The PHP programming language: a complete overview, pros, cons and limits
What the PHP programming language is for in 2026, where it is the best choice and where another language wins: modern PHP 8.5, pros and cons, a comparison with Node.js, Python, Go and Ruby, frameworks or your own code, examples, limits and tips.
In short
PHP is a free open-source language for the server side of websites: about three quarters of sites with a known server language run on it, including WordPress and Wikipedia. Modern PHP is not the PHP of the 2000s: strict types, enums, readonly properties, property hooks, the pipe operator, a bytecode cache and JIT. Its strengths are cheap hosting everywhere, a request model where every request starts clean, a huge ecosystem (Composer, Laravel, Symfony) and fast development of sites, shops and admin panels. Its weak spots are long-lived connections and real time, heavy computing and the legacy of old code and plugins — modern PHP is written strictly or not at all.
PHP at a glance
The main facts in one table — where the language came from, how it runs and how it evolves.
- Type
- A general-purpose scripting language, created for the web
- History
- Rasmus Lerdorf, 1995 (PHP/FI); the modern engine — since PHP 7 in 2015
- Developed by
- An open community; core developers are funded by the PHP Foundation
- License
- PHP License — free, including commercial use
- Typing
- Dynamic with optional types;
declare(strict_types=1)turns on strict checks - Execution
- Compiled to bytecode, cached by OPcache; JIT since PHP 8.0
- Request model
- Every request starts clean (PHP-FPM); long-lived servers — FrankenPHP, RoadRunner, Swoole
- Packages
- Composer and the Packagist registry
- Latest version
- PHP 8.5 (November 2025): the pipe operator
|>, a URI extension,array_first() - Releases
- Once a year in November; each version is supported for four years — two active, two with security fixes
- Popularity
- About three quarters of sites with a known server language, by W3Techs
- Built on it
- WordPress, Wikipedia (MediaWiki), Drupal, Magento
What PHP is used for: 8 areas
PHP was born for the web and remains strongest there. Under each area — the tools it usually runs on.
-
01
Sites and landing pages
Pages are assembled on the server and arrive ready — fast for people and clear for search engines.
-
02
Online shops and catalogues
Products, filters, carts, payments and stock — the classic PHP task.
-
03
Content management systems
The most popular CMS are written in PHP — and so are their plugins and themes.
-
04
APIs for sites and apps
REST APIs for mobile apps, single-page interfaces and partners.
-
05
Admin panels and CRM
Internal systems with roles, forms, tables and reports.
-
06
SaaS and personal accounts
Sign-in, subscriptions, payments and queues — mature frameworks have it all out of the box.
-
07
Integrations and data exchange
Linking the site with CRM, accounting, payments and delivery through APIs and webhooks.
-
08
Scripts and scheduled tasks
Imports of price lists, reports and mailings from the command line and cron.
Pros and cons of PHP
PHP was designed to make the web simple. Most of its strengths come from that — and so does the reputation it has to outgrow.
Pros · 8
-
Hosting everywhere
Any hosting runs PHP, from the cheapest to the cloud. Deployment is copying files.
-
Every request starts clean
No shared state between requests: a memory leak or a crash does not pile up and does not take down neighbours.
-
Fast enough for the web
Since PHP 7 the engine is several times faster than PHP 5; OPcache and JIT do the rest.
-
A modern language
Strict types, enums, readonly properties,
match, property hooks, the pipe operator. -
A huge ecosystem
Composer, hundreds of thousands of packages, Laravel and Symfony, ready solutions for almost any web task.
-
Fast development
No compilation step: change a file, refresh the page. Templates are part of the language.
-
Predictable releases
A new version every November and four years of support for each.
-
Many developers
A large market of specialists — the project does not depend on one person.
Cons · 8
-
The legacy of old code
The web is full of PHP written without types and tests, and plugins with holes — the language’s reputation suffers for it.
-
An inconsistent standard library
Function names and argument order differ from function to function — historical baggage.
-
No generics in the language
Collections of a given type are described in PHPDoc comments and checked by PHPStan or Psalm.
-
Real time needs extra tools
WebSockets and streaming do not fit the request model — you need Swoole, FrankenPHP or a separate service.
-
Synchronous by default
Ten API calls inside one request go one after another unless you use
curl_multior an async library. -
Not for heavy computing
Video, machine learning and big numerical tasks belong to Python, Go, Rust or C++.
-
Loose comparisons
==converts types and still catches beginners; modern code uses===and strict types. -
A low entry bar
It is easy to start and easy to write badly — the quality of PHP developers varies a lot.
Laravel, Symfony or PHP without a framework
Laravel and Symfony give a ready structure: routing, ORM, queues, authentication, a large community and many developers who know the conventions. For a typical SaaS or a product with a team of several developers this saves months.
The price is weight and dependence: thousands of files that every request touches, updates that follow the framework’s schedule, and an architecture designed for everyone rather than for your task. For sites, catalogues and admin panels modern PHP itself is enough: strict types, enums, match, PDO and a small foundation of your own give a lighter, faster project that is easy to read years later.
- A framework — for big teams and typical products
- Own code — for sites, catalogues and admin panels
- Either way — strict types and tests
PHP compared with Node.js, Python, Go and Ruby
A qualitative comparison for the server side of the web. Exact speed depends on the code and the load, so the table shows relative positions rather than benchmarks.
| Criterion | PHP | Node.js | Python | Go | Ruby |
|---|---|---|---|---|---|
| Typing | dynamic + optional strict types | dynamic, TypeScript on top | dynamic + type hints | static | dynamic |
| Request model | each request starts clean | one process with an event loop | worker processes | one binary with goroutines | worker processes |
| Speed of a typical site | high with OPcache | high on I/O | medium | very high | medium |
| Hosting | any, including the cheapest | VPS or platform | VPS or platform | VPS, one file | VPS or platform |
| Ready CMS and shops | the most | a few | a few | almost none | a few |
| Real time | with extra tools | natively | with async frameworks | natively | with extra tools |
| Entry bar | low | low | low | medium | medium |
| Strongest at | sites, shops, admin panels | real time, shared code with the front end | data and AI | high-load services | fast prototypes |
When to choose PHP — and when not to
Thirteen typical tasks with a verdict. Where PHP is not the best choice, the alternative is named.
-
Corporate site or landing page
Best fitPages assembled on the server, cheap hosting, fast development.
-
Online shop or catalogue
Best fitThe classic PHP task, from your own code to ready platforms.
-
Admin panel, CRM, personal account
Best fitForms, tables, roles and reports are what PHP does every day.
-
API for a site or an app
Best fitREST APIs with documentation and validation.
-
Integrations with CRM and accounting
Best fitHTTP clients, webhooks and scheduled exchanges are routine.
-
Content project or media
Best fitFast pages that search engines read well.
-
SaaS with a team of developers
WorksYes with Laravel or Symfony; for high load, put Go services next to it.
-
Background jobs and queues
WorksWorks through workers and the command line; for huge streams — Go.
-
Chat and live notifications
WorksThrough FrankenPHP or Swoole, or a separate service in Go or Node.js.
-
Tens of thousands of long connections
Pick anotherGo or Node.js: connections are their native element.
-
Machine learning and data analysis
Pick anotherPython: the libraries are there.
-
Mobile and desktop apps
Pick anotherSwift, Kotlin or Flutter; PHP can be their backend.
-
Video processing and heavy computing
Pick anotherGo, Rust or C++ — or ready tools like FFmpeg called from PHP.
The PHP ecosystem: tools for common tasks
Much is built into the language, the rest comes through Composer. The middle column is what ships with PHP itself.
| Task | Built in | Packages and tools |
|---|---|---|
| Packages | — | Composer, Packagist |
| Frameworks | — | Laravel, Symfony, Slim |
| Templates | PHP itself | Twig, Blade |
| Database | PDO, mysqli | Doctrine, Eloquent |
| HTTP client | curl | Guzzle, Symfony HttpClient |
| Tests | — | PHPUnit, Pest |
| Static analysis | — | PHPStan, Psalm |
| Code style | — | PHP-CS-Fixer, PHP_CodeSniffer |
| Upgrading code | — | Rector |
| Debugging and profiling | — | Xdebug, SPX, Blackfire |
| Long-lived server | — | FrankenPHP, RoadRunner, Swoole |
| Queues | — | Symfony Messenger, Laravel Queues |
| Bytecode cache | OPcache, JIT | — |
| Local server | php -S | Symfony CLI |
The limits of PHP: where it hits the ceiling
-
Long connections
A classic PHP worker serves one request at a time. Thousands of open WebSockets need an async server or a separate service.
-
Long tasks inside a request
Imports, reports and mailings hit the time limit and hold the visitor. They belong in a queue or the command line.
-
Workers and memory
Each worker takes memory. If the web server allows more workers than the server or the database can hold, a peak takes the site down.
-
Heavy computing
Image recognition, video and big calculations are slow in PHP — hand them to specialised tools.
-
Types without generics
In a large codebase, collections and contracts are held together by static analysis, not by the compiler.
-
Plugins and old versions
Most PHP site hacks come through outdated plugins and versions without support — not through the language.
8 tips for writing PHP that is not ashamed of itself
-
01
Strict types in every file
declare(strict_types=1)plus types for every argument, return value and property. -
02
PHPStan at a high level
Static analysis finds the errors the language itself does not see — before users do.
-
03
Only prepared queries
PDO with parameters: what the user typed never becomes part of SQL.
-
04
Passwords only through password_hash
No md5 and no own schemes:
password_hash()andpassword_verify()do it right. -
05
OPcache in production
Without the bytecode cache PHP parses every file on every request.
-
06
Long work in the background
Imports and mailings go to a queue or cron, and the visitor gets an answer at once.
-
07
Keep the version current
PHP 8.2 stops getting security fixes at the end of 2026. Rector helps move to a new version.
-
08
Keys outside the code
Passwords and API keys live in environment variables, not in the repository.
What modern PHP looks like: 3 examples
Three examples behind the main strengths of modern PHP: strict types, new syntax and safe work with the database. Checked on PHP 8.5.
Enums and property hooks
The order status cannot be anything but the listed values, and the total checks itself on every write.
<?php
declare(strict_types=1);
// order status: the language itself fixes the set of values
enum Status: string
{
case New = 'new';
case Paid = 'paid';
case Shipped = 'shipped';
public function label(): string
{
return match ($this) {
Status::New => 'Awaiting payment',
Status::Paid => 'Paid',
Status::Shipped => 'On the way',
};
}
}
final class Order
{
// property hook (PHP 8.4): the total is checked on every write
public int $total {
set(int $value) {
if ($value < 0) {
throw new InvalidArgumentException('The total cannot be negative');
}
$this->total = $value;
}
}
public function __construct(
public readonly int $id,
public Status $status = Status::New,
int $total = 0,
) {
$this->total = $total;
}
}
$order = new Order(id: 42, total: 1500);
echo $order->status->label(), PHP_EOL; // Awaiting payment
$order->status = Status::from('paid');
echo $order->status->label(), PHP_EOL; // Paid
$order->total = -10; // InvalidArgumentException
The pipe operator of PHP 8.5
A value goes through the steps from left to right — no nested calls read inside out.
<?php
declare(strict_types=1);
// PHP 8.5: the pipe operator passes a value through the steps left to right
$slug = ' Hello, World! Привет '
|> trim(...)
|> mb_strtolower(...)
|> (fn(string $s): string => preg_replace('~[^\p{L}\p{N}]+~u', '-', $s))
|> (fn(string $s): string => trim($s, '-'));
echo $slug, PHP_EOL; // hello-world-привет
$orders = [
['id' => 1, 'total' => 900],
['id' => 2, 'total' => 4200],
['id' => 3, 'total' => 7300],
];
// array_first() is also new in 8.5
$firstBig = array_first(array_filter($orders, fn(array $o): bool => $o['total'] > 1000));
echo $firstBig['id'], PHP_EOL; // 2
Safe queries and passwords
A prepared query does not let an injection through, and the password is stored only as a hash.
<?php
declare(strict_types=1);
$db = new PDO('sqlite::memory:', options: [PDO::ATTR_ERRMODE => PDO::ERRMODE_EXCEPTION]);
$db->exec('CREATE TABLE users (id INTEGER PRIMARY KEY, email TEXT UNIQUE, hash TEXT)');
// the password is stored only as a hash
$insert = $db->prepare('INSERT INTO users (email, hash) VALUES (:email, :hash)');
$insert->execute([
'email' => '[email protected]',
'hash' => password_hash('correct horse battery staple', PASSWORD_DEFAULT),
]);
// a prepared query: what the user typed stays data and never becomes SQL
$find = $db->prepare('SELECT hash FROM users WHERE email = :email');
$find->execute(['email' => "[email protected]' OR '1'='1"]);
var_dump($find->fetchColumn()); // bool(false): the injection found nothing
$find->execute(['email' => '[email protected]']);
var_dump(password_verify('correct horse battery staple', $find->fetchColumn())); // bool(true)
Questions about PHP
Is PHP outdated?
No. A new version comes out every year, PHP 8.5 added the pipe operator and a URI extension, and the language runs about three quarters of sites with a known server language.
PHP or Node.js for a website?
For sites, shops and admin panels PHP is simpler and cheaper to host. Node.js is stronger in real time and when the front end and back end share code.
Do I need Laravel or Symfony?
For a typical SaaS with a team — often yes. For sites, catalogues and admin panels modern PHP without a framework is lighter and faster.
Which PHP version should I use?
The newest your hosting supports — 8.4 or 8.5. PHP 8.2 stops getting security fixes at the end of 2026.
Is PHP secure?
The language is. Holes come from code and plugins: no prepared queries, weak password storage, outdated versions.
Can PHP handle high load?
Yes, with caching and several servers — Wikipedia runs on PHP. For tens of thousands of long connections a separate service in Go or Node.js is better.
What is Composer?
The PHP package manager: it installs libraries of the right versions and connects them to the project.
Is PHP the same as WordPress?
No. WordPress is a CMS written in PHP. On PHP you can also write a site, a shop or an API from scratch, without any CMS.
Is PHP good for an API?
Yes: REST APIs with validation and OpenAPI documentation are a routine PHP task.
Online form
Development
in PHP
I write PHP 8.5 without a framework: sites, catalogues, admin panels, APIs and integrations — strict types, fast pages and code that belongs to you. Tell me about the task — I answer within one working day.