PHP devs determined to keep their record of the least secure and buggiest web technology in human history.
My hatred for ai Bros is unbounded
Why are open source devs either the coolest people ever or a straight up piece of shit incapable of doing the bare minimum?
For popular open source projects, you’re under really specific pressures that aren’t immediately obvious to onlookers, so either they can’t handle the pressure or their decisions seem inscrutable (or both). There’s good talk about this called The Hard Parts of Open Source that walks through a lot of it. And then of course some people are just unbearable on top of it. Talent for programming has very little correlation with quality of character.
Yeah on popular projects I can only imagine the amount of pressure these devs must be under. I meant more in general because I’ve seen these 2 types of behavior independently of the size of the project, including small sutff. I’ll watch the video you linked to be better informed, thanks!
For sure. I think for some people the amount of power required to corrupt them is just “barely any”. I think competently and respectfully managing your responsibility over others’ work is also a skill that can be developed but in general not taught unless absolutely necessary. Let me know what you think of the talk. It’s one of my favorites!
I found a YouTube link in your comment. Here are links to the same video on alternative frontends that protect your privacy:
Man if you’re vibe coding anyway why the fuck would you do it in PHP
Why PHP for anything in this tyool 2026
I use Bookstack at work for a docsite since it’s more structured than a mediawiki and most people I work with are pretty tech illiterate.
The bookstack team is pretty cool too, they migrated the whole project to Codeberg and aren’t fans of AI.
I’m maintaining a large PHP/jQuery/React codebase that’s over 20 years old. 20 years ago was the second rewrite of the system and at this point it’s just too big to do another rewrite. Reasons to not rewrite:
- Many parts of the system have been hardened by a dozen different audits, security reviews, bug fixes, etc.
- There are parts of the system which are complicated and were written by people who no longer work here using requirements written by people who also no longer work here. Sometimes, those requirements were written two or three acquisitions ago.
- 10% of our features are used by 90% of our clients but 90% of our clients only use 10% of our features. So you can rewrite some random feature to modernize it, but if even if you’re careful not to change any output, you’ll still get a client with a multi-million dollar contract upset that their 1 dealbreaker feature is now broken (maybe they’re the only one that uses it).
- Oh, and we have members of the PHP steering committee on our team. So it would be a major waste to not use PHP lol. But that’s not nearly as common of a reason
I get it, I work on a 15 year old rails app that I wouldn’t implement the same way today but which cannot be replaced for similar reasons. But legacy is one thing, doing new development in PHP is another
Oh I misunderstood. Yeah, I agree. There’s an odd amount of hype around the fact the PHP now has more modern language features. I guess if you want something very batteries included I guess I could see looking at Laravel. But not if you want an AI-first experience. You really as much static analysis and inline documentation as possible
PHP is still the easiest technology to get managed hosting for.
No because why would he do this of all things? The agents are all going to be of mixed quality depending on user ability and means.
The users in question, being devs, usually open issues when they do not know how to fix it themselves. Telling me, or my LLM slop agent by proxy, to fix their software and then make maintainers (likely not this dipasss who owns the projects) is how you end up with sloppy quality and spam.
sloppy quality and spam
In the PHP ecosystem? My goodness!
What an absolute garbage way to handle change and issue management
Still smarter than running your project from a discord channel.
Lol I’ve tried to open issues and PRs to fix said issues in the past, and Taylor always would tell me no.
The only thing I’ve ever gotten to contribute was some tests that covered unexpected behavior in helper functions that he admitted should be fixed but didn’t want to deal with because it was for an older version that he didn’t want to support anymore. Which is fair, and I know that maintaining an open source framework is a pita, but he comes across as a huge dick
Sorta feels like this move is just gonna make more problems 🫠
Id do this to then tell everyone that I have reduced issues to zero then instantly close all ai PRs as le epic troll.
This also doesn’t make any sense for any kind of issue triage since a good portion of problems don’t have any code to fix at all but comes from user misunderstanding.
Setting aside all the OTHER ways this is idiotic, nice working alienating every dev who doesn’t have access to coding agents.
Ya, don’t those generally cost money?











