An Internet of PHP
timotijhof.net
timotijhof.net
> PHP is used by 77% of all the websites whose server-side programming language we know.
I had a quick look at the methodology section, but it’s not clear to me how accurate this data is. Determining whether a site uses PHP can be relatively straightforward (especially with default extensions / if Wordpress is used / etc), but if a site (potentially using a different language) is behind a reverse proxy/uses an API/etc then it is less clear. Does anyone know whether PHP is over-represented in the results because it’s easy to identify?
No doubt PHP is still huge, but 77% seems almost too huge. There is also a very good chance that PHP is actually that big and I’m just in a different crowd.
The conclusion has no coherence to the source.
I guess that most of the web runs on PHP (because it runs on Wordpress) if counted by page-view. But I'm not sure that's the proper measure.
Wordpress and similar CMSs, e-commerce platforms, and the Laravel framework give themselves away in other ways that take more work to hide. Likewise non-PHP back-ends have easy to see fingerprints in the headers and page source. There’s no reason to think PHP appears to dominate because crawlers can easily identify PHP but can’t identify other back-ends.
Banks and large companies with large COBOL code bases mainly maintain their legacy code, they don’t write a lot of new code in COBOL or RPG. And you won’t find COBOL powering web sites, which makes the argument irrelevant to the topic. The last time I worked on a big legacy back-end I was putting a web front end on it, using PHP and ColdFusion.
I think we should stop using these numbers. GitHub uses ruby on rails but we know it from the developer team, not from what the server tells us. How many websites communicate about their backend infrastructure?
I don't doubt Wordpress powers many websites out there. But I'm tired of these figures which don't mean anything to me. Especially that if you look for all job ads, PHP isn't so big (except in some PHP-centric countries like France).
You can't just make up numbers. If you give me statistics, give me the methodology you used and all the details. Otherwise I suggest we all start saying Haskell powers 87% of the web. After all, if you can invent what suits you, I can do the same.
Multiple independent surveys of web back-end technologies by different outlets, across many years, have reached the same conclusion: PHP powers approximately 3/4ths of public web sites/applications. I do a lot of PHP work and I see PHP used heavily in restricted/private web applications as well -- internal sites that won't show in these kinds of surveys. One school I work for has one public WordPress-powered site and several internal-only WordPress sites, and multiple internal PHP-powered sites not based on WordPress, including Moodle (learning management system) and their student management system.
The large ecosystem, relatively large population of experienced developers, and ease of deployment play into the decision process. Sometimes it comes down to hosting costs or other non-technical factors.
Deducing the number of jobs for PHP developers based on job ads will mislead you. Most jobs get filled internally, informally, or by recruiters before they get posted online (because that costs). If you don't see a lot of ads for PHP developers that might mean few jobs exists (which wouldn't match the experience of anyone who works with PHP). It may also mean the jobs got filled before the employer has to pay to advertise the job. A position for a 5+ yrs experience Elixir dev may sit open for months, but I can and have filled PHP dev openings in a few days, from a large list of applicants acquired by a free posting in a local PHP user's group forum, without having to post in public job forums or do LinkedIn email blasts.
We should also consider that web developers with more than a few years of experience have likely worked with multiple tech stacks, and those of us with 10+ years very likely cut our teeth on PHP. I started in the '90s with ASP and ColdFusion, with some Perl, and then saw employers move to PHP (and a few to Rails a few years later) mainly because ASP (which predates .NET) and ColdFusion required increasingly expensive licenses whereas PHP did not. Among experienced web developers you will find many/most of them have worked with PHP, and could work with it again, though they may prefer something else. Likewise I know COBOL and could fall back on that if more interesting work dried up for me, but I don't call myself a COBOL developer or look for jobs in that space.
I still think the stats they provide are a bit weird since there is no "unknown" category. If they can't find the backend technology used for 5% of websites, it changes the whole result, and from what I have seen they don't provide this information.
But your really nice and detailed answer tells me I might be wrong once more.
Using your 5% example, supposing that 5% unknown includes no PHP sites, that only brings the PHP percentage down a little. It doesn’t change the main point that PHP dominates by a wide margin.
Some technologies seem to give more tells than others. Which means some technologies could be way more invisible than others. I am not sure we can suppose the known and unknown technologies have the same ratio.
I quickly checked some websites with BuiltWith and Wappalyzer and from my personal totally unscientific and small sample data, they seem to detect more easily PHP than other languages like Python.
Again, I don't know. But I took 5% to be optimistic. It could be 30% or 50%. And then the whole picture changes.
Edit: Funny thing, it even adds PHP to some sites I know (almost for sure) don't use PHP. Like GitHub using Ruby (true) and PHP with Drupal (???).
No need to speculate about how it works.
tl;dr A lot more than looking at Apache headers or WordPress meta tags.
- WordPress - Joomla! - Magento - Moodle - Zend Framework/Cart - Laravel - Symfony - Open E-commerce
If you count all the websites using one of the above items, you will come up with a huge list of websites.
And way too many Academic sites are running on PHP.
The LAMP oder LNMP Combo (nginx instead of Apache httpd) is strong.
That number doesn't surprise me.
Also I want to point out that almost any time people quote number about PHP's popularity, this is the only number, which is strange -- for metrics like iOS market share you can always find multiple numbers from multiple sources which don't fully agree with each other but are within a certain range. Not for this PHP number. In other words, w3tech's number is not cross validated by any other source. I wouldn't use it to "prove" anything.
Whether PHP runs 77% or 69% of public web sites, how does that offend anyone or make them feel insecure? No one is trying to "prove" anything, there's no race to the one ultimate tech stack that requires winners and losers. You can accept the fact that PHP objectively runs a large majority of public web sites without interpreting that as a threat to your choices, your job, your image of yourself as a professional.
Having so much PHP out there may look like a problem, but programmers attaching their ego and identity to languages and tools and frameworks accounts for a lot more wasted time and crappy code than a popular language that has some obvious and well-known flaws.
I run a couple of services that are accesible through an API built in Symfony (PHP), but the data is generated with software built with JS (event driven -> lambda, cloudflare workers), Python (depending on GDAL mostly) and also PHP.
I agree that it's an interesting challenge to try to determine which language a large number of sites are using for the backend, or at least it would be a challenge in some small but maybe not insignificant percentage of cases. And no doubt whichever way they solved it involved compromises.
But that by itself doesn't give us enough information to draw conclusions about accuracy.
How much revenue generation occurs on PHP? I'll cede the argument about the e-commerce platforms and CRMs, but I'm just not convinced that PHP is where a budding developer should be focusing their efforts. You enter the business/corporate world and there are tons of applications out there running the world, not just websites. Those applications are predominantly written in languages like .NET, Java, JS/ECMAScript, Python, Rust, and Go. Also, among the managed languages like .NET/Java/JS the knowledge is quite transferrable and sometimes almost identically named.
I'm not trying to bash PHP as a language, but every time I see this argument it's the same. Evangelizing PHP also seems to come with a requirement to mention Wordpress, Wikipedia, and Facebook. I'm sure there's money to be made in PHP, and I'm sure it's a great language for the internet. But learning .NET or Java is likely to have a much larger window of opportunity. Also, if you have a specific industry you want to work in you should be looking at the language predominately sought after in that industry.
I think this is why a lot of developers bash PHP, it's not that it's a non-valid choice. It's that it has limited applicability. I would never advise someone to learn PHP as their first language.
It wasn't the language, it's everything around it. It's knowing frontend and how it works, it's knowing about cloud/operating systems, databases, 3rd party integration, IAM, SSO and the list goes on.
These skills are applicable everywhere, next to any language. Compensation I was offered revolved around the ability to be non-invasive towards younger teammates and to provide education with emphasis on critical thinking. During the years I've done this job, I learned other languages as well and I can safely claim that initial language one learns has huge impact but it's learning additional skills that makes up for a valuable employee.
In the end, knowing C# but not knowing PHP bears little insight into whether you're capable of listening about a requirement and coming up with a solution that satisfies the need, code it in such a way code can safely die one day and make in such a way that additional people in the team can jump in and manage it.
I also found a lot of job offers and opportunities. My previous engagement was insurtech/fintech, there's quite a bit of PHP used there (and it works well).
Wordpress, Magento, Facebook - these aren't the only places where PHP is/was used, the world we don't hear or read about is larger than the blogo-investo-googlesphere we're used to reading about.
No. What I said was that language was not as relevant as the complete engineering ability that makes someone a valuable (financially viable) employee.
> but smart/good developers will find that CV/Salary pressures steers them away from PHP
I never met a person who entered world of IT with the criteria that you highlighted there. My recent experience shows that people enter IT/development based on salary alone, not based on research they conducted taking into account industry they'd work in, language features etc.
If this case you wrote of actually existed, world of software would be a place of much more high quality software and not of "it barely works" projects that resemble Frankenstein's monster.
My experience in London/UK market is that offered salaries are based on market rates based on keywords including tech stack. And I know a decent number of competent developers who deliberately moved away from PHP because of the lower offered salaries. It might just be the local ecosystem which imo doesn't really value engineering roles in general
I was more focused on where I think one's energies early into their career should be directed if they want the best chance at advancement and integrating those solutions in the corporate space. Yes, those solutions are integrated in PHP for various projects, but not as often in the applications that are running your day-to-day corporate operations.
I've used and developed in PHP for many web projects. I've used and developed in .NET/MVC and Java/Tomcat for many web projects.
I've used and developed in .NET for many desktop/server/infrastructure projects. I've used and developed in PHP for a single infrastructure project, some custom development for pfSense integration (which was horrifying, running as root, hodgepodge scripts).
Objectively, the evidence I've seen, appears to indicate that a developer with skills in any other mainstream language has more opportunities for employment and a greater salary.
The majority of sites may well be in something else, and the majority of things that people will pay you to code may be behind a login page.
Still seems to be most popular in France, doesn't appear to be dying off there... Interestingly it's gaining popularity. Curious why that would be.
I saw a video not long ago that made me have hope for the future of PHP again -> https://www.youtube.com/watch?v=ZRV3pBuPxEQ
PHP has indeed ranked close to the lowest in average salary in StackOverflow surveys for years. The amount of templated thrown-together solutions for the exact same site as yesterday with different branding vs. custom solutions probably is the root of this.
Honestly, anyone that blindly criticizes or dismisses php these days, is a big red-flag for me.
People googling for solutions will get 30+ year old "advise" on how to do certain things / use certain libraries etc.
Especially StackOverflow should be incorporating a major version number for which the question is valid.
So yes, "PHP is still dead" as long as you get the same old advise.
https://meta.stackoverflow.com/questions/405302/introducing-...
It’s better to have the same question in a new era. The version info should be in the question. The question has either been answered or not, but it’s not relevant anymore for the original poster.
Only if it really is, you could add a new major version to it to indicate compatibility
Questions are often timeless. The answers change and SO shows them all with their timestamps ordered by its best guess at which will help you, the reader, not the original poster.
Did you mean standard, as in HTML5 or ES6? Or something more like a fashion or fad, like FP or OOP (which PHP has had for a long time)?
People ask the same old questions about PHP on StackOverflow et al. because a lot of people start with PHP and as beginners they will have the same questions every beginner had before them, and the same lack of ability figuring things out themselves or finding their questions already answered. That has nothing to do with PHP per se except that PHP offers a very easy on-ramp to getting started with web development, so a lot of newbs start there.
If you look at the W3Techs methodology, posted on their site for all to see but apparently few to bother with, you will see that self-hosted hobbyist and learning projects aren't going to make it into their results.
MS didn't change, they still exploit as much as they can.
And they try to force people people into the cloud unable to secure their own software stack.
MS didn't get better just because Google got worse.
Well, that's like asking me if I wanted a recreational root-canal, so I answered "no".
Boot into the OS, and the task-menu-bar-thing is spinning with X-box ads and all sorts of other crap.
I dispensed with that shit immediately, and gained a nice little extra disk-space for my /home dir.
As someone who was on the whole pretty pro Microsoft for the past several years, 2022-2023 was when I started 'hating' Microsoft again. Both today me and year 2000 me would agree that 2020 me was completely wrong about giving Microsoft the benefit of the doubt.
> What other values from the 9/11 era do they hang on to?
I'm still into taking care of my family, being honest with people, being nice to people, even if they are not nice to me, and I still like a good single malt whisky.
There's still an insane amount of money to be made with WordPress plugins, WordPress support, and more. That industry isn't dead, it's thriving, it's insanely cheap to jump into and not get yourself into debt, and there's tons of people that need help.
While people here argue about the 10th "correct" way to do server-side rendering (hey, React says we gotta use RSC now!) or figure out how to get their Rust code to compile to WASM for their Codepen demo website to increase a number from 1 to 2, thousands of us churn away daily making money from this "dinosaur" PHP in the real world.
The bias on HN makes you think PHP is completely dead and it's funny to see the comments here.
And because so many people make real money off of it, there is a focus on making practical things. Hackers who are looking at doing their own startup, might want to try out Laravel and it's ecosystem.
I think its strength is its architecture, namely shared-nothing state and concurrency at the web-request level. [1]
xdebug, while it works, also feels antiquated. Trying to get it working in a new system or project can take quite a while. Again, compared to python or node's debugging experience or profiling experience, and it feels like something stuck out of the 90s.
Even just getting output from php is difficult for me. Maybe it's because of the webserver I'm using? But python, elixir, node, go, etc, all output logs to stdout while running a local service. Maybe that'd work with the built in webserver, but fpm or modphp, etc, it seems like you have to hunt down logs.
Not to mention that the dev servers almost always require a full apache or nginx setup just to function. Opposed to a node, elixir, python, or go server which all run directly from the directory you're in. (Including things like hot/auto reloading in node and elixir)
I'm not a full time php dev, but my time in php always feels like a grind, and just getting tooling working is not an easy thing. If I'm missing some state of the art alternatives, I'd love to hear them though.
What would you do if HHVM didn't even exist?
Admittedly PHP has had recent performance gains, but by no means would it ever be a first choice in any backend service architecture.
What would any of us do if some innovation never happened? How does Facebook committing heavily to PHP and then giving back in the form of performance enhancements somehow tar PHP as crap? What language or framework with any longevity didn't have something like that happen? Is Javascript crap if not for Typescript, or V8?
You may not make PHP your first choice but plenty of businesses and developers do. If you can point to some actual reasons no one should choose PHP, or widespread failures due solely to flaws in PHP, go ahead.
> Admittedly PHP has had recent performance gains, but by no means would it ever be a first choice in any backend service architecture.
Other than at Yahoo, Facebook, ...
Don't get me wrong; PHP has issues. But it's very mature; it's fast; it's easy to learn; it has a very diverse and rich ecosystem; it's easy to debug; and in general, it's very useful for building reasonably efficient and performant scalable web services.
If you're referring to the Slack article, it is a bit out of date.
PHP has since added stronger typing and better performance. I don't think using HHVM is very popular.
Every other tech, it's complicated servers or complicated billing, not to mention depencies and build tools.
thats why php
If I had to guess, this person committed their .env file in some repo and pushed that up, and that become available because the server was misconfigured.
For other servers (such as, say, Jetty), config files like that won't get exposed like that unless you're very obviously placing your config files in a public resource folder.
Every other language acts as its own web server which wouldn't even be capable of serving files even if you tried; the only thing it does is respond to web routes defined by the application.
This eliminates a whole chunk of security issues, from the one described above to malicious file uploads (PHP is probably the only language where a malicious file upload leads to RCE by default - other languages could happily accept and serve the malicious file back but wouldn't execute it).
A non issue though after 2-3 days of working with this approach. All modern PHP frameworks have a so called front controller (an index.php file) that loads what it requires from ../ after, ideally, properly validating the request to avoid issues.
The only way to avoid to have the server open only to you till everything is tied down right and the backend is ready to face the world.
To rely upon being quicker on the draw than the bots is quite courageous.
Keep a shared host secure, PHP or something else was not an easy task, most people installed unsecure versions or misconfigure something.
Also it was a pain to support PHP versions after EOL (yes, money), and multiple versions .
When you extrapolate that to modern tech, you could create a shared hoster with a configured reverse proxy and per customer docker images.
But that is so much expensive to build, operate and bill than an apache. And looks very close to AWS and friends.
Not with CGI.
Thanks to cPanel (written in Perl) this make life easier for developers to set up websites and skipped the ceremony but why is cPanel written in Perl instead of PHP?
But Go language has it own security implementations which are more secure and easier to deploy as a static binary. I did tried to write entire Go app using only built-in or some dev use Chi for routing. I didn't have to install Go runtime on VPS that you need for PHP.
Go built-in HTML template is quite secure, rare seen some fix to html/template make it easier to deploy new app, but our website has evolved with Astro web framework that require NodeJS since none of the server side language can solve client-side issues.
> the advantages of the PHP environment (reduced cost of bugs through fault isolation; safe concurrency; and high developer throughput) are more valuable than the problems […]
The "high developer throughput" is really what does it for me.
I remember vividly when I started at Amazon (where PHP is forbidden) and we were spending days building a single relatively basic CRUD endpoints in Java (with Hibernate, that sucks for non-trivial models), I was constantly thinking "this would have literally taken 1 minute and 5 lines of code with Laravel".
You want your whole team to become 10x developers? Switch to PHP.
Between the simply incomparable frameworks that do absolutely all the work for you and the fact that a simple instant page refresh shows your changes, productivity is multiplied.
And I've never had to deal with ESM/CJS/AMD whatever module nonsense with PHP. No transpiling anything, just edit and refresh. And so many useful functions out of the box (array_column anyone?).
I think its bad rap comes from its ubiquity. Pretty much any existing website I've had to work on has been a putrid mess. That's just the way codebases go unless you're a SaaS with a CTO who's hell bent on preventing that.
And since most of these putrid messes have been based on PHP, due to it's age and ubiquity, people blame it, due to observation bias.
I do actually pick it for several reasons.
1. I want to know if the environment I am going into is pragmatic about languages. If you are going to refuse to continue working with me over something so minor as PHP then we aren't a culture fit.
2. I want to showcase my best. I know this language in and out. It's the first language I learned and I have the greatest ease of building algorithms with it. I've had interviews where I was asked to do something with PHP that PHP did not support and I found ways to make it work.
3. In some ways I love the conversation that comes with positive interviews when using it. Oftentimes the interviewer isn't very familiar and it sparks discussion on the languages benefits and drawbacks further showcasing my skillset.
Sure as we progress along in the interview process I will switch to whatever language the company uses primarily but if I get a choice I always choose PHP.It's also the thing I'm best at!
They cherish their languages but are not fanatics.
In the grand scheme of things, talking solely about software projects not life in general, it kind of is.
Most modern languages, are interchangeable, and projects of most kinds have been done with all of them succesfully.
As long as the programmers for the chosen language are available, and the libs you want are there, for startups doing some web backend for example, it doesn't really matter if it's Python, Ruby, JS/Node, PHP, C#, Go, Java, CL, Kotlin, Clojure, and so on.
My go to for this is to say "I don't think Typescript is needed most of the time". The snobs look at you like you just farted in their face.
But having done some coding interviews where time and space complexity were a factor, I found it easier to succeed with Python.
This is a terrible example, typescript (especially in 2023) is basically free with most setups (including vanilla) and easy to ignore for velocity then optionally enforce typechecking later.
A much better hill to die on would be large frameworks/tooling like react/angular/webpack.
And yet people seem to keep inventing variations of this as "templating" languages.
We would have seen dramatically fewer bugs and injection attacks over the years if PHP had made <input value="<?=$value?>"> a perfectly safe and normal thing to write back in 2005.
This has been fixed in PHP 8. https://wiki.php.net/rfc/string_to_number_comparison
That… makes it even worse.
And yet people would take a bullet for React and the JSX templates.
I was so confused when I heard that, "like... a HTML file?".
Keep going at this rate and we'll be using frames again.
Serving a static HTML file is not server-side rendering.
It's much dumber than that. The people advocating for SSR want the server to respond with HTML generated based on whatever is in the request.
That’s pretty much what htmx is…
The ability to mix html and code means it’s extremely easy to get started which is the big strength.
You don't hear too much about it. You almost never notice it unless you're actually looking for it, unlike McDonald's with its ostentatious golden arches.
It's popularity is waning. But it's still everywhere. [0] There are a hundred other sandwich chains that have tried to do it better but none have managed the ubiquity of Subway.
People like to look down on it and espouse the alternatives, but when it comes down to it fast food can only ever be so good.
I guess that means that JavaScript is McDonald's?
[0] https://en.wikipedia.org/wiki/List_of_the_largest_fast_food_...
I don't think that applies though. If anything, laravel is pushing PHP into another "golden age" not seen since code igniter 2, with again a framework that does things not quite how they should be under the hood, but definitely how people need them to be to be fast and efficient, except this time backed up by a proper package management system, a much better and stronger language and an ecosystem based on reusable modules.
Does it have the favor of the modern hype or new language seeker or anything like that ? No, absolutely not, but when has PHP ever had that ?
Of over 100 I have only heard of 1/3: 35 in total.
I have only ever been into and eaten anything from half of those.
So fully 2/3 of the list I've never even heard of. Interesting.
My first reaction to this was that it's actually very accurate insofar that I genuinely wonder how one can like either of these and why they're so popular. At least JavaScript has the obvious excuse that it's the only thing that runs in a browser, so it's still more logical than the popularity of McDonald's.
No idea how recent PHP is. It's hard to escape those opinions that formed fairly widely in the industry is, though.
Once the file is on the filesystem, it's deployed.
Each invocation to run PHP is stateless and it parallelises effectively. (There's no communication, synchronization between PHP instances.)
* php.ini * php extensions * hardish deploy needing a specially configured web server * huge number of terribly named builtins * functions returning int|bool|null|whoknows * $, -> * cant trivially dockerize * laravel wants me to install even more crap other than Apache phpfpm php composer artisan sail larathis larathat so he can buy the second lambo by copying rails and django * xdebug
And i just go on my merry way. Php devs forgot the mountain of quirk and bullshit they internalized. That’s the same reason I’m starting to hate python
Last I check a few year ago Java is the only other platform with as good ICU integration, and nodejs has BreakIterator but not Transliterator. Other platform require complex setup to install ICU as a third party library.
Also listing language usage by what’s returned in server headers undercounts languages used on some of the biggest, most popular internet properties.
Sites like Amazon, TikTok and YouTube/Google consume a lot of our total attention, but they tend not to report their backend server languages in response headers.
If you shift from raw numbers to where people actually spend their time, I doubt PHP would be at the top.
On one hand I'm almost positive that someone who's made the transition from PHP to Hack would point out that it's way more cumbersome to switch than you're making it out to be but on the other I have no personal experience with it and I would assume that set is small enough where we might have issues finding one to inform us here.
It is not a surprise that PHP is running the web. That's because WordPress made sites/e-commerce accessible to the average Joe. Despite the massive security issues with these setups, it has enabled a large number of people to run businesses.
But if you are a software developer, I'd strongly advice you not to do PHP.
Now I look back on PHP3/PHP4 with disgust. Globals, function names, massive pieces of code right in the middle of HTML, shell_exec.
And they're not inherently bad.
PHP made the internet fun. Anyone could get going with a PHP enabled host with by creating an HTML document starting with <?php> and have a working something that the world could see by end of the day.
Today's web development feels like such a drag. In that you need to choose the scaffolding, create the scaffolding, wait for the concrete to dry, drill holes for the infrastructure and then construct the infrastructure.
When you then go to connect the infrastructure you find that one of the girders has buckled which requires a patch-up or refactor. Someone's misprinted the blue-prints and the cable ferret has gotten lost down one of the connectivity holes. You then discover that a new scaffolding company has come to town so your construction is now obviously out of date.
PHP enabled you to have something cool in days. Nowadays you spend days just trying to setup react. my two cents.
I don't do PHP work much these days (permanent "working from home" made me not want to do any extra work from home after hours), but it felt incredibly productive compared to the more modern tech I've seen in my day jobs. There's a lot of crap to wade through nowadays. A typical small project might have a React front end, Python back end, REST API's, documentation, cloud deployments, on-and-on. Web development isn't fun anymore.
I owe everything I have to Rasmus and his beautiful "shitty" language.
I had a similar "simple counter" moment at a later date and the tech was AJAX. I am yet to have a similar moment after that. Perhaps WASM based interfaces? But it's not the same. Maybe I am not the same.
There are lots of industries that are lucrative, but there's clearly no linear correlation to quality or societal benefit.
I think PHP did make the pie bigger, but there won't be shortage of companies who used PHP to only take a bigger slice.
The state of JS is maddening, whoever spit on PHP but love JS will need to explain why an hello world from create react app has 800 dependencies in the node_modules, why do we keep using babel when most browser is already supporting es6 fine and why do we have some many way to import modules. PHP had its issues which got fix over time but we can't say the same with JS.
Dude, Node is as broken as PHP. And it starts from having no standard library leading to hell like leftpad and general software supply chain holes that PHP never had in the same quantity.
It isn't clean. Node was just shinier and had more applications to leveraging it for a shiny frontend.
With node.js or java spring boot i can build an application with an http endpoint and create a single docker image with all included easily.
With php I need 2 distinct containers, e.g., nginx, php-fpm and the code mounted on a volume to the the containers. So it seems to be more difficult for setup and continous integration etc.
I would like to have one image with php, a webserver and the code. Is there something like that for PHP?
FROM php:7.2-apache
COPY src/ /var/www/html/
and this is it.There are real application servers using an event loop by now, most notably Roadrunner (https://roadrunner.dev), FrankenPHP (https://frankenphp.dev), Laravel Octane (https://laravel.com/docs/10.x/octane#introduction), Swoole Bridge for Symfony (https://github.com/insidestyles/swoole-bridge-bundle).
In general, you can do a lot with OpenSwoole or Roadrunner. They are vastly superior (in a container scenario) to any other suggestion in this thread!
[0] https://github.com/docker-library/php/blob/1c4b255f3e5ab610c...
People use Apache or nginx because they want to, but because they need to.
Unfortunately it has some really opinionated routing rules with certain file extensions, preventing you from having a dynamic URL with something like a .json or a .xml extension. Instead it will always try to look up a static file of that and serve it instead.
I can’t find the bug tracker issue for it but it was closed out with a message along the lines of “don’t use the built in web server for anything besides a toy”.
Luckily there are plenty of PHP Cli based web servers now that some other commenters have mentioned.
Warning: This web server is designed to aid application development. It may also be useful for testing purposes or for application demonstrations that are run in controlled environments. It is not intended to be a full-featured web server. It should not be used on a public network.
In my case, the Dockerfile looks a bit like the following:
# Whatever base web server image you want, Debian/Ubuntu based here
FROM .../nginx
# Bloated packages for installing dependencies and also Supervisor
RUN apt-get update \
&& apt-get -yq --no-upgrade install \
software-properties-common \
supervisor \
&& apt-get clean \
&& rm -rf /var/lib/apt/lists /var/cache/apt/*
# Add repository for PHP 8
RUN export LC_ALL="C.UTF-8" && add-apt-repository ppa:ondrej/php
# Then we install PHP and the Nginx integration package (we use PHP-FPM)
RUN apt-get update \
&& apt-get -yq --no-upgrade install \
php8.2 php8.2-common php8.2-cli php8.2-dev php8.2-opcache ... php8.2-fpm \
&& apt-get clean \
&& rm -rf /var/lib/apt/lists /var/cache/apt/*
# We will also need Composer for managing dependencies
RUN curl -sS https://getcomposer.org/installer -o /tmp/composer-setup.php \
&& php /tmp/composer-setup.php --install-dir=/usr/local/bin --filename=Composer
# Create directories, clear regular web server index directories
RUN mkdir -p /run/php \
&& rm -rf /var/www/html && mkdir -p /var/www/html
# Copy over config (whatever you have)
COPY ./php_nginx/etc/nginx/nginx.conf /etc/nginx/nginx.conf
COPY ./php_nginx/var/www/html /var/www/html
COPY ./php_nginx/etc/supervisord.conf /etc/supervisord.conf
# Copy PHP config (whatever you have)
COPY ./php_nginx/etc/php/8.2/fpm/php.ini /etc/php/8.2/fpm/php.ini
COPY ./php_nginx/etc/php/8.2/fpm/php-fpm.conf /etc/php/8.2/fpm/php-fpm.conf
COPY ./php_nginx/etc/php/8.2/fpm/pool.d/www.conf /etc/php/8.2/fpm/pool.d/www.conf
# Default run script
COPY ./php_nginx/docker-entrypoint.sh /docker-entrypoint.sh
RUN chmod +x /docker-entrypoint.sh
CMD "/docker-entrypoint.sh"
Here's the entrypoint: #!/bin/sh
echo "Software versions..."
nginx -V && supervisord --version
echo "Running Supervisor..."
supervisord --configuration=/etc/supervisord.conf
Here's a snippet of nginx.conf, how to get *.php to be executed (put inside of a server block): location ~ \.php$ {
include snippets/fastcgi-php.conf;
fastcgi_pass 127.0.0.1:9000;
}
And here's the Supervisor configuration: [supervisord]
nodaemon=true
[program:php-fpm]
command=/usr/sbin/php-fpm8.2 -c /etc/php/8.2/fpm/php-fpm.conf --nodaemonize
stdout_logfile=/dev/stdout
stdout_logfile_maxbytes=0
stderr_logfile=/dev/stderr
stderr_logfile_maxbytes=0
[program:nginx]
command=/usr/sbin/nginx
stdout_logfile=/dev/stdout
stdout_logfile_maxbytes=0
stderr_logfile=/dev/stderr
stderr_logfile_maxbytes=0
Of course, it isn't necessarily the most idiomatic way to work with containers, but if you have health checks then it should still be fine. With a base image a little like this, you should then be able to build your own images with the code included, or use a bind mount. You can probably get images that work a bit like this pre-made, this is just how I do things, in case you're curious about what that might look like from scratch. Apache also has mod_php which would be even simpler, though generally will perform worse than PHP-FPM.Curiously, this is also one of the few detriments of PHP in my eyes - when compared to something like Java that just spits out one .jar that can be run on anything with a compatible JDK version (at least with how things are done in the recent years vs standalone Apache Tomcat).
I'm a big fan of trying out different stacks, and I think a lot of people would love Laravel if they tried it. Give it a shot using PHPStorm and Laravel IDEA (free trials for both), and see what you think. Can't hurt.
They add a layer of complexity over the top of PHP such that instead of learning how to write PHP, you need to learn how to write the framework.
Let's take an example right from Laravel's homepage:
Authenticating users is as simple as adding an authentication middleware to your Laravel route definition:
Route::get('/profile', ProfileController::class)
->middleware('auth');
Once the user is authenticated, you can access the authenticated user via the Auth facade:
use Illuminate\Support\Facades\Auth;
// Get the currently authenticated user...
$user = Auth::user();
As a developer, looking at that code tells me nothing. WTF is the "auth" middleware? Where is it configured? What's it doing?Then we come to `Illuminate\Support\Facades\Auth` - another meaningless string with a seemingly arbitrary name. WTF is "Illuminate" and why is it in my code? Why do I need it to authenticate users?
So I have to go and learn all of this crap before I even begin to understand what the code is doing. And for every other thing I want to do with the framework I need to look up how to do it "the Laravel way".
I personally have a large prject with a ton of code that was written in the last 16 years from when I was very inexperienced to now. After a while you realize that patterns are important, and you start building more and more features to make development and maintenance simpler and faster.
Here is a list of things I created over some years for that project: - Authentication system that supported different types of login. - Pretty routes. - Simple dependency injection container. - Emailing. - A templating system. - A scheduling system. - A worker pool. - Reusable forms. - Simple DB migrations in code. - Caching system. - A file storage system. - Data seeding. - Testing. - Websockets. - Asset bundling and versioning. - Localization. - Payment integrations. - +++
Sure, I could do it the JS way and find different packages instead of doing it myself, but I don't want to rely on a bunch of projects as that quickly can become maintenance hell.
After a while you realize that you're basically reinventing the wheel. Is Laravel and Somfony complex? Yes. Does it sometimes seem like magic? Yes. Is it hard to use, modify or figure out how it works? No.
You might not know why 99 % would want to use them, but I'd agrue that most probably should when the project achives some complexity. That way you can reap the benefits of the work and experience of thousands of contributors behind these projects.
I am one of those "I want to know what happens in the background" people too, and it's not that hard to figure out how Laravel works if you want to know. But most developers are not interested in how the framework they are using really works. The questions you have about what the auth middleware is, how it works, and what the Illuminate namespace is for(Laravel) is easy to figure out by checking the docs.
Laravel is definetly an opinionated framework, but personally I think most of the options are good ones.
To be fair, you could say this about many frameworks in many languages; Ruby on Rails is the first obvious example of this.
Not to say it's bad, but even with some experience, I couldn't grok it.
If you just need to do one simple thing, don’t use a framework :)
If you need to lots of simple (or complex) things, in an organised manner across a single project, Laravel is great!
(Having said that if you have an example of what you were referring to, I’d be curious)
Is that a fork of IntelliJ or did they just usurp the “IDEA” branding from JetBrains?
A framework-centric IDE seems silly. Like mini cupcakes.
Anecdotally I see also rude health: Wordpress already has an activitypub plugin whereas symphony based kbin is a very interesting proposition for a federated alternative to reddit that already sees traction. And Nextcloud is delivering data sovereignty and showing the way for personalized "clouds" here and now.
What is missing from PHP is really an easily communicable "story". Both at the technical level of the language and its tooling and at the community level and its vision.
This is not unique to PHP. Older ecosystems like C++ and Java, on which much of the world still runs, have a similar problem. But the singular web focus of PHP means it has more of chance to develop an attractive personna.
Its not easy but its very useful to have a very clear identity. Right now the tech world goes through an ML/AI fever (and associated nightmares) and a clear vision and purpose would, for example make it obvious how the PHP ecosystem fits into new developments and the broader client/server design.
Fearless concurrency with actor model
Slack migrated to Hacklang in 2016 [1].
[1] https://slack.engineering/hakana-taking-hack-seriously/ "We started migrating to a different language called Hack in 2016."
I understand PHP is fast adding any actual language features that Hack has over it?
It was too sweet on effectful code around random maps (what's not to like, you can do whatever and spend hours trying to find the right combination of stdlib array_ functions until something happens).
Of course things change after the nonphp6. But if someone only knows and love php I'll check twice before working with him. I'm actually dealing with someone like that right now.
So culture is a plus thing. Because the technical mishaps are there in any community with size (looking at you JavaScript)
Take, for instance, the PHP environment around the time the "a fractal of bad design" (https://eev.ee/blog/2012/04/09/php-a-fractal-of-bad-design/) article was published — which also coincides with the last time I worked professionally with PHP. During that period, PHP was plagued with inconsistencies, a tendency to hide errors, and insecure default settings, all of which encouraged writing bad, unmaintainable, and insecure code. Those aspects truly matter.
I write C++, Rust, Python, C#, and JS in various capacities both personally and professionally and I always go to the first language I learned whenever I want to prototype, PHP.
That said, I agree with the sentiment you are expressing. If the app works, and people enjoy using it, the underlying language only matters to other devs who might work on it and that is it.
PHP is also the one language whose choice can make an impact on users' experience, since its shared-nothing (sans caches) runtime model is almost CGI-like and can, in my experience, lead to higher latency, as each request simply does more. Maybe some experienced PHP devs can tell me how they combat this?
Additionally, there are several application server strategies, sometimes with a process manager that keeps preloaded request workers at hand, sometimes hosting an event loop, and sometimes a request worker that gets partially reset after handling requests. This yields performance comfortably comparable to optimized Node.js apps.
In general, PHP has a highly optimized runtime, and we didn’t even really touch caching yet. Trust me when I say performance is not one of the problems PHP poses :)
I mean, you kind of answered your own question - they use caches like apcu or memcached. Apcu is just shared memory so its basically ends up being very similar to languages that don't do shared nothing.
That said, how good or bad a language is might not be quantified or qualified to a point where all audiences are happy. How it's used vs how it's structured, where it's used vs. how much money it's making can all mean different things to different people. If you look at it from an academic (CS) perspective it might not matter how much money it makes if it lacks some scientific nuances. But the same works the other way around as well; it doesn't matter how cool COBOL, FORTRAN or lisp is if you can't run your massive eCommerce web app with it (there is a joke in here somewhere).
For example, Erlang is painful to adapt to, but in some cases (example: if you build a Messenger app) it will be the best.
It doesn't mean that Erlang is a bad language at all, it is designed for a main purpose in mind.
It's normal to see junior developers and low-quality packages in PHP, JavaScript, Java or Python, it's because these languages are well-documented and rather accessible.
There is no point in making a language needlessly complex.
Which is literally what the article said.
Most of these fanlistings (and also the massive number of forums running on vbulletin and phpbb in the early 2000s) were created not by software developers, but people who had a passion. It was a road that a lot of people, especially girls, took to get into software development. I think that gender parity in software development might have hit a record high during that time.
Comparing to PHP, modern frontend is the true mess still though, there was never a simple to use SPA frontend in existence, they're all complicated, over-engineered and changing too fast to me, and now they are even adding what PHP was good at(SSR), frontend is the problem and getting even worse to me. The backend, be it PHP-laravel, Ruby-rails or python-django, even node-express are an already solved problem, the frontend framework folks adding SSR into frontend frameworks are simply insane to me.
NOTE I'm not against SSR, what I dislike is that they add SSR directly into an already over-complicated SPA framework, which will kill itself under its own weight soon.
Is part of this just getting in on the latest trend? Definitely. I like scrolling through trending on Github, ya know?
But I was also just tired of writing PHP. Python is cleaner, so if I can do the more complex backend stuff in that, coding is more fun. I would say PHP and JS are about equally “unclean” but if it’s just frontend all those brackets and parentheses don’t become an issue as much.
Just one experience.
Compared to the Python 2 to 3 mess and the constant churn that today's frontend frameworks seem to suffer from, I would say that PHP is more serious about maintaining backward compatibility than nearly every other language commonly used in web dev.
It is so successful because people who build new things are different from people who are paid to maintain old things. That is why WordPress, Wikipedia and countless other successful internet projects have been created using PHP and not using Java.
People who build new things like simplicity and elegance and tools that empower them. While people who are paid to maintain old things like a rigid structre which gives you the feeling of "nothing can go wrong".
Also, people who build and run things do not like breaking changes of their stack. While people who are paid to maintain old things don't care about breaking changes in their stack. Because they are paid to then work around those changes.
In the last version (8), PHP has introduced a ton of breaking changes which makes the language more rigid. And therefore less useful to build new things and more cumbersome to maintain:
It broke the order of parameters in join statements.
It broke calling static functions without the need to declare them as static.
It broke adding properties dynamicly to objects.
It broke easy string handling for many functions where null was rendered as an empty string. This is especially annoying as you often get null values from the database. It makes sens to have a value for "Don't know the color of the car" in the DB. And it makes sense to render it as "Color: " in the user interface. The easy string conversion always was one of the strengths of PHP. Why is it sabotaged now?
Some of these changes have been objected to by the original developer of PHP and long standing contributors like the author of xdebeug, PHP's most popular debugger. Yet they have been implemented.
The big danger is that this trend continues and existing PHP projects will be choked to death by more and more breaking changes. Changes which have to be worked around by making the code of the projects more and more bloated.
I’ve been able to keep several large business-critical projects up-to-date for years, even up to PHP 8.3, with little to no breaking changes encountered.
PHP 8 didn’t really break adding properties to objects dynamically, it just deprecated one bad-practice way of doing so. I remember worrying about this before upgrading, across my entire project with 40+ Composer direct dependencies, there were zero instances of this deprecated approach being used.
With other breaking changes there’s plenty of notice given (years, even). You can control where and how deprecation notices are logged, there really shouldn’t be any surprises at upgrade time.
“Old PHP” made it easy to write buggy or unpredictable code. Modern PHP feels more like writing TypeScript vs JS, there’s real safety and a much better developer experience now. PHP is having a resurgence for good reason, yes, it’s (marginally) harder to keep up with, but with proper tooling (PhpStorm, phpstan, etc.) the DX is leaps and bounds ahead of where it used to be.
I thoroughly enjoy writing modern PHP. I don’t have to worry about the language doing unpredictable dynamic type casting unless I want it to explicitly. The flexibility of old PHP is still there, but it’s much harder to shoot yourself in the foot accidentally.
I have not doubted that there are people who like the more rigid structure which the current maintainers push for. I actually mentioned that.
But the success of PHP comes from the people who like PHP the way it was. Empowering them to write their own web projects with the least amount of code and bloat.
I'm sure that was the case for many years, but I believe the successful resurgence of modern PHP is coming from the people who want to see PHP actively improving. Not those who like PHP the way it was!
PHP got a nasty reputation thanks to things like the "Fractal of Bad Design" site. Modern PHP has resolved (effectively) all of those early critiques.
The ongoing success of PHP comes from it continually improving :)
For a one-off script, I might still use a bit of PHP, if I didn't have javascript.
To talk about PHP without mentioning WordPress, whether in a good light or not, would be like discussing Ruby without mentioning Rails.
I know PHP is not perfect and I've definitely contributed some hot messes of code in the past as I figured things out. Sorry...
PHP has let me code anything I've wanted so far, so it's a really powerful tool for me.
I'm the guy who built an automated home cinema using PHP and MySQL: I hit a button on a website and it tells a Raspberry Pi to start the desired show.
It selects a Dolby ad, some sort of vintage ad like dancing hot dogs, a couple of trailers, and the feature. It brings the lights up for the credits.
I use PHP everyday but we definitely have a lot to learn from others.
- Better libraries and frameworks overall
- Better programmers overall, so more competent colleagues
- Relevant in many fields outside web development
- Allows to learn and use various paradigms, like async/multithread/multiproc...
I do keep track of PHP improvements. In fact, I keep a small personal toy framework as a way to test its new features. Some of these were very much welcomed, like safe mode + runtime typing. But some of these were just catch-ups and none of these are compelling enough so that I would want to start a new project in PHP.Other ecosystem I'm interested in is Go, for other reasons.
PHP had a lot of breaking changes in the last version. Changes which got pushed through despite being quite controversial. I fear that this trend will continue.
Python had breaking changes in version 3, but at least those made the language better. PHP's recent changes were unnecessary and counterproductive.
If you are spammer and read this: search a different job and drop all tables before you leave!