Then I reached this sentence, which I felt needed to be bolded and underlined:
A large number of sites run PHP as either an Apache module through mod_php or using php-fpm under nginx. Neither of these setups are vulnerable to this.
<insert immense sigh of relief>. Thank God.
That said, some blackhats are going to be really sore that a backdoor that's been wide open for "at least 8 years" is finally being closed.