive documentation and "Definitive Guide" that covers basically everything.
In my current experience as a developer, Yii's documentation is the best I've ever utilized. Much better than any Javadoc I've googled or even php.net's
I've used form libraries from the PHPClasses one back in 2003 through Symfony forms now (which has cognitive overload, and is so flexible as to be restrictive). Most business systems I write are data focused so forms play a massive role in them - and in my developer happiness.
The view/controller layers are very flexible and can be hooked up to anything from an HTML template using Yii to angular/bootstrap (which is what we're using) or another framework to handle the forms.
What I like about it is the flexibility of the ORM, where you can use the model in a sane way but can completely toss it aside and just use SQL for those edge cases that would be a PITA in something like Django.
Some related discussion here: https://laracasts.com/index.php/discuss/channels/general-dis...
You think that feels enterprisy? Try Symfony, and listen to the community, with its "way to do things" that change every 6 months depending what's in vogue - and each time are invariably more abstract and complicated.
There's an upgrade path, sort of, but more importantly major versions of Drupal live for years. I think we'll keep seeing new D7 projects for at least 2 more years.
> ... And to anyone considering programming as a career, or trying to get into it… stay away from PHP. There’s lots of fun, interesting languages out there that also get the job done quick, but with a better reputation and this will have an actual effect on your future career options.
> Looking for a PHP developer for your next project? I'm looking for work! Check out my resume or drop me a line!
Here, I deploy every other morning. Usually, while my coffee is getting to the right temp. The ability to just "throw it on the server", and to take it back if you need to make it great. There's a bunch of devs here, and that deploy all day long every day is one of the main reasons we move "so much faster" than our competition.
So as much as I hate how weird it is, and how frustrating it is not to have strong typing... i respect the heck out of it.
We've since learned that this is problematic.
It's a company issue.
Once we switched over to Octopus we no longer had to bring several people on the team in and expect them to work 6+ hours on the weekend to do a deploy anymore, catch mistakes made during the deploy, etc. Now it's just done with a netops team clicking 'start' for each project, my boss on standby, and the whole thing done in about an hour, usually.
I still prefer .NET and C# for the cleanliness, correctness, and the fact that it's easy to write code that works the first time, but it is nice when I just need to update one PHP file and drop it on the server without any downtime to recompile on our WAMP server.
Yes, every popular language has critics, but that doesn't mean they're always wrong.
That's me but ... I've known quite a few good PHP developers like this author. I've also seen horrible, horrible things - things that other languages and frameworks simply won't let you do. A language that gives you a lot of slack also gives you more opportunity to hang yourself. There's nothing that says you have to hang yourself.
As mentioned, the barrier to entry is low with PHP. The combination of a "loose" language and a newbie programmer is dangerous. And didn't all of us, as newbs, think we were done when it seemed to work properly? So the correct statement is not that PHP sucks, it's that many write sucky PHP. I'd rather see everyone aspire to not sucking (and certainly not hanging themselves) regardless of the language they use.
NOTE: I wrote a lot of PHP code in the late '90s and reworked part of a project in 2005/2006 so I obviously don't know anything about the current state of PHP. I'm not against it - I simply choose not to use it (at least at the moment).
and then there's the other extreme. the overly scientific who brings all sorts of crap into the language or the frameworks. it's justsuch a shit show.
What we found is that most good programmers didn't want to work in php and most php developers were designers that learned how to code php. But they didn't understand CS fundamentals or even a decent idea how to code. They could cobble together a web site that worked and even looked great, but they didn't know how to write maintainable, modular code.
It got to the point where I would ask the candidate to merge two sorted arrays and 70% couldn't do it properly.
In terms of language, I thought php itself was a surprisingly productive language. I just quit though because I didn't want to be known as a php developer because of the stigma and there poor quality of other php developers that I encountered.
In fact, this is one of PHPs greatest strongs, not a weakness! NodeJS, Ruby and especially long-running Java web apps easily turn into huge memory leaks.
PHP, on the other hand... not so much.
> PHP is generally not approved in the enterprise
I believe OP is looking from the wrong angle. There certainly are successful, enterprise-used PHP applications (e.g. SugarCRM, Drupal, Typo3), so it certainly is not a problem of approval.
IMHO the real problem is the total dominance of (extremely!) outdated COBOL/FORTRAN/(other mainframe stuff), SAP and Java (hello Lotus Notes!) applications in business.
Basically for all the decent PHP developers I've known in my life money has never been an issue.
So maybe there are lots of mediocre php devs pulling the average down?
I think it's possible my salary has hit a plateau. Most SMBs do a false equivalence between PHP developers and junior developers. One place I worked at the owner used to brag about hiring people starting out for $12/hr.
The thing is, with my experience in PHP it's easier for me to write secure code in PHP than anything else at this point. I can do it really fast, too. I've internalized a lot of micro-optimizations in PHP. Project scaffolding on a greenfield project ends up looking a LOT like Express if you use the Slim framework. And I stay away from PHP if I need concurrency (and so far, per business requirements, I haven't). I can scale it really well, and I rarely have to worry about memory limits like you do with the JVM.
I'm hoping for a breath of fresh air with PHP7, because I'm not entirely sold on the current runtime alternatives - JavaScript, Python or Ruby. I've been trying Scala and I write less code than Java, but definitely more than PHP. It's also hard to jump into the Play framework if you don't grok the 'weird' operators. I also find that it's easier to hang yourself with incompatible components/libraries. So far it's fun to write though, but I don't think I've seen anyone hiring for Scala in my town.
In my experience the modern PHP developer is characterized by a crippling self-consciousness. When I meet someone who is a fellow developer and tell them that I do C and Python and stuff... they usually begin with a bit of self-deprecating humor: I do PHP and stuff, not real programming like you, blah blah blah. I feel obligated to correct them.
The best thing you can do for yourself as a programmer is to not pigeon-hole yourself to a single language regardless of how tempting it might be from an economic/marketing perspective. Learn maths and get good at identifying problems and simplifying them. Become an expert in at least one general-purpose language and one specialized one for sure... but remember to think like an engineer: these are just the brick and mortar of the job! You still need a good mind for design, creating blueprints, and the experience to make informed trade-offs.
PHP is good for many things. Deal with it.
All trendy technologies might be replaced anytime (hey React, Go, I'm looking at you!), one day they are very cool, the next day nobody maintains them and everyone talks about another new cool thing; how many of these have we seen?
New cool stuff are important to know, explore, test, use because they bring a lot of interesting stuff, but often they only address some use cases, as they have been made by a team with specific needs (looking at all hundreds NoSQL databases?); php and some others (like ruby) are stable, well known, cover a vast area of use cases with very well made and long thought frameworks and tools (symfony, doctrine, phpstorm, ...).
You are always free to follow trends, like with clothes, or just choose the best thing for what you need to do. You'll definitely find jobs with any of these, if you are able to explain why they are good for what you are doing.
I hate it, because it makes me feel defensive. PHP in their minds
is much worse than it practically is. Im tired of defending
PHP, Im tired of being set back and having to proof my compete
by virtue of being a PHP programmer.
For me it is the other way round. I like it when journalists ask me what super advanced tech stack I use. When I get tweets about what libraries I use in my projects. And students mail me questions about the technology behind my Startup. And I can reply "It is just your average LAMP stack".Some people openly question if a PHP developer who understands security exists at all: https://twitter.com/MalwareJake/status/506488937096183808
This is silly when you think about it. If so many systems run PHP, wouldn't you want your infosec people to know PHP and work with it more often? Why are we, culturally, encouraging such a blind spot by ostracizing folks who know it well? That part never made sense to me.
This conversation plays out more frequently than I like:
Rando: Hahaha PHP security is an oxymoron.
Me: Okay, then hack paragonie.com. It runs PHP. Logically, you should
be able to hack it _just for running PHP_ if PHP is so insecure.
Rando: But that website's mostly static content!
Me: Yes, but it runs PHP. So it must be insecure, right?!
So far, despite giving people permission so the prospect of CFAA convictions don't discourage them, none of these "PHP is inherently insecure" folks have succeeded. I wonder why. :)TL;DR - A lot of the hate against PHP is founded on ignorance and peer pressure. Be open to constructive criticism, of course, but a lot of the hate you'll hear is bullshit.
So it's not peer pressure, we actually have data to back this up, and if you think about it, the whole thing boils down to motivation. Sure, you can write secure and insecure code as well in any language/environment. But defaults are powerful, and it makes me feel sad every time I have to write in reports that "you should've paid attention to opt-in to the secure solution every time you do X" vs. when we do demos to developers and we have to work really hard to disable every protection built into ASP.NET. (And no, I don't like Microsoft at all.)
* Did they support EOL'd versions of PHP?
* Are they legacy WordPress/Drupal/Joomla projects that haven't been updated in years?
* Are they in the "we (didn't use a framework|rolled our own framework) and used the mysql_* functions" league?
* Did they attempt to do something weird/crazy (i.e. store all session state in an encrypted cookie instead of server-side like normal, but forget to authenticate the ciphertext)?
Those are the kinds of things that I rarely find in modern PHP projects.
One thing I think Evert neglected to mention in his post: There's definitely an ecosystem problem. Incidentally, I've been working on cleaning it up on multiple fronts:
* Improving the quality of information developers will find via Google search or StackOverflow
* Writing blog posts that address security concerns e.g. https://paragonie.com/blog/2016/02/how-safely-store-password...
* Improving the security of the tools and frameworks developers use
* Working to improve the language itself (part of the reason why PHP 7's CSPRNG functions don't fail open is because a few of us were very vocal on how/why that would harm security)
Frameworks were sometimes used, although their effect on security is somewhat baffling at first sight -- and this is regardless of the platform, although we found most issues with PHP and J2EE. Sure, when you use the framework for security-critical things such as constructing SQL queries (SQLi) or HTML output (XSS), things work quite well. However, since most developers don't think about these issues, the single time they have to "escape" from the framework, since it doesn't (or they just think it doesn't) support a certain scenario, they don't know about all the things PHP and in smaller ways, J2EE requires to do for security.
Of course, this way, the framework protects 9x% of the application, but the asymmetry of security is that the attacker only needs a single vulnerability while the defender must patch it all.
I'm not surprised to hear that custom-made business applications fared so poorly. Back when I worked for a telecommunications company, I saw some of the worst code imaginable endorsed by corporate and deployed to production with wild abandon. I reported no less than 10 vulnerabilities in my first day with a new codebase and they were all ignored. My boss took me aside and said, "There's some politics going on right now, just keep that in your back pocket in case you need to bring it up later. Now's not the time."
Personally, I don't see much point in arguing the merits of PHP compared to, say, Python, Ruby or Javascript, since those languages are so similar: procedural scripting by default; opt-in use of OO as the happy path for most libraries; functional programming possible, but an uphill struggle WRT APIs, tailcalls, language cruft, etc.
There's also a lot of interbreeding in those language's ecosystems, so there's rarely a killer library/framework/app in one which doesn't have a few carbon copies in the others. I would recommend developers in those languages look at what the others are doing, but I don't see much point in switching between them as an end to itself; go for it when convenient, but nothing much will change (e.g. I was heavily into Python, but fell into PHP dev roles commercially).
The more interesting comparisons are to be made with languages/ecosystems which have a different philosophy, e.g. Java/C#, Haskell/ML, Lisp/Scheme/Lua, C/Go/Rust, C++/D, Smalltalk, Forth, etc. Those kinds of comparison have meat; they're not just bikeshedding about which syntax to write imperative procedural/OO scripts in. I commend the author's choice of learning Go (although I'm not familiar with it myself).
I think the procedural/OO scripting languages will be around for a while to come, but I think their niche is in public-facing applications (usually Web sites, but Python certainly has a heritage of desktop GUIs and CLIs). Certainly the use of REST services is making it easier to use languages for those jobs they're good at; for example, using Go for data crunching, while Web site rendering is done in PHP.
Still, PHP is so goddamn cheap it's not even funny. But I recognize everything the author is describing.
Besides, learning a new language is fun and not that hard... They are all pretty much the same...
I agree that learning new languages is very useful. But as analogies go, going from PHP to another imperative language is more like switching dialects than learning a foreign language.
Yes it gets the job done and you can argue it is readily available, a calorie is a calorie etc....
...but the reality is even "new" McDonald's is not terribly good for you and people will judge you if continuously eat there (I'm not saying that is a good thing but it does happen. Just try asking coworkers to go there with you).
And that is the point. The OP doesn't like to be judged but the general consensus is PHP is "probably" not good for you long term (regardless of the caveats of the language one cannot argue that other language programmers are generally paid much higher).
Imagine it this way. Imagine a fitness professional saying: "you know calories are the main thing that make you fat so I eat a small McDonald's meal and fast the rest of the day".... what would you think of this fitness expert... would it honestly not affect your judgement?
I'm not saying PHP is bad... I'm just saying I understand the behavior the OP doesn't like.
This is what a function call looks like in PHP:
myfunc($arg1,$arg2);
What a mess, right?Functions can represent any subset of computation within a program, or in some cases a function can represent all of the computations of an entire program. If you're hung up on small nuances of a language, you're probably just not doing it right. That's not a bad thing. A lot of people find themselves in this position, but the bottom line is you're probably just not writing your programs with the correct lower level abstractions.
That's it. It's not magic, but it's not always easy either. You shouldn't feel bad about it. Just keep trying and one day you'll realize that very little of what makes a great programmer has anything to do with the language you're using.
NOTE: This isn't in response to the author. They appear to have a strong reputation within the PHP community. This is really just a general response to all of the PHP hate in this thread.
The author didn't explicitly state it as a causal relationship, but doesn't this have more to do with supply and demand than respect?
It's true that if you're a guru in a more esoteric language you're going to earn more respect than a guru in PHP (although if you're really a guru in PHP you're probably also pretty good in more respected languages).
But it's also true that your skills would be in much higher demand for any available jobs in that esoteric language than PHP skills are for its available jobs.
[EDIT: I suppose an argument that cuts the other way is that PHP projects -- regardless of what the employers know or care about the language -- tend to be lower status and lower paying than those built on more esoteric or more "serious" languages.]
This really hits the nail on the head. A lot of the criticism of PHP comes from people who have never worked with a good PHP codebase and have only seen some of the many examples of awful PHP code out there. A well written PHP codebase is really nice to work with.
> The problem I have with PHP has nothing to do with the language, it’s its reputation. I can’t count the times I’ve started a conversation with a programmer who upon finding out I primarily do PHP got awkward with me.
I've experienced this many times as well. I think the previous point is really the root cause of this. People have a lot of misinformed ideas about PHP due to the sheer amount of really low quality PHP code and "developers" (i.e. people with no experience just trying to get shit done).
I don't think you can argue it's just an opinion. I haven't seen anyone argue that php isn't badly designed or implemented. Other than stating that it works and you can work around it.
I'm a developer. I use tools to get things done. PHP is one of many tools in my arsenal. For certain projects, it's awesome. For others, it's very much not awesome.
That's the beginning and the end of it. I don't get defensive. If I bring up PHP and someone says something like, "Oh, I’m sorry about that" -- that's an indication of that person's immaturity, not any weakness on my part. It's a super condescending thing to say to someone...
If I didn't just give up on them at that point, maybe I'd explain why I chose PHP. If I'm wrong and I'm actually making a bad choice of tools for the given project -- happy to have that conversation and learn a thing or two!
As an aside, my favorite syntax is C#.
But at the end of the day, the author has the right idea and it seems many of you don't. If you're a skilled programmer the language is a preference, not a precursor to what your app will turn out to be. If for any other reason than platform related your code turned out bad it's a good indication you're not one of those skilled programmers.
The HN post title is sure helping with the reputation.
> PHP is great at gettings things done, pedantic points about design don't matter.
> PHP is a huge mess of a language - that people have overcome that to create things doesn't change that.
Both of these responses can be (and are, imo) true.
Asp.net on linux, Go, Elixir, Python, Ruby,Java ...
PHP kinda saved itself when it got Java like classes(which are fairly rigid thus allowed retrofitting "type safety" in PHP) which allowed engineers to write large and maintainable codebases (Symfony,Doctrine...).
So again, no need to complain, go see your manager and try to convince him to try an alternative solution. Of course if you're using a CMS like Worpdress or Magento it might be a bit more complicated to migrate. But for projects started from scratch frankly, an engineer that can write a Symfony/Doctrine app can easily switch to Asp.net, it's exactly the same level of complexity.
PHP get in your way only when your starting. You never make these "bad language mistakes" once you're experimented. And then you can write really clean code.
ASP, however, makes me vomit everytime I read a single line. COBOL is more readable !
There's nothing unreadable about .Net.
http://www.azquotes.com/author/47278-Rasmus_Lerdorf
As a language designer myself, I would find it hard to design a language worse than PHP, but Mark Rendle has tried: https://www.infoq.com/presentations/worst-programming-langua...
You can hate it as much as you like, but bad code comes from bad coding practices. PHP has all the features other languages have. It even fairs pretty well in the benchmarks game against its peers http://benchmarksgame.alioth.debian.org/
The one thing I never understood about developers is how your programming languages are a total pissing match. If it gets the job done, who gives a fuck if it has a few quirks here and there? Can you create something cool? Can it be properly secured? Ok, great, let's focus on building something instead of whether we're using wood or concrete.
On the article itself, it is a mindset issue with people. Not sure how it is different from people saying "haskell is useless" or "JS is a toy language".
Once you need a framework and the complexity that goes with it, PHP starts to suck. It lacks the behavior and tools to nicely manage complexity beyond a pile of files.
But when what you need is a pile of files, PHP is awesome.
The day a languages appears that is web-ready and dead-simple with no technical debt that's the day we can say: PHP Suck.
But I love them. As long as they stayed doing PHP they didn't contaminated other communities.
Now that they came to python with their bad practices exacly for the bad reputation reasons described in the article, I see PHP kind of coding ... SQL injections, shell injections ....
Please PHP coders I love you doing PHP, don't leave PHP.
Anyway...
>> For many people, PHP is the first programming language they try without formal education.
>> We’re not taken as seriously, and we’re being paid less.
Is this one of those correlation not causation things I keep hearing about?
What a great way to look at this. Author has some really interesting insights into why the PHP stigma exists and the problems that it creates for a (good) PHP developer.
Why PHP is so successful? Well...
"Shantytowns are usually built from common, inexpensive materials and simple tools. Shantytowns can be built using relatively unskilled labor. Even though the labor force is "unskilled" in the customary sense, the construction and maintenance of this sort of housing can be quite labor intensive. There is little specialization. Each housing unit is constructed and maintained primarily by its inhabitants, and each inhabitant must be a jack of all the necessary trades. There is little concern for infrastructure, since infrastructure requires coordination and capital, and specialized resources, equipment, and skills. There is little overall planning or regulation of growth. Shantytowns emerge where there is a need for housing, a surplus of unskilled labor, and a dearth of capital investment. Shantytowns fulfill an immediate, local need for housing by bringing available resources to bear on the problem. Loftier architectural goals are a luxury that has to wait."
Now as to why a facebook would use it? mindblown
PHP7 took a lot of great ideas from Hack but is still saddled with its legacy.
Never remember Facebook having much issue.
It's also stateless - less rope to hang yourself with.
Many web programming environments started with the same simple CGI model, but eventually moved away chasing performance (for the computer), and leaving behind rapid feedback during development time.
hyperdev.com is nice, but it's still way more complicated than a single file PHP app.
That's its best feature and I love it.
It was then just a matter of uploading a few files via FTP to have a working website. .Net deployment, Java deployment were always more complicated and expensive. It was also easy for administrators to deploy Wordpress or Drupal, with next to no PHP knowledge whatsoever. That feature (ease of deployment) was often underestimated by other solutions, until the PAAS era.
Could PHP have been made better language wise while keeping the same features absolutely, but PHP was not taken seriously by people who could have fixed it early on.
And don't start talking about docker... that's a patch/hack to a serious problem, if i need an entire "jail manager" just to run your app then deployment is not as easy as you kins think it is.
Of course that may not be the case if you have some kind of commodity service you have to install in lots of different environments, such as Wordpress.
Incidentally, this attitude is why PHP is among the most popular target platforms among malware writers.
I've made a ton of money doing PHP contracting locally. For my day job, it's been Python, Java, and Go.
Coming from php to golang is insane, you will be very impressed by all the mature and insanely fast tooling.
For example I now have test suite running in about 0.3 seconds, where my last PHP (laravel) app took about 20 minutes testing similar stuff.
Composer is not a new wave but piece of shit which brings old shit-code style with rules "don't touch it while it works" and "legacy code is a good reason for bad architecture".
And Golang sucks too.
The child suspended in the air is wailing about how the whole playground is being totally ruined by the other kid.
The other children watch, bemused, from the other playground equipment, happy that they've grown out of the seesaw; all the parents watch from outside the playground, not caring who plays with what.
I'm overweight and enjoy seesaws. Yay!
And yet this morning I'm earning yet another paycheck digging deep into PHP.
There’s a lot of outdated information on the Web that leads new PHP users astray, propagating bad practices and insecure code. PHP: The Right Way is an easy-to-read, quick reference for PHP popular coding standards, links to authoritative tutorials around the Web and what the contributors consider to be best practices at the present time.
There is no canonical way to use PHP. This website aims to introduce new PHP developers to some topics which they may not discover until it is too late, and aims to give seasoned pros some fresh ideas on those topics they’ve been doing for years without ever reconsidering. This website will also not tell you which tools to use, but instead offer suggestions for multiple options, when possible explaining the differences in approach and use-case.
PHP will still be the most accessible backend language for a long time and only JavaScript stands a chance at outcompeting it for a long time. (And yes I know JavaScript is normally seen as a frontend language)
PHP, Javascript, C, C++, Java. Arguably "great" languages given their success, and each attracts a mob with pitchforks and torches wanting to burn it down.
I would like to see Hack take off a bit more though. The XHP extension alone solves so many headaches with templating. Treating XML elements like first class citizens and having the language be able to reason about its current context, and not having to echo HTML strings everywhere and just hope you escaped everything properly, is something I wish PHP had picked up years ago.
Shit producing daemons suck.
I'm kind of glad I'm very disconnected from the communities and the various groups that handle this stuff, I just write my code and go home. It sounds like thousands of bickering children.
tell me something new
Same for JS.
Many languages (like Go or Clojure) require you to learn quite a few concepts and exercise your mind in general. This automatically filters out incompetent programmers, and puts the rest in the right mindset.
I wouldn't say that it filters out incompetence completely though. I remember when I was writing Prolog for a school project and wasn't familiar with any of its concepts. I ended up writing terrible Prolog that looked a whole lot like the imperative stuff I was used to (wait, comma doesn't mean next instruction?!).
Perhaps remembering that PHP could mean "PHast Prototyper" could help you/your team come to terms with all this?
I've built a static analysis tool for it, and it sort of feels like writing a CAD tool for lego bricks.