That translates to easy access to labor for a lot of companies. If you want a quick web app stood up, you can have your pick between a few hundred thousand hungry PHP devs or the three node.js devs that are currently considering being available for new work.
...'course, a lot of those cheap PHP devs will turn out some horrifyingly bad code, but that's not PHP's fault, and most businesses don't care.
[1]: https://venturebeat.com/2018/03/05/wordpress-now-powers-30-o...
Wordpress powering most of the web is not necessarily a good indicator of the popularity of the language among developers, as the whole point of Wordpress is that you do not need to be a developer to operate your website.
The barrier to entry is very very low (for better or worse), and if you're careful and avoid most of the crazy, you can make really fast , low overhead, lightly dynamic pages. Of course, it also gives you more than enough rope to get yourself into a lot of trouble, and I have feelings about the modern trend of obfuscating things with frameworks and autoloads, but lots of people think they're great.
The barrier to entry is very very low
This, absolutely this. There's literally nothing to configure or setup beyond PHP itself. You open a text editor and write your script, save the file, drop it on the server and it's immediately ready to run. No messing around with convoluted toolchains, massive frameworks, or some elaborate "build process" just to get a "Hello world" to work.
I'm not sure if it's even a majority of users, but PHP certainly appeals to those of us who like writing plain HTML in a text editor and being able to immediately refresh the browser that has it open to see the effects of changes.
The language itself has its warts, but they're easy to avoid and IMHO the disadvantages pale in comparison to the extreme simplicity of getting started and continuing to work.
My company has some legacy PHP stuff that is rock solid, making money for years, survived every single audit (and PHP 7 cut our server costs by half).
Their numbers are huge so of course the number of exploited servers will be higher in raw numbers, but is the core "extremely" exploited or is the plugins the real problem? We should be talking about the language/merits but I'll listen to arguments about the ecosystem. Just feels really dumb to talk about things like plugins. It's like saying JS is crap because 70% of the web extensions written in JS are sold to the botnet or are pure crap. Or how a popular operating system has more CVEs because it's popular. Not sure how to explain better what I want to say so let's just leave at that.
> WordPress also works with PHP 5.2.4+
That's a nearly eight years end-of-lifed version.
Think about a small business with no tech experience that just needs a basic marketing site. They download some cheap Wordpress theme, make it say what they want and upload it. Easy! Digital Ocean would be a disaster for them.
So, presumably for the same reason somebody would do a project in ROR.
Looking around at actual production node code, huge swathes of it could easily be written in Rails, Django, or Symfony with no real loss of performance or developer productivity. (And given the maturity of those ecosystems, probably a net gain in developer productivity. Example: ORMs aren't great at everything, but sometimes they save you a lot of time, and Node doesn't have an ORM that can compare to ActiveRecord, Doctrine, or SQLAlchemy.)
Node has found plenty of use outside of what it was originally built for (the canonical examples are web servers). As far as I can tell, it's used more widely and critically as a tool for packaging client-side scripts or for client-side applications (vscode, electron, Slack).
Examples of places where it seems like node would be an obvious choice, but it's not: blogs (WordPress still reigns), Mozilla's Add-ons (runs on Django [1]), Slack (very heavy user of JS on the front end, but backend is coded in PHP [1]), Zapier [2] (Python backend, though custom integrations are often written in JavaScript)
1: https://github.com/mozilla/addons-server
2: https://slack.engineering/taking-php-seriously-cf7a60065329?...
3: https://zapier.com/engineering/automating-billions-of-tasks/
Even as a giant fan of Elixir, Rails still has a firm place in the "choose for a new project" bucket.
If your goal is an SPA and your backend performance is a concern you’re better off with Go or Elixir than either of them.
If you're an experienced dev, this is a nitpick. But for new users, this is a major hurdle.
Edit: as an aside, I'd rather use Rails or Laravel for an api unless the backend had to be a set of microservices for some reason. Less time writing architecture, more time writing biz logic :).
and when that isn't a concern, a stable well maintained language and framework is good enough. PHP has gone through a seemingly endless stream of vulnerabilities but if you actually patch your stuff then its fine.
for a web service or site, if you set your routes then nobody would see file extensions and would never know you are using PHP, so when you throw on the trendy bootstrap GUI on top, no one is the wiser and it performs just as well.
PHP may seem like an anathema solely because of its correlated and predictable use by out of touch fortune 500 companies that have vulnerabilities and horrible GUIs. But that isn't the fault of PHP.
Personally, since .NET Core 2.1 (latency dropped and the performance is phenomenal on Linux), which is a pleasure to write for, deploy with and very stable, I do not look too much at other things.
Of course you got downvoted (I have never used PHP but I also downvoted you) simply because you do not say any reasoning on your claim and thus there is no value in your comment.
Nice edit, by the way.
Also, Laravel is miles better than Rails.
I think any of the little dynamic programming langs like Ruby, Node, Php, Python are more about the builder than the tool
To answer your question, it doesn't really matter at the end of the day.
There's tools in every web language to do just about anything you need web wise. A competent programmer can switch between OOP langs and in a week or two be writing proficient code.
Really it all comes down to preference at the end of the day in the dynamic OOP web world.