shouldiuse.io

VERDICT

Should I use Php?

Not disclosed - php.fyi

Depends. The sources describe PHP the language, not what php.fyi actually sells, so confidence is low. PHP itself is free and battle-tested for CMS and hosting-bound sites; verify what php.fyi offers before committing, and look elsewhere for realtime or security-critical greenfield builds.

Confidence

Low. Based on ~40 public sources; nearly all cover PHP the language or PHP Agency, not the php.fyi page itself.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support quality
  • Security posture

Pricing

Free

PHP runtime

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes

Best for

  • WordPress and CMS sites
  • Cheap shared-hosting web apps
  • Teams with existing PHP codebases
  • CRUD-heavy business apps

Not for

  • Realtime, high-concurrency products
  • Security-critical apps without fast patching
  • Greenfield teams wanting modern type-first stacks
  • Anyone expecting to be a supported product

Gotchas - check before you buy

high

Old versions lose security support; running them unsafely is common

high

CVE-2024-4577 saw widespread real-world attacks; patch cadence is mandatory

medium

No security page on; unclear who runs or supports it

medium

Poorly secured PHP apps enable injection attacks; hosting quality varies widely

Pros and cons

Pros

  • Free, open-source language with a massive hosting ecosystem
  • Runs 77% of sites with a known server-side language
  • Still actively maintained; PHP Foundation funds core development
  • Developers report it remains fine for many businesses
  • Upply credits PHP with resisting a costly rewrite

Cons

  • Recurring critical CVEs, including one mass-exploited in 2024
  • Persistent developer criticism makes hiring harder
  • itself publishes no security page
  • Newcomers report less current learning content

Sources & method

Analyzed 9/25/2026 - 10 sources - Active CVE stream with several critical issues in 2024-2026, one mass-exploited; php.fyi itself shows no security page.

official x3review x2security x2news x3
  • CVE-2024-4577 — PHP CGI argument injection, Critical vulnerability under widespread cyberattack.
  • CVE-2024-8926 — command injection, Command injection vulnerability enabling remote code execution.
  • CVE-2026-6735, High-severity vulnerability per Zend advisory.
  • CVE-2026-7258, Affects PHP 8.x versions per NVD.

Key stats

  • Value for money: 5/5

    Rating

  • Free

    Starting price

  • 10

    Sources

  • Analyzed

  • Value for money: 5/5. Runtime is free; you pay only for hosting
  • Ease of use: 3/5. Easy to start, messy legacy patterns
  • Feature depth: 4/5. Mature frameworks cover most web needs
  • Support quality: 3/5. Community-driven; PHP Foundation funds core work
  • Security posture: 2/5. Recurring critical CVEs, some mass-exploited
  • 77% Server-side share Of sites with known server language, per W3Techs
  • Free Runtime price Open-source language
  • Yes Free tier Runtime free; hosting costs separate
  • 1995 First released Three decades of production use

Pricing

PHP runtime

Free

  • Open-source language
  • Hosting and paid support sold separately

Security

Active CVE stream with several critical issues in 2024-2026, one mass-exploited; php.fyi itself shows no security page.

  • CVE-2024-4577 — PHP CGI argument injectionCritical vulnerability under widespread cyberattack.⁴
  • CVE-2024-8926 — command injectionCommand injection vulnerability enabling remote code execution.
  • CVE-2026-6735High-severity vulnerability per Zend advisory.
  • CVE-2026-7258Affects PHP 8.x versions per NVD.

What users say

Reddit sentiment is mixed: developers concede PHP still runs many businesses fine while acknowledging heavy criticism and thinner beginner content.

Alternatives

Compare Php with each alternative.

  • Node.js

    JavaScript everywhere; better for realtime and API-heavy products.

  • Python

    Cleaner syntax; strong for data, scripting, modern backends.

  • Ruby on Rails

    Opinionated full-stack framework; ships fast with sane defaults.

    Php vs Ruby on Rails

Companies that use it

  • Upply⁹
  • WordPress (platform built on PHP)⁶
  • OpenEMR
Full analysis

Based on ~40 public sources; nearly all cover PHP the language or PHP Agency, not the php.fyi page itself.

php.fyi itself is unclear; PHP the language is free, proven, CVE-prone — fine for CMS sites, weak for realtime SaaS.

Methodology

Based on ~40 public sources; nearly all cover PHP the language or PHP Agency, not the php.fyi page itself.

Sources

  1. official
  2. news
  3. official
  4. security
  5. security
  6. news
  7. review
  8. review
  9. news
  10. official

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.