Every dynamic page a LAMP server produces passes through PHP. Linux keeps the processes alive, Apache 129 accepts the connection and MySQL 524 holds the rows, but the decision about what a visitor actually sees (which products, in what order, whether the login worked, what the error says) is made by a few hundred lines of PHP that run, print and forget on every request.
PHP has changed more in the last decade than its reputation suggests. The language you will write here has strict types, enums, readonly classes, property hooks, first-class callables, attributes, a pipe operator and a JIT compiler. Much of the PHP 5 code in old tutorials no longer runs at all: mysql_*, each(), create_function() and mcrypt are gone. Every example in this chapter is written for PHP 8.5, the current stable series, and was run on PHP 8.5 before its output was printed. Where a feature arrived in an earlier release, the text says so, so you know what an older server can use.
The chapter moves from the engine outward. It starts with how PHP sits behind Apache and how a request becomes a page, then covers the language itself: types, operators, functions, arrays, strings, dates, files and the object model through interfaces, traits, generators, enums and attributes. From there it turns to the work a web application does: Composer 5,243 and autoloading, error handling and logging, forms and validation, sessions and uploads, database access with PDO and prepared statements, security, JSON and HTTP APIs, and email and images. It finishes with the tools that keep code honest in production: PHPUnit 79,198 , debugging and static analysis, OPcache and PHP-FPM tuning, and asynchronous PHP.
MySQL taught the SQL, so the database sections here cover only the PHP side of the conversation. Laravel builds on all of it with Laravel 2,157 , which is PHP code organized by conventions: everything you learn here is what runs underneath.
What you will learn
How PHP runs under the CLI, PHP-FPM and mod_php, and where each one reads its configuration
PHP 8.5's type system, strict mode, and the comparison rules that catch newcomers out
Functions, closures, arrays and strings, including the 8.4 and 8.5 additions such as the pipe operator
Modern object-oriented PHP: readonly classes, enums, property hooks, attributes and interfaces
Namespaces, PSR-4 autoloading and Composer
Handling forms, sessions, cookies and uploads, and talking to MySQL safely through PDO
Defending against injection, XSS, CSRF and weak password storage
Testing with PHPUnit, debugging with Xdebug 16,266 , static analysis, and tuning OPcache and PHP-FPM
Sections
- PHP on the Server
- Syntax, Variables and Types
- Operators and Control Flow
- Functions and Closures
- Arrays and the Array Library
- Strings and Regex
- Numbers, Dates and Time Zones
- Files, Directories and Streams
- Classes and Objects
- Interfaces and Generators
- Enums and Attributes
- Namespaces and Composer
- Errors, Exceptions and Logging
- Requests and Forms
- Sessions and Uploads
- Databases with PDO
- PDO, mysqli and Why PDO Wins
- Connecting with PDO
- Error Modes and Exceptions
- query, exec, prepare
- Placeholders
- Emulated vs Native
- Binding
- Placeholder Limits
- Fetch Modes
- Inserts and IDs
- Transactions
- Special Column Types
- Character Sets
- Pdo\Mysql
- A Repository Class for a Table
- Connection Handling
- Query Builders and ORMs
- Security
- JSON, cURL and HTTP APIs
- Email, Images and Documents
- Testing with PHPUnit
- Why Tests Pay for Themselves
- Setting Up PHPUnit
- Your First Test Case
- Assertions Worth Knowing
- Fixtures, setUp and tearDown
- Data Providers
- Testing Exceptions and Errors
- Stubs and Mocks
- Mockery and Hand-Written Fakes
- Testable Code
- Time and File System
- Database Tests
- HTTP Handler Tests
- Code Coverage
- CI and Mutation Testing
- Debugging and Analysis
- Performance and OPcache
- Asynchronous PHP
- Test Yourself!