5 ms·
PHP has a few downsides, everything from poor naming conventions to security vulnerabilities. People around these parts are always looking for the cleanest sol
by coglethorpe 17y ago
PHP has a few downsides, everything from poor naming conventions to security vulnerabilities. People around these parts are always looking for the cleanest solutions to their problems and the latest methods available. PHP's relative age and problems make it neither.
That said, I coded my first startup in PHP. It's dead simple to make a dynamic web page with PHP, but it's also dead simple to create a huge mess. In that sense, PHP reminds me of C. It's pretty simple to write an app in C, but there are 1,000 pitfalls.
Just like with C, there are definitely talented coders out there who can make PHP behave correctly. Sadly, they are a minority. Many of them move on to other languages and frameworks.
I've since moved on to Ruby (on Rails) as well as Python. Both languages offer simplicity and power. Rails, in spite of being the Dane Cook of frameworks, makes it extremely easy to create a web application.
- j2d2 17y agoWell said. I would recommend Django to people who prefer Python to Ruby.
- rbanffy 17y agoDjango is Rails, without the toxic company. That's why I am unsure about Zed Shaw at EuroDjangoCon. I love to have smart and capable people around, but Zed still has to prove he can play well with others.
- JustAGeek 17y agoI agree with more or less with what you said but a downside of PHP is not security vulnerabilities, that's really just a myth. I can't remember the last vulnerability which could be directly attributed to PHP as a language. Sure, there are plenty of apps containing holes but those are not caused by PHP but by not coding correctly, eg not checking input making SQL injections possible etc. Which might confirm what you said, it's easy to create a huge mess with PHP. But then, it's easy to create a huge mess in any other language, too. It's probably even easier with Ruby due to its highly dynamic nature. Languages are like tools, you have to know how to use it but you can't blame the tool if somebody misuses it. Edit: Fixed typo.
- pavel_lishin 17y agoThe security issues mostly come from the community; PHP is branded as a language that's easy to learn, and in that same spirit, a lot of the examples offered by the manual and by people trying to teach others are horribly insecure. I think nearly every SQL example, for instance, totally ignores the concept of SQL injection.
- hapless 17y agoLanguages are like tools: buying a the best set you can afford is the best possible start to a project. PHP doesn't cause SQL injection flaws, but it doesn't make it any easier. How many escape functions are there ? Shall we count them ? ---------- mysql_escape_string() - Escapes a string for use in a mysql_query mysql_real_escape_string() - Escapes special characters in a string for use in a SQL statement mysqli_real_escape_string() - Escapes special characters in a string for use in a SQL statement, taking into account the current charset of the connection addslashes() - Quote string with slashes stripslashes() - Un-quotes a quoted string The magic_quotes_gpc directive The magic_quotes_runtime directive stripcslashes() - Un-quote string quoted with addcslashes stripslashes() - Un-quotes a quoted string addcslashes() - Quote string with slashes in a C style htmlspecialchars() - Convert special characters to HTML entities quotemeta() - Quote meta characters get_magic_quotes_gpc() - Gets the current configuration setting of magic quotes gpc ---------------- I especially love the contrast between "mysql_escape_string" and "mysql_real_escape_string," since the first one is fake in a magical, side-effect-laden way.
- EliAndrewC 17y agoI think this comment sums it up nicely: http://blog.ianbicking.org/php-ghetto-comment-11.html http://blog.ianbicking.org/php-ghetto-comment-11.html It basically argues that in PHP there's often an easy, insecure way to do something and a verbose, secure way to do it. With regards to SQL injection, Java is the same way; prepared statements are much more verbose and annoying than string concatenation.
- rbanffy 17y agoI regard string concatenation as very annoying in Java. Actually, just about anything is annoying in Java. I guess I have been spoiled by more modern languages like... Smalltalk/80 or Lisp'56.
- jlsonline 17y agoAmusing. Rails as the "Dane Cook" of web frameworks pretty much hits the nail on the head. I love Rails but the fanboy culture really sucks.
- whacked_new 17y agoThat reads to me as "Rails is a pop culture icon that only XYZ people know about." I'm not XYZ because I don't know who that is. Actually, perhaps unintentionally, you still hit the nail on the head.
- JoelMcCracken 17y agoBe glad.
- coglethorpe 17y agoGlad to be your unintentional hammer. Dane Cook is a comedian who hit it BIG, in part, due to MySpace. He's been in a couple of movies, including "Employee of the Month." He's got millions of fans, but also a sizeable group of haters, inlcuding many of his fellow comedians. He's just another in a series of people or items that hit it big, leaving many of us wondering why.
- zacharydanger 17y agoCould it be that he's hated because he steals material?
- coglethorpe 17y agoWell, I didn't want to get into the details here, but yes, that's part of it. :-) He's also been criticized for not actually telling jokes when it is his material, being/attracting the worst sort of humanity, etc.
- zackattack 17y agoA worse insult would be calling it the 'Carlos Mencia of frameworks'.
- dbul 17y agoJust like with C, there are definitely talented coders out there who can make PHP behave correctly. Sadly, they are a minority. Many of them move on to other languages and frameworks. What does that mean? I'll take the compliment, but I'm not sure what the difficulty is in making PHP 'behave correctly.'
- Brentley_11 17y agoI think PHP compares well to the saying "Guns don't kill people, people kill people." Most of the time security issues are in the hands of the programers. Although, PHP sure makes it easy sometimes to create those issues.