PHP is on my mental list of forever-security-challenged tech, but it got on that list a long time ago. It’s 2023, is that still a reasonable concern?
PHP is on my mental list of forever-security-challenged tech, but it got on that list a long time ago. It’s 2023, is that still a reasonable concern?
No. A LOT has changed in the world of PHP over the years. And to be honest, I give credit to amazing frameworks like Laravel [0] for giving PHP a massive facelift (I consider Taylor Otwell one of my software heroes). Overall though, modern PHP software is much cleaner and more secure than whatever you knew from years ago.
[0]: https://laravel.com
Moreover, I'd like to point out that even if the vast majority of PHP-backed websites are based on WordPress, WordPress is not an example of good PHP practices at all. Its code-base and coding standards are old and horrible.
Re Taylor, if I was a billionaire (or at the very least, extremely wealthy), he’s one of those folks I’d write a no-strings-attached blank check to go build anything he wants—just a brilliant and overall great human. I used to be very active in the Laravel community many years ago, and even way back then, before Laravel was super famous (first Laracon days), I remember meeting Taylor and being thoroughly impressed. Over the years, on multiple occasions, I’ve heard folks at relatively large organizations say they adopted PHP solely because of Taylor and Laravel. Recently, when I saw someone mention in a post that Taylor has a Lambo now, I was so happy for him—it feels great to see him thrive after making the type of impact that he has.
Unfortunately, not so much. They still follow PHP 5-days style, for example they still haven't adopted the short array syntax [], they always use array() which is horrible in my opinion.
The code base is horrible, but the front-facing experience is not so bad (unless you start installing lots of plugins, which tend to add different interface styles and lots of banners everywhere in the admin panel).
For experienced devs following best practices and using modern frameworks it's "mostly fine", and that's the side of things that's been improved over the years, but most of the old rakes are still there to be stood on.
I don't think that's necessarily true -- a lot of features have been deprecated and removed.
The former was notoriously insecure, as what it did was promote anything passed in as a cookie, GET, or POST variable into a global-scoped variable inside your script. Since PHP didn't require any sort of declaring-your-variables-before-using-them, it was pretty easy to wind up with scripts written in a way that would allow this an unwise amount of access to the script's internals.
The latter automatically escaped special characters with backslashes in all the aforementioned user-provided variables so you could pass them straight into mysql queries. It was, however, optional and so caused errors because code got written relying on it and then ran on servers with it disabled, allowing SQL injection attacks... or double-escaping things in code written the other way around.
But these days are long behind us!
PHP applications are fun to test because most teams found another set of solutions to the same problems (it has so much history that wheels have been reinvented a lot), so you get to see new things. They're also typically larger than newer and new-style services written in a shiny new language, which haven't had time to accumulate as many features and are often written as a microservice (smaller components where one/each dev can know all the ins and outs, allowing to have a total overview so that security controls can much more easily be implemented in a unified way).
However, you get two additional factors: a) it's easy, therefore it attracts beginners and b) it's popular, therefore a lot of software uses it. More various software - more security issues. More software implemented by beginners - a lot more security issues. That was inevitable - any platform that was as low entry barrier and as popular and that appeared in the same time, when the web was exploding, but the understanding of how to manage security on the web was lagging behind - would have absolutely the same going on.
But, blaming the tool because a lot of people didn't use it correctly - and, also, because due to its novelty there weren't proper education and frameworks that made it easy to do the right thing - makes little sense. There's nothing security-challenged in PHP. It's just that PHP was there when security-challenged programmers started to build websites. Most of them grew up now and know how to do it right. Either in PHP or in any other language.
PHP itself has also come along way. I don't know if it's because of it's reputation that it seems to evolve faster than most languages.
I recently used PHP to construct my personal site/blog. I didn't use any frameworks but I did use it's statically typed/strongly typed features that that is very different from how I would have coded in PHP years ago.
Presumably you can still write bad code in PHP. But the mysql library that was sql injection heaven is now truly dead.