6 |8 |“{{ quote | striptags | raw | nl2br }}”
7 |
I look forward to talk about @ThePHPF at @afup #ForumPHP together with @pronskiy!
We’re eager to answer your questions and look forward to hearing your suggestions! pic.twitter.com/2x8id0mDZ5
31 | 32 |Nous sommes ravis d'accueillir pour la première fois @Girgias, jeune et talentueux core-contributeur à PHP, pour un talk sur les rouages du typage lors du Forum PHP 2022.
— AFUP (@afup) July 11, 2022
🎤 "Typage en PHP comment ça fonctionne ?" - Forum PHP 2022 - 13&14/10, Disneyland Paris pic.twitter.com/dB0pWflmKB
83 | 84 | Let Derick know what you think. 85 | 86 | > You can find more insights on PHP core development process in **[PHP Roundup Series](https://thephp.foundation/blog/tag/roundup/)**. 87 | > 88 | > Tweet at us: [@ThePHPF](https://twitter.com/thephpf), [@Ayeshlive](https://twitter.com/Ayeshlive), [@pronskiy](https://twitter.com/pronskiy). 89 | 90 |Making PHP's DateTime class mutable was one of the bigger mistakes of the Date/Time APIs. I'm considering to change DateTime to be immutable by default in PHP 9, and to drop DateTimeImmutable altogether (or make it an alias). This is likely going to break some code. Opinions?
— Derick Rethans (@derickr) July 25, 2022
31 | Apply 32 |
33 | 34 |105 | Open submission form 106 |
107 | 108 | 109 | -------------------------------------------------------------------------------- /source/_posts/2023-11-23-php-83.md: -------------------------------------------------------------------------------- 1 | 2 | --- 3 | title: 'PHP 8.3 Released!' 4 | layout: post 5 | author: 6 | - name: Ayesh Karunaratne 7 | url: https://aye.sh 8 | 9 | - name: Sergey Panteleev 10 | url: https://sergeypanteleev.com 11 | published_at: 23 November 2023 12 | 13 | --- 14 | 15 |26 | Apply 27 |
28 | 29 |95 | Open submission form 96 |
97 | 98 | 99 | -------------------------------------------------------------------------------- /source/_posts/2024-09-30-call-fo-sponsors.md: -------------------------------------------------------------------------------- 1 | 2 | --- 3 | title: 'The PHP Foundation Calls for Sponsors: Help Shape the Future of PHP' 4 | layout: post 5 | tags: 6 | - update 7 | author: 8 | - name: Roman Pronskiy 9 | url: https://twitter.com/pronskiy 10 | published_at: 30 September 2024 11 | 12 | --- 13 | 14 | Hey there, PHP enthusiasts and tech leaders\! It's that time of the year again when everyone's crunching numbers and deciding on budgets. We've got an opportunity for you to make a real impact on the PHP ecosystem. Let's dive in. 15 | 16 | **Don't need convincing? [Sponsor us now](https://thephp.foundation/sponsor/)!** 17 | 18 | ## Join us\! Fund the Future of Web Development 19 | 20 | We just opened applications for PHP core language contributors: [The PHP Foundation application form for 2025 is now open](https://thephp.foundation/blog/2024/09/17/application-form-2025/). 21 | 22 | Here's the deal: **the more sponsors we get, the more ambitious we can be with our plans**. At a minimum, we finance maintenance and security support, but with more funding, we can continue high-reaching projects. 23 | 24 | Your sponsorship could help us: 25 | 26 | * **Tackle long-standing bugs** that have been bothering developers for ages. 27 | * **Implement cool new features** that will make PHP even more awesome. 28 | * **Improve performance and security** (because who doesn't want a faster PHP). 29 | 30 | And if we get enough sponsors, we might even venture into some experimental territory. Your support could lead to the next big breakthrough in PHP development. 31 | 32 | {{ include('quote.html', { 33 | name: 'Kévin Dunglas', 34 | title: 'author of [FrankenPHP](https://frankenphp.dev/)', 35 | image: '/assets/post-images/2024/report-2023/kevin_dunglas.png', 36 | quote: 'To achieve exceptional performance and simplify application deployment, FrankenPHP pushes the PHP engine to its limits and uses it in atypical ways (ZTS, musl libc, specific timeout management...). 37 | 38 | This would not be possible without the excellent work done by the PHP Foundation\'s team: they correct the problems we report, continuously improve performance and make the engine always more generic and modular, which not only enables us to innovate in FrankenPHP, but also benefits the entire ecosystem by making PHP faster and more reliable. 39 | 40 | By sponsoring the foundation, you\'re investing in the future of PHP!' 41 | }) }} 42 | 43 | ## 2025: The Year PHP Turns 30 (and It's Going to Be Epic\!) 44 | 45 | PHP is turning 30 in 2025, and we're planning a special celebration\! By sponsoring the PHP Foundation, you'll be front and center for this milestone year. Here's what we've got cooking: 46 | 47 | * A massive collaboration with the marketing teams from Laravel, JetBrains, and Zend by Perforce. It's like the Avengers of the PHP world coming together. 48 | * A much-needed facelift for php.net. Let's make it shine for PHP’s 30th birthday\! 49 | 50 | Imagine your company being visible as a part of this historic moment. Pretty cool, right? 51 | 52 | ## Why Sponsor the PHP Foundation? 53 | 54 | You might be wondering, "Why should I sponsor the PHP Foundation?" Let us list some of the reasons: 55 | 56 | 1. **Visibility:** Your brand will be seen by millions of developers worldwide. That's a lot of eyeballs. 57 | 2. **Influence:** Help shape the future of one of the most widely used programming languages on the web. 58 | 3. **Security:** Without sufficient funding, the PHP language will lack the resources to promptly address bugs your company runs into. 59 | 4. **Recruitment:** Attract top PHP talent by showing your commitment to the language. 60 | 5. **Giving Back:** If PHP has helped your business grow, here's your chance to return the favor. 61 | 6. **Tech Cred:** Nothing says "we're serious about web development" like sponsoring a major programming language. 62 | 63 | ## Ready to Jump In? 64 | 65 | Here's how you can get started: 66 | 67 | 1. Check out our sponsorship tiers on our website: [thephp.foundation/sponsor](https://thephp.foundation/sponsor/). 68 | 2. Reach out to us at [contact@thephp.foundation](mailto:contact@thephp.foundation). 69 | 3. Let's chat about how we can make this partnership beneficial for both of us. 70 | Office hours call: [cal.com/pronskiy/php-foundation-office-hours](http://cal.com/pronskiy/php-foundation-office-hours) 71 | 72 | ## Stay in the Loop 73 | 74 | Don't miss out on any PHP Foundation news. Follow us on: 75 | 76 | * LinkedIn: [PHP Foundation](https://www.linkedin.com/company/phpfoundation) 77 | * Twitter/X: [@ThePHPF](https://x.com/thephpf) 78 | * Mastodon: [@thephpf@phpc.social](https://phpc.social/@thephpf) 79 | 80 | 81 | And for those who prefer their news in their inbox, subscribe to our email newsletter. We send ~1–2 emails a month – just the good stuff about PHP and the Foundation. 82 | 83 | {% include "newsletter.html" %} 84 | 85 | P.S. If you have any questions or wild ideas about how you'd like to support PHP, don't hesitate to reach out. We're all ears. 86 | -------------------------------------------------------------------------------- /source/_posts/2024-10-08-open-source-pledge.md: -------------------------------------------------------------------------------- 1 | --- 2 | title: 'The PHP Foundation Supports The Open Source Pledge' 3 | layout: post 4 | tags: 5 | - news 6 | author: 7 | - name: Roman Pronskiy 8 | url: https://twitter.com/pronskiy 9 | published_at: 8 October 2024 10 | 11 | --- 12 | 13 | The PHP Foundation is proud to announce our support for the Open Source Pledge initiative, launched by Sentry and its partners. This step addresses the sustainability challenges within the Open Source Software (OSS) community, particularly affecting PHP and its ecosystem. 14 | 15 | ## The Open Source Pledge: A Commitment to Sustainability 16 | 17 | The Open Source Pledge represents a commitment from member companies to provide meaningful financial support to Open Source maintainers. This initiative aims to prevent maintainer burnout and reduce the risk of high-profile security incidents that can impact the broader tech ecosystem. 18 | 19 | The OSS community, including PHP, faces significant challenges: 20 | 21 | * **Security risks:** High-profile incidents like Log4shell, XZ, and Heartbleed have highlighted the potential consequences of under-resourced projects. 22 | * **Developer burnout:** Many maintainers, often volunteers, are feeling exhausted and leaving the very projects you might be using. 23 | * **Losing maintainers:** The demanding nature of maintaining open-source software means we’re seeing fewer contributors over time. 24 | 25 | ## The PHP Foundation's Role 26 | 27 | As the main funder and steward of the PHP language, we’ve seen firsthand how a lack of funding impacts crucial projects. For example: 28 | 29 | * **Core language development:** Keeping PHP up to date and improving it takes a lot of time and expertise. 30 | * **Security support:** Without enough funding, PHP can’t address vulnerabilities quickly. 31 | * **Extension maintenance:** Many essential PHP extensions are struggling to find people to maintain them. 32 | * **Documentation efforts:** Keeping PHP’s extensive documentation current is always a big challenge. 33 | 34 | # How to Join the Pledge 35 | 36 | The Open Source Pledge offers a structured approach to supporting OSS with the following requirements: 37 | 38 | * Minimum contribution: $2,000 per year, per developer on staff. 39 | * Transparency: Companies should publish annual reports detailing their payments. 40 | * Direct impact: Funds go directly to maintainers, supporting their crucial work. 41 | 42 | Thanks to supporting the PHP Foundation, our major sponsors [Private Packagist](https://packagist.com/) and [Tideways](https://tideways.com/) are already part of the [Open Source Pledge](https://opensourcepledge.com/). 43 | 44 | # \[Action Required\] Join the Pledge\! 45 | 46 | We urge PHP-based companies, developers, and organizations to join the Open Source Pledge and **[sponsor The PHP Foundation](https://thephp.foundation/sponsor/)**. 47 | 48 | To learn more about the Open Source Pledge and how you can participate, visit [https://opensourcepledge.com/](https://opensourcepledge.com/). 49 | 50 | Help us spread the word by sharing this post. 51 | 52 | 💜️ 🐘 53 | -------------------------------------------------------------------------------- /source/_posts/2024-11-19-pie-pre-release.md: -------------------------------------------------------------------------------- 1 | --- 2 | title: 'Announcing the Pre-Release of the PHP Installer for Extensions (PIE)' 3 | layout: post 4 | tags: 5 | - news 6 | author: 7 | - name: James Titcumb 8 | url: https://phpc.social/@asgrim 9 | published_at: 19 November 2024 10 | --- 11 | 12 | We're thrilled to introduce the pre-release of the PHP Installer for Extensions (PIE) – [**github.com/php/pie**](https://github.com/php/pie)! 13 | 14 | PIE aims to simplify managing PHP extensions by providing a modern, flexible alternative to PECL and treating extensions as first-class citizens in the PHP ecosystem. 15 | 16 |17 | PIE development is commissioned by the Sovereign Tech Agency. 18 |19 | 20 | This initial pre-release is available as a [PHAR download](https://github.com/php/pie/releases/tag/0.2.0), and we invite you to take it for a spin and share your feedback. While this release is an exciting milestone, we know there's a lot more work ahead to make PIE ready for widespread use, so your feedback is invaluable. If you encounter any issues, or have any questions, feel free to open an [issue on GitHub](https://github.com/php/pie/issues), and help us shape the future of PIE. 21 | 22 | ## Why PIE? 23 | 24 | With PIE, the process of managing PHP extensions becomes more streamlined. Extensions are distributed via [Packagist](https://packagist.org/extensions) just like regular PHP packages! It makes the installation and update process quite familiar if you already use Composer. 25 | 26 | We’re working to make PIE stronger and easier to use. We’re improving how PHP extensions are managed and using ideas from Composer to make the process smoother. 27 | 28 | ## Are you an extension author? 29 | 30 | Extensions do need to be made compatible with PIE by adding a `composer.json` (more instructions [here](https://github.com/php/pie/blob/main/docs/extension-maintainers.md)), and submitting it to [Packagist](https://packagist.org/packages/submit). Once a package has added support for PIE, it will appear on the Packagist [Extensions list](https://packagist.org/extensions) page. 31 | 32 | 💜️🐘 33 | -------------------------------------------------------------------------------- /source/_posts/2024-11-22-php-foundation-turns-three.md: -------------------------------------------------------------------------------- 1 | --- 2 | title: 'The PHP Foundation Turns Three!' 3 | layout: post 4 | tags: 5 | - news 6 | author: 7 | - name: Roman Pronskiy 8 | url: https://twitter.com/pronskiy 9 | published_at: 22 November 2024 10 | --- 11 | 12 | Wow. Can you believe it? Just three years (and one day) ago, PHP had no organization behind it. Only two people were being paid to work on the language that powers 70% of the web. 13 | 14 | Here’s the very first announcement about the creation of the PHP Foundation: 15 | [The New Life of PHP – The PHP Foundation](https://blog.jetbrains.com/phpstorm/2021/11/the-php-foundation/). 16 | 17 | ## Fast forward to today 18 | 19 | We now have a team of 10 talented engineers dedicated to PHP. We’re supported by major companies, governments, and an incredible community. That same community is creating amazing projects with PHP, while businesses continue to thrive thanks to a mature, secure, and performant language. 20 | 21 | Since 2021, we’ve seen three PHP releases—PHP 8.2, 8.3, and the freshly released [PHP 8.4](https://www.php.net/releases/8.4/en.php). Here are just a few highlights from these releases, developed by the PHP Foundation team: 22 | 23 | - [Property hooks](https://wiki.php.net/rfc/property-hooks) 24 | - [Asymmetric Visibility](https://wiki.php.net/rfc/asymmetric-visibility-v2) 25 | - [Lazy Objects](https://wiki.php.net/rfc/lazy-objects) 26 | - [New tool for installing extensions: pie](https://thephp.foundation/blog/2024/11/19/pie-pre-release/) 27 | - [Support object type in BCMath](https://wiki.php.net/rfc/support_object_type_in_bcmath) 28 | - [Saner Increment/Decrement operators](https://wiki.php.net/rfc/saner-inc-dec-operators) 29 | - Multiple type system improvements: [null and false as stand-alone types](https://wiki.php.net/rfc/null-false-standalone-types), [Disjunctive Normal Form Types](https://wiki.php.net/rfc/dnf_types) 30 | - [Readonly amendments](https://wiki.php.net/rfc/readonly_amendments) 31 | - [Dynamic class constant fetch](https://wiki.php.net/rfc/dynamic_class_constant_fetch) 32 | - [Arbitrary static variable initializers](https://wiki.php.net/rfc/arbitrary_static_variable_initializers) 33 | 34 | ## Feature development is only about 20% of what the foundation team does 35 | 36 | Behind the scenes, there’s a lot more: triaging and fixing issues, handling security reports, reviewing code, updating documentation, and maintaining infrastructure. All of this work empowers the community and ensures PHP is stable and reliable. 37 | 38 | Here are some highlights: 39 | 40 | - The total contributions to the PHP repositories grew by 51+% 41 | - We conducted the first external security audit for PHP in 10 years 42 | - We extended security support for PHP versions by one year 43 | - We improved CI and testing infrastructure 44 | - We introduced automated benchmarks to track performance regressions 45 | 46 | None of this would be possible without our sponsors. Huge thanks to every company and individual who has supported us over the past three years! 47 | 48 | Special shout-outs to: 49 | JetBrains, Automattic, Sovereign Tech Agency, Craft CMS, Private Packagist, Tideways, Zend by Perforce, Laravel, Symfony, Mercari Inc., Les-Tilleuls.coop, pixiv Inc., Aternos GmbH, Sentry, Ardennes-étape, Cybozu, 50 | 51 | and many others — PHP is all of us! 52 | 53 | If you haven’t already, please consider [sponsoring the PHP Foundation](https://thephp.foundation/sponsor/) 🙏 54 | 55 | Here’s to PHP and many more years ahead! 56 | 🐘💜 57 | -------------------------------------------------------------------------------- /source/_posts/2024-12-23-happy-holidays-from-the-php-foundation.md: -------------------------------------------------------------------------------- 1 | --- 2 | title: 'Happy Holidays from The PHP Foundation!' 3 | layout: post 4 | tags: 5 | - news 6 | author: 7 | - name: Roman Pronskiy 8 | url: https://twitter.com/pronskiy 9 | published_at: 23 December 2024 10 | --- 11 | 12 | As 2024 comes to a close, we at the PHP Foundation want to take a moment to thank everyone who has supported us this year. It’s been an incredible journey, and we couldn’t have done it without the amazing PHP community and our generous sponsors. 13 | 14 | ## A Year of Milestones 15 | 16 | In [its third year](https://thephp.foundation/blog/2024/11/22/php-foundation-turns-three), the PHP Foundation has achieved several milestones that have further strengthened the PHP ecosystem: first in a decade [security audit](https://thephp.foundation/blog/2024/11/22/php-foundation-turns-three/#feature-development-is-only-about-20%25-of-what-the-foundation-team-does), [pie](https://thephp.foundation/blog/2024/11/19/pie-pre-release/), numerous features and improvements for [PHP 8.4](https://www.php.net/releases/8.4/en.php), and much more to come next year! 17 | 18 | ## Celebrating Our Sponsors 19 | 20 | We owe a special thanks to our major sponsors who make our work possible: 21 | 22 | ### Platinum 23 | 24 | [**Sovereign Tech Agency**](https://www.sovereign.tech/) 25 | 26 | [**JetBrains**](https://www.jetbrains.com/) 27 | 28 | [**Automattic**](https://automattic.com/) 29 | 30 | ### Gold 31 | 32 | [**Laravel**](https://laravel.com/) 33 | 34 | [**GoDaddy**](https://www.godaddy.com/) **\[new! ✨\]** 35 | 36 | ### Silver 37 | 38 | [**Private Packagist**](https://packagist.com/) 39 | 40 | [**Craft CMS**](https://craftcms.com/) 41 | 42 | [**Cybozu**](https://cybozu.co.jp/en/company/) 43 | 44 | [**Tideways**](https://tideways.com/) 45 | 46 | [**Zend by Perforce**](https://www.zend.com/) 47 | 48 | [**Symfony Corp**](https://symfony.com/) 49 | 50 | [**Sentry**](https://sentry.io/welcome/) 51 | 52 | [**Manychat**](https://manychat.com/) **\[new! ✨\]** 53 | 54 | [**Mercari Inc.**](https://www.mercari.com/) 55 | 56 | [**Les-Tilleuls.coop**](http://Les-Tilleuls.coop) 57 | 58 | [**pixiv Inc.**](https://www.pixiv.net/en/) 59 | 60 | [**Aternos GmbH**](https://aternos.gmbh/en/) 61 | 62 | [**CH Studio**](https://chstudio.fr/en/homepage/) 63 | 64 | Big thanks to newly joined major sponsors: [**GoDaddy**](https://www.godaddy.com/) and [**Manychat**](https://manychat.com/)! 65 | 66 | Your contributions enable us to support developers, fund crucial projects, and ensure PHP is a modern and reliable choice for web development. 67 | 68 | If you are yet to decide on sponsoring the foundation, [here](https://thephp.foundation/blog/2024/09/30/call-fo-sponsors/) you can find information on how to join us and why it matters. 69 | 70 | ## Wishing You Joyful Holidays ✨ 71 | 72 | To everyone in the PHP community, we wish you a joyful holiday season filled with warmth, happiness, and a well-deserved break. Thank you for your support, passion, and commitment to PHP. 73 | 74 | Here’s to a wonderful 2025! 🥂 75 | 76 | Warm wishes, 77 | The PHP Foundation 78 | 🐘💜 79 | -------------------------------------------------------------------------------- /source/_posts/2025-01-31-laracons.md: -------------------------------------------------------------------------------- 1 | --- 2 | title: 'Proud to Be Community Sponsors of Laracon EU and Laracon India' 3 | layout: post 4 | tags: 5 | - news 6 | author: 7 | - name: Roman Pronskiy 8 | url: https://twitter.com/pronskiy 9 | published_at: 30 January 2025 10 | --- 11 | 12 | The PHP Foundation is thrilled to announce our community sponsorship of both Laracon EU and Laracon India! We believe in the power of in-person connections and are excited to support these conferences as they bring together PHP enthusiasts from around the world. 13 | 14 | ## [Laracon EU](https://laracon.eu/) 15 | 16 | * **Location:** Amsterdam, Netherlands 17 | * **Date:** February 3–4 18 | * **Meet us:** This year at Laracon EU you can meet [Roman Pronskiy](https://www.linkedin.com/in/pronskiy), [Sebastian Bergmann](https://www.linkedin.com/in/sebastian-bergmann-phpunit), and [Nils Adermann](https://www.linkedin.com/in/nilsadermann/) from the PHP Foundation board. Can you spot our first ever conference banner? 19 | 20 | ## [Laracon India](https://laracon.in/) 21 | 22 | * **Location:** Ahmedabad, India 23 | * **Date:** March 8–9 24 | * **Sponsorship:** Laracon India [welcomes sponsors](https://docs.google.com/forms/d/e/1FAIpQLScQTQJA9tnpwnED3Af61EyewEr7T2bybBR5GJ3MUd3x52FhrA/viewform) who are eager to support the Laravel community and connect with talented developers in India. 25 | 26 | ## Let's Collaborate! 27 | 28 | The PHP Foundation is committed to fostering the growth and development of the PHP ecosystem. We’re excited to collaborate with and support (non-financially) PHP conferences and meetups worldwide! 29 | 30 | 📩 Get in touch: contact@thephp.foundation. 31 | 32 | Here are a few upcoming events to watch for: 33 | 34 | * [PHP UK Conference 2025](https://www.phpconference.co.uk/) – London, UK, February 19. 35 | * [Dutch PHP Conference](https://phpconference.nl/) – Amsterdam, March 18–21. 36 | * [PHP Conference Odawara 2025](https://phpcon-odawara.jp/2025/) – Japan, April 12. 37 | * [PHPDay](https://www.phpday.it/) – Verona, May 16-17. 38 | * [php\[tek\] 2025](https://phptek.io/) – Chicago, IL, USA, May 20-22. 39 | * [PHPers Summit 2025](https://summit.phpers.pl/en/) – Poznań, Poland, 24-25 May. 40 | * [International PHP Conference](https://phpconference.com/berlin-en/) – Berlin, June, 3–5. 41 | 42 | 🐘💜 43 | -------------------------------------------------------------------------------- /source/_posts/2025-04-03-welcoming-passbolt-to-the-php-foundation.md: -------------------------------------------------------------------------------- 1 | --- 2 | title: 'Welcoming Passbolt to the PHP Foundation' 3 | layout: post 4 | tags: 5 | - news 6 | - sponsors 7 | author: 8 | - name: Roman Pronskiy 9 | url: https://twitter.com/pronskiy 10 | published_at: 3 April 2025 11 | --- 12 | 13 | We’re thrilled to announce that **Passbolt has joined the PHP Foundation** as a Silver sponsor! PHP powers over 77% of the web – including Passbolt’s collaborative password and secrets manager. Their support strengthens our mission to keep it thriving. 14 | 15 | Check out their heartfelt announcement here: **[Passbolt’s Blog](https://www.passbolt.com/blog/a-love-letter-passbolt-joins-the-php-foundation-as-a-company-member)**. 16 | 17 | The Foundation funds developers to ensure PHP remains fast, secure, and innovative. With Passbolt and many other industry leaders by our side, we’re building a sustainable future for the language we all rely on. 18 | 19 | > This post kicks off a new blog series highlighting our amazing sponsors. Stay tuned as we spotlight the companies and individuals driving PHP forward – each one a vital part of our community’s success. 20 | 21 | Want to join the effort? [Sponsor The PHP Foundation](https://thephp.foundation/sponsor/) and help us power the web’s backbone! 22 | 23 | 🐘💜 24 | -------------------------------------------------------------------------------- /source/_posts/2025-04-10-php-core-security-audit-results.md: -------------------------------------------------------------------------------- 1 | --- 2 | title: 'PHP Core Security Audit Results' 3 | layout: post 4 | tags: 5 | - news 6 | author: 7 | - name: Roman Pronskiy 8 | url: https://twitter.com/pronskiy 9 | published_at: 10 April 2025 10 | --- 11 | 12 | The PHP Foundation is pleased to announce the completion of a comprehensive security audit of the PHP source code ([php/php-src](https://github.com/php/php-src)), **commissioned by the [Sovereign Tech Agency](https://www.sovereign.tech/)**. 13 | 14 | This initiative was organized in partnership with the [Open Source Technology Improvement Fund](https://ostif.org/) (OSTIF) and executed by the esteemed security group [Quarkslab](https://www.quarkslab.com/). 15 | 16 | ## Audit Overview 17 | 18 | Conducted over a two-month period in 2024, the audit encompassed: 19 | 20 | * Development of a threat model tailored to php-src 21 | * Manual code reviews 22 | * Dynamic testing procedures 23 | * Cryptographic assessments 24 | 25 | The collaboration between Quarkslab’s auditors and PHP maintainers ensured a thorough examination of the codebase. 26 | 27 | > _⚠️_ 28 | Due to budget constraints, the recent security audit focused on the most critical components of the PHP source code rather than the entire codebase. Organizations interested in sponsoring a comprehensive audit or additional assessments are encouraged to [contact us](mailto:contact@thephp.foundation)! 29 | > _⚠️_ 30 | 31 | ## Key Findings 32 | 33 | The audit identified 27 issues, with 17 having security implications: 34 | 35 | * 3 High-severity 36 | * 5 Medium-severity 37 | * 9 Low-severity 38 | 39 | Additionally, 10 informational findings were reported. 40 | 41 | Notably, four vulnerabilities received CVE identifiers: 42 | 43 | * CVE-2024-9026: Log tampering vulnerability in PHP-FPM, allowing potential manipulation or removal of characters from log messages. 44 | * CVE-2024-8925: Flaw in PHP’s multipart form data parsing, potentially leading to data misinterpretation. 45 | * CVE-2024-8929: Issue where a malicious MySQL server could cause the client to disclose heap content from other SQL requests. 46 | 47 | ## Recommendations and Resolutions 48 | 49 | Quarkslab’s report commended the overall high quality and specification adherence of the php/php-src project. 50 | 51 | The PHP development team has addressed all identified issues. Users are strongly encouraged to upgrade to the latest PHP versions to benefit from these security enhancements. 52 | 53 | ## Acknowledgments 54 | 55 | We extend our gratitude to the individuals and organizations that made this audit possible: 56 | 57 | * **The PHP Foundation Team and PHP maintainers:** 58 | Jakub Zelenka, Arnaud Le Blanc, Niels Dossche, Ilija Tovilo, Stas Malyshev, Dmitry Stogov, Derick Rethans, and Roman Pronskiy. 59 | * **Quarkslab Team:** 60 | Angèle Bossuat, Julio Loayza Meneses, Mihail Kirov, Sebastien Rolland, Ramtine Tofighi Shirazi. 61 | * **Sovereign Tech Agency:** 62 | Abigail Garner and the team – for commissioning the audit and all the help. 63 | * **OSTIF:** 64 | Amir Montazery, Derek Zimmer, Helen Woeste – for organizing the collaboration. 65 | 66 | This audit underscores our commitment to enhancing PHP’s security and reliability. We remain dedicated to ongoing improvements and collaborations to ensure PHP’s robustness for the global development community. 67 | 68 | ## Further Reading 69 | 70 | * [Audit Report](/assets/files/24-07-1730-REP-V1.4_temp.pdf) 71 | * [OSTIF Blog](https://ostif.org/php-audit-complete/) 72 | * [Quarkslab Blog](https://blog.quarkslab.com/security-audit-of-php-src.html) 73 | 74 | If your company is interested in commissioning another round of security audit, please contact The PHP Foundation team: [contact@thephp.foundation](mailto:contact@thephp.foundation). 75 | 76 | 🐘💜 77 | -------------------------------------------------------------------------------- /source/_posts/2025-05-09-manychat-powered-by-php.md: -------------------------------------------------------------------------------- 1 | --- 2 | title: 'Meet Manychat: A PHP Foundation Sponsor Sharing Their PHP Scaling Journey' 3 | layout: post 4 | tags: 5 | - news 6 | - sponsors 7 | author: 8 | - name: Roman Pronskiy 9 | url: https://twitter.com/pronskiy 10 | published_at: 9 May 2025 11 | --- 12 | 13 | At the PHP Foundation, we’re proud to be supported by companies that build amazing products and contribute back to the PHP ecosystem. Today we’d like to highlight [Manychat](https://manychat.com/?utm_source=phpfoundation&utm_medium=site&utm_campaign=casestudy) — one of our Silver sponsors. 14 | 15 | Manychat is the world’s leading chat marketing platform, helping businesses connect with their customers on Instagram, WhatsApp, Facebook Messenger, and beyond. With over **1 billion conversations powered every year** across **170+ countries**, Manychat is a great example of how PHP scales and supports high-traffic applications around the world. 16 | 17 | ## Why PHP? Because Speed Wins 18 | 19 | In their recently published case study — _[How Manychat Scaled to 1 Billion Conversations Using PHP](https://medium.com/manychat-engineering/how-manychat-scaled-to-1-billion-conversations-using-php-a-startups-guide-to-smart-tech-choices-781c74f16f23)_ — the Manychat team shares the story of how PHP helped them go from a tiny startup with just one developer to a platform supporting millions of users. 20 | 21 | > _“We could build right away — our only developer already knew PHP, so we skipped onboarding and got straight to work.”_ 22 | 23 | By choosing PHP, Manychat was able to build their MVP in just a few days and start learning from real users immediately. As they grew, they faced the familiar scaling challenges of high traffic, heavy workloads, and resource management. Their case study provides mentions architectural decisions they made — from using asynchronous request handling with NGINX + Lua, to optimizing background task processing with PHP-CLI workers, and managing database connections efficiently with PgBouncer. 24 | 25 | ## PHP at the Heart of a Global Platform 26 | 27 | Today Manychat’s platform continues to run on PHP, handling millions of API calls and conversations while keeping infrastructure costs under control. 28 | 29 | If you’re excited about building products that reach millions and love working with PHP at scale, check out the [open positions at Manychat](https://careers.manychat.com/team/engineering?utm_source=phpfoundation&utm_medium=site&utm_campaign=casestudy). They’re hiring PHP engineers! 30 | 31 | ## Supporting the Community 32 | 33 | Manychat isn’t just building with PHP — they’re giving back to the community. As a **Silver sponsor** of the PHP Foundation, they help us fund initiatives that keep PHP stable, modern, and accessible to millions of developers worldwide. 34 | 35 | In addition, Manychat is active in the tech community, hosting [PHP meetups and events](https://www.eventbrite.com/o/manychat-46565622503) in **Barcelona** and **Amsterdam**. We love seeing our sponsors not only build great products but also foster connections between developers around the world. 36 | 37 | ## Read Their Story 38 | 39 | We encourage you to check out their full case study on scaling with PHP: 40 | 41 | 👉 _[How Manychat Scaled to 1 Billion Conversations Using PHP](https://medium.com/manychat-engineering/how-manychat-scaled-to-1-billion-conversations-using-php-a-startups-guide-to-smart-tech-choices-781c74f16f23)_ 42 | 43 | 44 | **Thank you, Manychat, for your support!** 45 | 46 | 🐘💜 47 | 48 |