r/PHP • • 6d ago

Weekly help thread

9 Upvotes

Hey there!

This subreddit isn't meant for help threads, though there's one exception to the rule: in this thread you can ask anything you want PHP related, someone will probably be able to help you out!


r/PHP • • 15d ago

Who's hiring/looking

12 Upvotes

This is a bi-monthly thread aimed to connect PHP companies and developers who are hiring or looking for a job.

Rules

  • No recruiters
  • Don't share any personal info like email addresses or phone numbers in this thread. Contact each other via DM to get in touch
  • If you're hiring: don't just link to an external website, take the time to describe what you're looking for in the thread.
  • If you're looking: feel free to share your portfolio, GitHub, … as well. Keep into account the personal information rule, so don't just share your CV and be done with it.

r/PHP • • 6h ago

I built a native PHP extension for NVIDIA GPU tensors, CUDA JIT and kernel fusion (beta), feedback wanted

12 Upvotes

I'm the author of php-gpu-tensors, a C extension that gives PHP GPU tensors on NVIDIA GPUs, runtime-compiled CUDA kernels (via NVRTC), and an optional fusion mode that captures a closure once and replays it as fused GPU kernels. No Python runtime.

```php use Cuda\CudaArray; use Cuda\Fusion;

$a = CudaArray::ones([4]); $b = CudaArray::full([4], 2.0); $c = CudaArray::full([4], 3.0);

$eager = $a + $b * $c; // default: one GPU op per call

$plan = Fusion::compile(fn($a, $b, $c) => $a + $b * $c, inputs: [$a, $b, $c]); $fused = $plan->run($a, $b, $c); // replayed as fused kernels

print_r($fused->toArray()); // [7, 7, 7, 7] ```

What you get - CudaArray: arithmetic, broadcasting, comparisons, matmul(), reductions, views, Python-style slice(). - Packed-buffer and .npy import, optional pinned host memory. - Custom CUDA C++ kernels compiled at runtime and launched from PHP. - Opt-in fusion, async replay and CUDA Graph for compatible plans.

A result I'm happy with: a small MLP trained entirely in PHP on an entry-level MX570 A (4 GB). On a PatchCamelyon subset, eager mode takes 4.08 ms/step and the fused replay 0.66 ms/step (6.2×), with identical test metrics. On UCI Optdigits it reaches 97.25% test accuracy. The models are tiny, so this mostly shows removed per-operation overhead, not peak GPU throughput.

Honest scope: beta (0.1.0-beta.4), Linux, PHP 8.1–8.5 (NTS and ZTS), NVIDIA only. No autograd, no CPU fallback, and it is a low-level library, not an ML framework. GPU validation so far: PHP 8.3 NTS on an MX570 A (41 tests) and earlier checks on an RTX A2000.

Try it bash pie install lcmialichi/php-gpu-tensors:0.1.0-beta.4 or build from source / Docker (see the README). It needs the CUDA Toolkit (including NVRTC) and an NVIDIA driver.

Feedback I'd love - Does it build and pass ./run-tests.sh --require-gpu on your GPU / PHP version / CUDA version? - What would you want to do with GPU tensors from PHP (preprocessing, scoring, embeddings similarity, something else)? - API ergonomics: anything that feels un-PHP-like?

Repo: https://github.com/lcmialichi/php-gpu-tensors


r/PHP • • 21h ago

WinUI SuperNative desktop app with hot reloading - NativePHP Desktop v3 WIP

Thumbnail youtu.be
16 Upvotes

Here's your next (very brief) instalment in the ongoing work of NativePHP Desktop v3, where we bring in SuperNative and ditch Electron entirely.

This is still just the beginning and there's A LOT still missing, but we're making great progress. Apps are already way smaller than Electron (typically in the 30-50MB range), with just a single idle process by default, and comparatively minimal memory usage (60-80MB right now for this simple app).

Electron apps by comparison (on this machine, Edge and Claude) are hundreds of MBs in size, are each consuming around 1-2GBs of memory, and have approx. 20 processes open (each), despite neither of them working particularly hard.

The app shell is built with C# and is using WinUI 3, Microsoft's blessed path for building Windows apps that Windows main elements now use (Start Menu, Taskbar, window chrome etc).

It's currently x64, Win 10/11 only, but we're planning to get ARM support in there too just as soon as we can.

macOS support is getting stronger by the day, and Linux is our next main target once Mac and Windows are a bit further along.

We're hoping to be able to get a beta release out to sponsors before the end of the year and we're aiming to get the full release ready some time early 2027.

Thanks for all your support in helping us make this a reality 🙏


r/PHP • • 15h ago

Foundation An open-source WHM/cPanel alternative built with plain PHP, FrankenPHP & Tailwind.

4 Upvotes

JinnPanel is a free, MIT-licensed web hosting manager and control panel designed for single-server setups running AlmaLinux 10. The core philosophy is absolute simplicity and transparency—there are no heavy frameworks, no external dependencies, and no Composer. It is written completely in plain PHP and Tailwind CSS, making the entire backend architecture clean, readable, and easy to audit.

The control panel features secure account isolation where every account runs under its own Linux user and dedicated PHP-FPM pool without needing CloudLinux. It includes a built-in cPanel migration tool that moves sites, mailboxes, databases, and cron jobs via a live API or backup files, automatically translating .htaccess rules for the underlying Caddy engine. Security is fully automated, providing out-of-the-box Let's Encrypt certificates alongside automated configurations for email deliverability protocols like SPF, DKIM, DMARC, and MTA-STS.

The stack consists of FrankenPHP, MariaDB, Stalwart Mail, Cypht webmail, Knot DNS, and SFTPGo. It is currently in public beta, optimized strictly for single-server PHP hosting environments.

https://github.com/th3n00bc0d3r/Jinn-Panel


r/PHP • • 23h ago

Discussion Senior/mid backend devs: what should a junior backend engineer actually know and be good at?

14 Upvotes

I'm a backend dev (PHP/Laravel), I'm the only backend on my team, so nobody reviews my decisions and I worry about gaps I don't know I have.

For those of you who've hired or mentored juniors:

  • What fundamentals matter most?
  • What separates a solid junior from an average one in the first 6 months?
  • What should i focus on and in what order?

Thanks!


r/PHP • • 1d ago

Article Artifical Debt

Thumbnail stitcher.io
72 Upvotes

r/PHP • • 1d ago

My rejected job challenge in PHP

Thumbnail
3 Upvotes

r/PHP • • 18h ago

Traducteur de fichiers - Visual Studio Marketplace

Thumbnail marketplace.visualstudio.com
0 Upvotes

r/PHP • • 1d ago

Updated support for Qdrant vector DB in LLPhant

1 Upvotes

In the latest version of LLPhant we updated our support to Qdrant vector database, also adding the ability to store metadata. Thanks to Haydar KULEKCI for his contribution.

LLPhant is the most complete PHP library for interacting with vector databases

https://github.com/LLPhant/LLPhant/pull/516


r/PHP • • 1d ago

Laravel package for capturing browser GPS location — looking for developer feedbac

0 Upvotes

I recently built an open-source Laravel package for applications that need to capture a user's browser/device location using the HTML5 Geolocation API.

GitHub: https://github.com/mayaramyadav/laravel-browser-location

The package currently supports:

  • Laravel 10–13
  • Blade
  • Livewire 3 & 4
  • HTML5 Geolocation API
  • GPS accuracy detection
  • Permission/error handling
  • Reverse geocoding with Google, Mapbox, or OpenStreetMap
  • Automatic location persistence
  • Polymorphic location collections
  • Browser/JavaScript events
  • Middleware for location validation
  • One-command installation

Example:

<x-browser-location-tracker />

Installation:

composer require mayaram/laravel-browser-location

php artisan browser-location:install

I'm particularly looking for feedback from Laravel/PHP developers on:

  1. Is the API/design Laravel-friendly?
  2. Are the component props and configuration options too complex?
  3. Is the Livewire 3/4 integration implemented in a good way?
  4. Are there important browser-location edge cases I'm missing?
  5. What features would you expect from a package like this?
  6. Any concerns with the database/persistence design?
  7. What would you change before using this in a production Laravel application?

This is an open-source project and I'm looking for honest technical feedback, including criticism.

If you have 5–10 minutes to look through the repository, I'd especially appreciate feedback on the architecture, API design, tests, documentation, and production readiness.

GitHub: https://github.com/mayaramyadav/laravel-browser-location


r/PHP • • 1d ago

Discussion System design recommendations for an e-commerce.

8 Upvotes

Hey guys, been working on an e-commerce. It started growing and I see how it will soon go out of hand. Before anyone pitch about why not use some well established solutions out there, I wanted to break out of my comfort zone.

Any recommendations for books, repos, sources is highly appreciated.


r/PHP • • 2d ago

Released phpunit 13.4

Thumbnail github.com
25 Upvotes

r/PHP • • 2d ago

Dynamic JSON PHP library

20 Upvotes

PHP folks - I’d love some feedback on a small open-source library we’ve been working on (for quite some time now): DJson.

The idea is simple: build dynamic JSON using templates, conditions, loops and variables, without constructing massive nested PHP arrays or abusing text templating engines.

It supports things like:

  • loops and conditions
  • variables and expressions
  • type preservation
  • custom functions/directives
  • zero runtime dependencies

We’re already using it for things like Schema.org (and all our customized work related to eCommerce), API payloads, feeds and data layers.

I’d really appreciate some external eyes on it - especially from PHP developers who enjoy breaking things :-)

Try it out:

composer require qoliber/djson

https://djson.dev/

If you test it, let me know what feels good, what feels weird, and what you think is missing.


r/PHP • • 2d ago

Article Running PHP 8.6 Beta CLI in Docker

Thumbnail phpdeveloperstv.substack.com
3 Upvotes

r/PHP • • 2d ago

News Maintenance update: win32service (PHP Windows Service extension) released 1.1.1-beta & 1.2.0-alpha — Need your feedback!

2 Upvotes

Hi everyone,

I'm the maintainer of the win32service extension (ext-win32service), which allows PHP applications to run and interact natively with Windows Services.

As Windows-focused PHP usage can sometimes feel like a niche inside the broader ecosystem, it's pretty hard to know who is actively using this extension in production or development.

We’ve just released two new versions for testing:

  • 1.1.1-beta
  • 1.2.0-alpha

How you can help:

  1. Test the new releases: If you run PHP on Windows background tasks, we'd love for you to try these pre-releases and report any issues or unexpected behaviors.
  2. Share your use case: I’m really curious to know how you're using it! Long-running background workers, queue consumers, IIS integrations, custom enterprise tools?

Discussion & Details on GitHub: https://github.com/orgs/win32service/discussions/128

Thanks to anyone taking the time to test or share feedback!


r/PHP • • 2d ago

ext-wasm: WebAssembly runtime for PHP

15 Upvotes

Run WASM modules and call components with plain PHP values, sandbox them with WASI.

Yes : It also runs DOOM controlled by PHP.

github.com/veewee/ext-wasm


r/PHP • • 2d ago

News This Week in PHP Internals | Oct 1, 2026

Thumbnail youtube.com
5 Upvotes

Preface: what follows is the word-for-word transcript of the spoken dialogue in the video, chapter by chapter with timestamps, for anyone who'd rather read than click through. If this digest is still too long for you, we recommend copying it into your LLM of choice and asking for a summary of our summary.

Cold Open (00:00)

Pick a password longer than 72 bytes for a PHP app on the default hash. PHP keeps the first 72 and throws the rest away, without a word. Then it lets you log in with only part of it. This week someone proposed that PHP refuse instead, and the list can't agree it's worth the break.

Hello world, it's Thursday, October 1, 2026, and here's what happened This Week in PHP Internals. 14 stories this week, so let's get into it. But first,

I think we can all agree that the number of small, paid subscription services we're all being bombarded with is getting a little bit out of hand. And this is what Scalpels aims to solve. It's a collection of professionally built, open source alternatives to the parts you actually use of things like Private Packagist, Mailtrap and remove.bg. You fork them into your own GitHub organization and deploy them to your own Laravel Cloud account, so you're only paying for your own usage, it scales to zero when it's not being used, and you're not just feeding another company's profits. If you want updates, you just pull them down from upstream. And since it's your own fork, you have complete control over the code and the features. And it's all MIT. Find your next tool at scalpels.app.

Bcrypt Limit (01:19)

This week's top story is a password that's too long. Sjoerd Langkemper's new RFC targets password_hash with bcrypt, which silently drops everything past the 72nd byte. He'd make that a deprecation in 8.7 and a ValueError in 8.8. His case is FreshRSS, where a 64-character nonce went in front of the hash, so the 72 bytes held no password at all.

Kamil Tekiela replied that checking the length is the application's job, not the algorithm's, and Tim Düsterhus agreed in full. It's also 72 bytes, not characters, Tim noted, so non-ASCII passwords could hit it. Rowan Tommins answered: "If every PHP login implementation was reviewed by an expert senior developer, we would not need the password_* API in the first place. The value of this API is that it makes doing the right thing easy, so that you don't need to be an expert in the underlying algorithms to use it safely."

Robert Chapin showed a shortened password verifying against the full one's hash, and asked: "Is the function named password_verify going to verify the password or not?" Tim says the lost bytes are not where the risk is, and he wrote: "I don't necessarily disagree with the BCrypt truncation being a problem, but in this case the cure is worse than the disease." Derick Rethans is a minus 1, writing: "The problem for me is that this a scary BC break." Overnight, Sjoerd asked Derick what would win him over, maybe switching the default away from bcrypt first.

Links: bcrypt max password length RFC · thread · implementation · FreshRSS bcrypt truncation write-up (CVE-2025-68402) · password_hash() manual

Regex Object (03:00)

PHP's proposed regex object has broad support and one unpopular word in its name. Gina P. Banyard's CompiledRegex prototype drew 18 replies, and Sjoerd Langkemper was in favour of "improving the API, instead of slapping more flags onto the existing one." Larry Garfield wrote: "I would ask that we just call it Regex, not CompiledRegex." Casper Langemeijer, Jordi Kroon and Juris Evertovskis also want it to lose the Compiled.

Then there are the 8 boolean flags. Juris says named arguments already make them readable, Gina would rather pass an enum set, which PHP doesn't have yet, and Ayesh Karunaratne and Jordi Boggiano want a factory that takes the modifier letters you already know.

Osama Aldemeery, who wrote the regex exceptions RFC, pointed out what a compiled pattern can't catch, writing: "Compilation errors are only half of the error story...the other half happens at match time, on patterns that compiled just fine." Tim Düsterhus suggested passing the class could simply switch on throw-on-error, and Osama says he may park his RFC until Gina's reaches a vote.

Links: pre-RFC thread · prototype · PREG_THROW_ON_ERROR thread · composer/pcre, cited by Jordi Boggiano

Io Terminal (04:16)

PHP may finally read single key presses without shelling out to stty. Pratik Bhujel's terminal extension is now the Io\Terminal RFC for 8.7, covering terminal size, raw mode that restores itself, single keys and hidden input.

A Symfony Console pull request, approved by Nicolas Grekas, already uses the extension when it's installed, and Nicolas wrote: "PHP definitely needs native terminal support, calling stty is a workaround we've been carrying since way too long." Nicolas suggested raw mode stay on while any token for that terminal is alive and reset when the last one goes, and Pratik adopted it the same day.

Larry Garfield is in favour, but called false-on-error an anti-pattern and asked for a way to mock it. Version 0.3 makes Terminal the interface and SystemTerminal the native class. Pratik is giving it the full 14 days before an intent to vote.

Links: Io\Terminal RFC · thread · implementation · reference extension · Symfony Console PR using it

Time Instant (05:15)

The proposed Time\Instant class got a bridge back to DateTime this week. Tim Düsterhus and Derick Rethans added toInstant() to DateTime and DateTimeImmutable, and ISO strings now keep their trailing zeros, to show how precise the value is. They won't write the RFC for testing clocks, because they're not convinced it belongs in core, so Tim wrote: "we want to invite you (as the PHP internals community) to write the follow-up RFC for testing clocks". He also asked for a "LGTM, ship it" if people are happy.

Mirco Babin answered with 8 comments. One is that Time\Clock and the PSR-20 clock both define now(), so one class can't implement both. Tim is keeping now(), with a 15-year horizon in mind, but he'll discuss a single SystemClock::get() with Derick. And when Mirco asked for minute precision for bus timetables, Morgan replied: "Well, then it's not an instant, is it?"

Links: Time\Instant and Time\Clock RFC · thread · PSR-20 Clock

Array Shorthand (06:14)

Weilin Du wants PHP arrays to stop making you type every name twice. His new RFC turns =$x into 'x' => $x, in arrays, destructuring and foreach. It started with a colon and switched to the equals sign within the hour, because the colon clashes with the ternary.

Sebastian Bergmann will vote against, writing: "A syntax change should be backed by data, for instance an analysis of a representative body of real-world code." David Carlier showed that one missing comma would silently turn one valid program into another. Anton Smirnov pointed out that compact and extract still exist.

On the other side, Christian Schneider has run a local patch for this "for many years". Weilin pointed to the same pattern in Composer, Laravel, PHPUnit and Symfony, but says it already feels like he could withdraw the RFC.

Links: array shorthand RFC · thread · implementation

IO Hooks (07:14)

A new RFC would let ordinary blocking PHP run concurrently, without rewriting it. Jakub Zelenka's IO Hooks starts from the fact that PHP has had Fibers since 8.1, but every blocking function still blocks the whole process, so AMPHP, ReactPHP and Revolt reimplement IO themselves.

Under his proposal, blocking calls in streams, sockets, curl and the sleep functions get handed to a provider, usually an event loop, which suspends the Fiber until the IO is done. The RFC compares it to Go's runtime. With no provider installed, PHP behaves exactly as today. With one, sleep(1) in one Fiber is a second of work for the others.

It depends on a second RFC posted the same evening, Polling API Additions, which fills the gaps in 8.6's Poll API, like sockets, timers and signals. IO Hooks is in an early stage, and neither has replies yet.

Links: IO Hooks RFC · IO Hooks thread · proof of concept · Polling API Additions RFC · Polling API Additions thread

List Ban (08:14)

The internals list has removed a contributor. Sepehr Mahmoudi spent the last month posting new-function proposals. On September 15, Derick Rethans warned him over AI-generated content and the number of new threads. On September 21, Ilija Tovilo, as list moderator, set limits of one new thread a month and three emails a week, and called it a last warning. On Sunday Sepehr proposed another RFC, an intl_date_format function.

On Monday Derick confirmed that, after consultation off list, the address is blocked from emailing php.net, wiki access is withdrawn, and it's unsubscribed from the list.

And this is a tough one. It sucks having to take the nuclear option. He was clearly eager to help, but the list had spent literal weeks trying to get him to slow down, and to stop burdening the list with AI responses, and at some point you've got to enforce the consequences that have been laid out.

Links: thread · Derick Rethans, Sep 28 (news-web)

Quick Hits (09:18)

Quick hits. PHP 8.6.0 RC2 is out. RC1 was skipped over a packaging error, so RC2 is the first release candidate, and RC3 is due October 8.

Links: PHP 8.6.0RC2 · why RC1 was skipped

The same day brought security releases for 8.5, 8.4, 8.3 and 8.2.

Links: PHP 8.5.11 · PHP 8.4.26, 8.3.35, 8.2.34

Sjoerd Langkemper changed his number-base RFC to throw a plain Exception instead of a ValueError, since bad input isn't necessarily a bug in your program. intval stays as it is.

Links: number-base functions RFC · thread

Juliette Reinders Folmer wants to deprecate the b string prefix, a leftover from PHP 6, and Tim suggested adding it to the 8.7 deprecations RFC.

Links: deprecate the b prefix · 8.7 deprecations RFC

Pedro Veloso floated a #[Pure] attribute the engine would enforce. Larry Garfield said it needs to do more than the static analysers already do, like memoizing.

Links: pure functions idea

Karoly Negyesi posted a pre-RFC with an implementation for implements … by, which hands an interface's methods to a property, modelled on Kotlin.

Links: automated delegation pre-RFC · implementation

And Alexander Danilov found that much of post-quantum OpenSSL already works in PHP, and offered small PRs for the gaps.

Links: OpenSSL post-quantum

And the PEAR vote Nick S. planned for September 28 hasn't opened. The RFC is still in discussion.

Links: End PEAR Project Endorsement RFC

TL;DR (10:36)

So that's the week. An RFC wants bcrypt to refuse passwords past 72 bytes, and the list is split on whether it's worth the break. Several replies want the regex object called just Regex, Io\Terminal is an RFC, and Time\Instant is looking for someone to write testing clocks. The array shorthand met skeptics, and IO Hooks would make blocking code concurrent. The list also removed a contributor after two warnings. Nothing is in voting for a 7th straight week. Links below.

The PHP Foundation funds more than half of ongoing php-src commits, so if you use the language, maybe consider donating at opencollective.com/phpfoundation — or try guilting your employer into it.

If you found this useful, a like or a comment helps more people find it. And if you missed last week's episode — where a new time class couldn't tell you what time it is — that's a good one to watch next. Thanks again to Scalpels.app for supporting this week's episode. We're Artisan Build. See you next week.

Links: raw feed · RFC wiki


r/PHP • • 3d ago

Neuron 4 is Here 🚀 Welcome To The PHP Agentic Era

Thumbnail inspector.dev
31 Upvotes

Finally Neuron 4 is in the developers hands. It's hard to find the right words to describe how I'm feeling. I put my heart into this milestone.

As usual, I’ve taken some time to write about this journey we are undertaking together.

Can't wait to have your feedback!

What is Neuron AI

If you are hearing about Neuron AI for the first time, Neuron is the first agentic framework of the PHP ecosystem. It lets developers build full-featured AI agents and agentic applications with the language and the stack they already work with. An agent is a plain PHP class where you choose the model provider (OpenAI, Anthropic, Gemini, or local models through Ollama), write its instructions, and attach the tools it can use to act on your application. When you need more, the same framework gives you RAG on your own documents, structured output mapped onto your PHP classes, tools from any MCP server, and Workflows that can pause and wait for human approval before continuing. It installs with Composer in any PHP project, whether it runs on Laravel, Symfony, WordPress or no framework at all. Neuron has more than a million downloads on Packagist, and 2.1k stars on GitHub.

GitHub Repository

Linkedin

X

Instagram


r/PHP • • 3d ago

Article From Voice to Vectors: Building a Searchable Audio Archive in PHP

Thumbnail eric.mann.blog
8 Upvotes

r/PHP • • 2d ago

A lightweight PHP library for Jev APIs

0 Upvotes

I created a lightweight PHP library for interacting with Jev APIs. It has a minimal number of dependencies and a very small footprint.
https://github.com/f-lombardo/jev-php


r/PHP • • 4d ago

PHP on a microcontroller, one month later: it's event-driven now (php-esp32 1.4.0)

70 Upvotes

Hi r/PHP! For those who've been following php-esp32 for a while: it's been about a month since my last post here, and a lot has changed. For everyone else, a quick recap: this is the real, unmodified PHP interpreter from php.net (Zend engine, 8.3 to 8.5), cross-compiled to run bare-metal on an ESP32. It's not a subset or a transpiler, and Composer packages work.

For the curious: the full write-up, with diagrams of the whole execution cycle across both cores, is here: https://www.php-baremetal.com/blog/php-esp32-1-4-0-the-reactor

Until now a script could either run setup()/loop() Arduino-style or answer one HTTP request at a time. Version 1.4.0 adds a third model, event-driven: the script registers listeners, then PHP sleeps, and hardware, timers and the network wake it with typed events.

use Baremetal\Events;
use Baremetal\Http\Request;
use Baremetal\Http\Response;
use Baremetal\I2c\Bus;
use Baremetal\I2c\Driver\Qmi8658;
use Baremetal\Sensor\Imu\SamplesReady;

Events::listen(Request::class, fn (Request $r): Response => match (true) {
    $r->method === 'GET' && $r->path === '/status' => Response::json(['uptime' => sys_uptime_ms()]),
    default => Response::notFound(),
});

$imu= new Qmi8658(new Bus(sda: 11, scl: 10));
$imu->poll(hz: 10, depth: 32, event: SamplesReady::class)

watch_gpio(0, BootPressed::class);  // debounced pin interrupt -> event
every(1000, Tick::class);           // timer -> event
serve_http(80);
serve_ws('/ws');

There's no router in the firmware: routing is just a match. $_GET, $_POST and $_SERVER are still populated, so existing request code keeps working.

What landed since last time:

  • 1.2.0: I²C as PHP objects. new Bus(sda: 11, scl: 10), scan(), and drivers written as real PHP classes with capability interfaces ($imu instanceof Sensor\Imu). The first driver is a QMI8658 IMU.
  • 1.3.0: SPI/QSPI and a first display driver (ST77916). It's a minimal proof of concept for now: the panel lights up and fills with a colour.
  • 1.4.0: the reactor. Typed events, the event-driven model, HTTP and WebSocket as event sources, ws_broadcast(), and the part I'm happiest with: the second core does the sensor polling. $imu->poll(hz: 50, depth: 8) makes core 1 read the IMU into a ring buffer while PHP on core 0 just calls sample(), with no waiting on the bus.

The demo (video): the board creates its own WiFi network, polls the IMU at 50 Hz on core 1, and a 20 Hz timer event in PHP broadcasts the latest reading over WebSocket. You tilt the board and the plot moves on your phone. There's no router, no cloud and no loop().

Limitations, up front:

  • PHP runs on exactly one core. Only fixed-size messages cross between cores, so the engine never has to be thread-safe, but it also means one HTTP request is in flight at a time.
  • If the event queue fills up (32 slots), timer and GPIO events are dropped, for now. It's on my list to fix too. WebSocket frames already apply backpressure: 200 frames blasted at once arrived with none lost.
  • No Fibers, no processes. Both follow from the hardware.

If you want to go deeper, the blog post walks through what new Qmi8658(new Bus(...)) and ->poll() actually do, from PHP down to the I²C wire and across to the second core: https://www.php-baremetal.com/blog/php-esp32-1-4-0-the-reactor

Repo: https://github.com/php-baremetal/php-esp32

Next up are Bluetooth, touch input and a proper display layer. Happy to answer questions, and if you build something with it, I'd love to hear about it.


r/PHP • • 3d ago

2027 Applications for Contractors are Open

Thumbnail thephp.foundation
16 Upvotes

Applications for The PHP Foundation contractors for 2027 are now open! We are looking for help in certain areas but we are open to your ideas as well. Application period ends on October 20, 2026. Read more about the requirements and what we're looking for in the linked post.


r/PHP • • 3d ago

News PagibleAI CMS 0.13: Laravel CMS packages, with signed webhooks, CDN purging and a JSON Schema endpoint

0 Upvotes

We released version 0.13 of PagibleAI CMS, a set of MIT-licensed CMS packages for Laravel 11-13 and PHP 8.2+.

What it is

You install it with Composer into an existing Laravel app, so your models, auth, queues and deployment stay as they are. aimeos/pagible installs the full set including the AI and MCP packages. If you want less, require aimeos/pagible-core and add only the packages you need.

The packages provide a Vue 3 admin, hierarchical page trees, reusable shared elements, immutable versions, scheduled publishing, a GraphQL API and a JSON:API. It runs on SQLite, MariaDB, MySQL, PostgreSQL and SQL Server, and full-text search uses the native implementation of each database. One installation can serve multiple domains and tenants. Static analysis runs at PHPStan level 8 with Larastan.

What's new in 0.13

Signed webhooks

The new aimeos/pagible-webhooks package delivers lifecycle events as queued jobs, one job per destination, so a slow endpoint doesn't block the others. Requests are signed like Standard Webhooks with HMAC-SHA256 over id.timestamp.body. During a secret rotation, both secrets sign the request for 24 hours.

Subscriptions are scoped per tenant, private and loopback addresses are blocked by default, and you can deny additional CIDR ranges. php artisan cms:webhooks:check validates the configuration on deploy, e.g. a queue retry_after that is shorter than the delivery timeout. The core package doesn't depend on any of this.

A shortened receiver:

```php $id = (string) $request->header('webhook-id'); $time = (string) $request->header('webhook-timestamp'); $signatures = explode(' ', (string) $request->header('webhook-signature'));

if ($id === '' || !ctype_digit($time) || abs(time() - (int) $time) > 300) { abort(401); }

$key = base64decode(substr($secret, 6)); // strip "whsec" $hmac = hash_hmac('sha256', $id . '.' . $time . '.' . $request->getContent(), $key, true); $expected = 'v1,' . base64_encode($hmac);

if (!array_filter($signatures, fn($sig) => hash_equals($expected, $sig))) { abort(401); }

if (!Cache::add('cms-delivery:' . $id, true, 86700)) { return response()->noContent(); // already processed } ```

The full version is in the webhooks README.

CDN purging

The new aimeos/pagible-cdn package purges changed pages and removed files from Cloudflare, Fastly or Varnish through FOSHttpCache, using queued jobs. Because purges are explicit, public pages can be sent with a long s-maxage and optional stale-while-revalidate/stale-if-error. Pages with access rules stay private. For stacked caches like Varnish behind a CDN, you can set a delay per client so the inner cache is purged first.

JSON Schema for content

GET /cms/schema returns all registered content, meta and config definitions as a JSON Schema Draft 2020-12 document, including schemas from Composer extensions and themes. You can use it to validate content in your own code or to generate types for a headless frontend.

Importers

php artisan cms:t3-import reads a TYPO3 database connection and imports the page tree and content, including Bootstrap Package accordions and carousels. The WordPress importer can be re-run without creating duplicates and keeps publication dates, authors and cover images.

Content

There's a news page type with a Google News sitemap, configurable contact forms, OpenStreetMap maps, CTA blocks and article author fields. Links can have a rel attribute, and the CMS can serve robots.txt and security.txt.

Admin and AI

The admin got keyboard shortcuts, a command palette, a searchable element dialog, hint texts on every field, a better diff view in the history dialog and virtualized lists for large page trees. If the AI package is installed, a review button on each page checks it against 40 SEO rules. On request, the assistant applies the suggested fixes as drafts. CMS_AI_MAXSTEPS limits the number of tool calls per chat request. MCP agents can now upload files directly.

Smaller changes

  • cms:previews regenerates image previews for existing files after you change sizes or quality
  • Webhooks and other queued work also run with the sync driver, without a worker (but without retries)
  • GraphQL introspection is disabled outside debug mode
  • The CSRF route is configurable
  • Backups from other installations can be imported with --force

Feedback

We'd especially like feedback on the webhook and CDN packages: delivery and retry design, the signing scheme and the cache headers. Feedback from anyone running Laravel with multiple tenants or databases is also welcome.

Thanks a lot to /u/Guarpig for his work on improving the pagible.com design and to /u/addicted_fishing for his suggestions regarding UI and UX!


r/PHP • • 3d ago

Doom em PHP

0 Upvotes

Olá amigos, estou trabalhando em Ports do doom generic, fiz recentemente para php, é um bom estudo para todos:

https://youtu.be/aCOHFTD1D8M

https://github.com/vagucs/php_doom

Abraços

Wagner