I realize that a significant portion of the internet runs on PHP, but if you are going to do something as high-risk as SR, you should use more robust tools.
I realize that a significant portion of the internet runs on PHP, but if you are going to do something as high-risk as SR, you should use more robust tools.
The fundamental problem is that no matter what language and server combination you choose, it was never written for hostile environments. Exposing an IP address of an internal server is considered a very low risk vulnerability (as compared to say RCE), so very little work is put into auditing for such risks.
I'd rather have ample documentation on how to harden my PHP application than no documentation on how to harden my Node application. Security through obscurity is no security at all. Plus, many of the mitigation strategies are simply rules like "don't use mysql_query" or "use htmlentities with ENT_QUOTES and UTF-8 to escape your output", both of which can be built into a framework. See: laravel.
[edit] downvoting is much easier than formulating a response, isn't it?
Why not Python, or Go, or even Haskell? There are many languages other than the three you mention which have much better reputations for secure web programming.
You likely got downvoted because you presented a false choice to back up your argument.
* The language itself has a pretty good security track record * The more popular application frameworks (Django, Flask, et al.) seem to be doing pretty well * Process isolation techniques are well-known