PHP Core Security Audit Results
thephp.foundation
thephp.foundation
Last year, it received close to 680K USD, and managed this security audit, sponsored 10 developers, and paid for various expenses. For a language that runs close to 75% of the web, it certainly deserves more funding.
Some of the recent initiatives from the Foundation (https://thephp.foundation/blog/2025/03/31/transparency-and-i...) :
- All PHP versions now receive a total of 4 years of security updates; 2 bug fixes + 2 security, up from 3.
- PIE: A replacement for PECL, to easily install PHP extensions (C, C++ compiled, not PHP packages).
- The security audit.
(I'm one of the PHP Core team and a volunteer at the foundation, happy to answer any questions, but almost all of the work is public)
Wow, Automattic itself donated more than half of it: Silver Sponsor $387,500 USD
Why many donors with more than USD 24K and USD 100K still listed as Silver sponsor?
Source: https://opencollective.com/phpfoundation/contribute/major-sp...
That said, the recent changes around Laravel (being bought out and becoming more and more commercial) is not something I (we) consider a good thing. Not necessarily a bad thing, but we all know that a OSS framework becoming commercial doesn't usually end well.
Also, like most things, Laravel is built on the shoulders of others. It sometimes makes hard things easy to access (ppl like this) and hides complexity away, clouding how things actually work (ppl don't like this).
I primarily use Laravel but like to think I code in a generalist if way as to not get stuck in its system.
Ehh, I don't think I'd ever use that word but he had a huge impact on reinvigorating the PHP ecosystem as a whole with Laravel. I remember playing with early versions of Laravel on my own and having my eyes opened to a better way to structure/write code.
Mullenweg has been demanding 8% of WP Engine’s revenue, access to their books, and the ability to direct their staff on what to work on. For context, Mullenweg is maintainer of WordPress and WordPress.org, and CEO of WP Engine’s direct competitor, Automattic. The dispute has turned very nasty and included a lot of unhinged behaviour from Mullenweg. WP Engine is currently suing him for a bunch of things, including extortion.
davidandgoliath is basically saying that if Mullenweg thinks he is owed 8% of WP Engine’s revenue, presumably Mullenweg is donating 8% of Automattic’s revenue to the PHP Foundation, making their revenue only ~$5MM/yr. Obviously Automatic’s revenues are vastly higher than that and this is just a tongue in cheek way of pointing out hypocrisy.
While the 8% is probably a dig, the donation of .06% of revenue is going to be a much higher proportion of profits. No idea what their profits or margins are (a quick search does not provide useful info)
Overall, 658 organizations and individuals sponsored the foundation in 2024 through on Open Collective and GitHub Sponsors.
and in the Open Collective link, it is stated that Automattic donated those amount.
I know its all donations and not expected, but them kicking in ~$30k a month would realistically be nothing to them, but benefit the PHP foundation massively. The same goes for Symfony.
On the other hand Laravel has VC backing and sells services.
Symfony itself also had a round of funding many years ago when it wasn't rolling in cash, around $7 million if I recall.
- Type annotations are integrated and work well with PHP now. This results in a kind of scripty Java OOP that is more succinct and type checked ! (it is possible to write PHP without types when you want metaprogramming features also)
- Many inconsistencies in the design of the language (OOP, function naming etc.) have been resolved/smoothed out
- The language recognises the inherent problems with `null` and allows you to make type annotations that rule out null. This is my smell test for a language BTW -- golang for instance does not seem to have a good story for null.
- PHP Language developers have been really good about increasing performance year after year
- Lots of software like web frameworks and CMSes continue to be based on PHP
And -- the greatest part of the design -- PHP remains the best example of the "shared nothing" architecture. An architecture that allows you to scale your application easily.
I am pretty much in the "your dad" category here. Where best to start learning how PHP has changed since I used it?
There are things that appeal to be about PHP.
That said, you can still shoot yourself in the foot with PHP. The dark alleys are all still there.
I looked at Symfony a few years back and it looked nice. if it has kept up with modern PHP it looks like a nice choice.
The reason is simple: It's to me the most efficient, best performant SSR option out there, if your requirements are simple.
You will be amazed at the website's speed. We are so used to the lethargic JS slop of the average website out there these days.
I love PHP, I believe future "vibe coders" will be left bedazzled at its powers, which will be beyond their comprehension.
It has a low barrier to entry and great language features - static typing being one of the big ones. It has become a really nice language over the years, great to work in and in no way less satisfying or effective than for example golang.
And, of course, laravel exists.
... and it's completely optional in many cases on top of that. Even if you're using third party libraries, it will only crash if you mess up your types at the library's interface.
I would have thought PHP would scale very well. It may not be high performance, but its start each request-response cycle from scratch should scale horizontally very well, surely?
That said, with today's PHP it is possible to optimize the hot path pretty well with stuff like FFI.
Many of the quirks and problematic parts have been addressed through the years, it's battle tested, and there is a healthy and stable ecosystem behind. It doesn't need to be everyone's first choice, but there's also no strong reason to avoid using it in its current state.
And it's still performant enough https://x.com/arvidkahl/status/1775261978006896730
https://doc.rust-lang.org/reference/expressions/match-expr.h...
For example, imagine someone who had never really thought about routing in a definitions file versus file based versus annotations. Three valid use cases that might not exist if if you have a background in something like hardware or if you come from a non-programming discipline.
If you do have that experience, you can rebuild almost any affordance in PHP at this point and it purely comes down to personal preference and how you like to write and design with code.
(They had hundreds of millions of profit)