> Current solutions like Docker, Sandstorm, Cloudron, command line scripts etc. are "easy" for developers but not for ordinary users.
It sucks that Sandstorm didn't "win". But the implication here is that PHP is easy for "ordinary users". It's not, though. It's easy for a slice of the somewhat technical population at the low end of the technical spectrum. Ordinary people are still left out—and not to mention: susceptible/vulnerable to being lured by the false promises about the "easiness" of the PHP model. Unpatched installs of shoddily written PHP apps (or plugin-laden installs of WordPress) are an undeniable vector for potential security compromises of personal data, spam, and nodes use to coordinate the spread/execution of malware.