FuturByte

Hire PHP developers

PHP runs a very large share of the web, and the gap between modern PHP and the PHP people remember is the main thing a hiring process has to detect.

What PHP actually is

PHP is a server-side language with an unusually large installed base, powering WordPress, a great deal of commerce, and a long tail of business applications. It is developed in the open with a predictable annual release and a clearly dated support window for each version. Its reputation among people who last used it fifteen years ago is worse than the language now deserves.

Modern PHP has strict types, proper namespaces, a mature dependency manager, a strong testing culture and frameworks that compare well with anything in other ecosystems. It is also fast in a way that surprises people, having gone through substantial engine work over the last decade. None of this changes the fact that a very large amount of old PHP is still running, and that much of the available work involves touching it.

That split is the whole hiring problem. Two candidates can both have a decade of PHP behind them: one has spent it writing typed, tested, framework-based code with a dependency manager, and the other has spent it maintaining files that mix SQL, HTML and business logic. Both are experienced. Only one of them will be comfortable in a modern codebase, and the CV will not tell you which.

The part that separates seniors from mid-levels

PHP's execution model is the thing that shapes everything else about it. Traditionally each request starts a fresh process state, runs, and throws everything away. There is no long-lived application memory between requests unless you arrange one. That makes PHP unusually forgiving of memory leaks and unusually dependent on external state for anything that has to persist, and it is why caching layers and queues are such a prominent part of any serious PHP architecture.

That model has been changing. Long-running worker approaches keep the application in memory across requests, which removes the startup cost and dramatically changes performance, while introducing exactly the class of bug the traditional model protected you from: state leaking between requests. A developer who has moved an application to a long-running model can tell you what they had to fix, usually static properties and container state that nobody had thought about in years.

The third area is types. PHP's type system has grown substantially and is genuinely useful, but it is opt-in per file and not enforced everywhere. A codebase can be strictly typed, loosely typed, or a mixture with no clear boundary. Candidates who work with static analysis tooling as a matter of course are describing a different daily experience from those who do not, and the difference shows up directly in defect rates.

Where PHP is used

The label “PHP developer” covers several jobs that share a technology and little else. These are the settings the work usually turns up in, and the one you are hiring into should shape the whole process, because the judgement each demands is different.

Content management

WordPress, Drupal and similar systems, which together account for a very large share of all PHP in production.

E-commerce

Magento, WooCommerce and Shopware, where the platform is the constraint and PHP is how you work within it.

Custom business applications

Laravel and Symfony applications serving internal operations, often the system a company actually runs on.

APIs and back ends

Services behind mobile applications and single-page front ends, where PHP is the back end because it already was.

Legacy maintenance

Applications written before modern practice, still generating revenue, needing careful change rather than rewriting.

Integration work

Connecting content or commerce platforms to payment, fulfilment and enterprise systems.

If a candidate's experience sits in a different row of that list from the work you have, that is not a reason to reject them, but it is the thing to probe. Ask what would be different about their approach in your setting. Someone who can answer that has transferable judgement. Someone who says it would be much the same has probably not thought about it.

Which PHP versions are still supported

PHP publishes a fixed support window for each release, with active support followed by security-only support, so whether a version is safe to run is a matter of published record.

The table is generated from public release data rather than written by hand, so it states what is supported today rather than what was true when any given article was published. Of the 8 most recent release lines, 4 are still maintained and 4 have passed their published end-of-life date. That distinction is the practical one when you read a job specification: a requirement written against a line that is now out of support tells you the specification is older than the codebase it describes, and it is worth asking which of the two the new developer will actually work in.

PHP release lines
ReleaseReleasedEnd of lifeStatusLatest patch
8.52025-11-202029-12-31Maintained8.5.10 (2026-08-27)
8.42024-11-212028-12-31Maintained8.4.25 (2026-08-27)
8.32023-11-232027-12-31Maintained8.3.33 (2026-07-30)
8.22022-12-082026-12-31Maintained8.2.33 (2026-07-30)
8.12021-11-252025-12-31End of life8.1.34 (2025-12-18)
8.02020-11-262023-11-26End of life8.0.30 (2023-08-03)
7.42019-11-282022-11-28End of life7.4.33 (2022-11-03)
7.32018-12-062021-12-06End of life7.3.33 (2021-11-18)

Source: endoflife.date public release data, read 2026-09-25.

Two questions follow from this table in an interview. The first is which line the candidate has most recently shipped against, because someone whose last production work was on an unsupported line has not had to deal with the changes since. The second is how they have handled an upgrade. Version migrations are where you see whether a developer reads release notes, writes characterisation tests before changing anything, and knows how to stage a rollout, or whether they upgrade in place on a Friday and hope.

The toolchain around it

Nobody hires for PHP alone. The surrounding tools are where most of the day-to-day work happens, and a gap in any of them costs more time than a gap in the core library. This is the set that turns up most often on real job specifications alongside it.

Composer
Dependency management. Its presence and correct use is the fastest single indicator of whether a codebase is modern.
Laravel or Symfony
The two dominant frameworks. Laravel favours speed of delivery, Symfony favours explicitness and reuse.
PHPUnit or Pest
Testing. A PHP codebase with real test coverage is a meaningfully different proposition.
PHPStan or Psalm
Static analysis, which catches in PHP what a compiler catches elsewhere.
MySQL or PostgreSQL
The usual data stores, with MySQL dominant in the content and commerce world.
Redis
Caching, sessions and queues, which the request model makes essential rather than optional.
Xdebug or a profiler
Step debugging and profiling. Developers who use neither are guessing.
Docker
Local environments, which removed one of the historical pain points of PHP development.

Related skills that frequently appear on the same specification: Laravel, WordPress, JavaScript, MySQL, Magento and Adobe Commerce.

What to test in an interview

These are the topics that separate candidates in practice. Each one is given with why it discriminates, what a strong answer sounds like, and the response that should make you slow down. None of them requires a whiteboard.

Which PHP they have written

The central question, given how wide the range of real-world PHP is.

SQL injection and input handling

PHP's history makes this non-negotiable, and it is still the most common serious fault found in PHP codebases.

Static analysis and types

The clearest marker of modern practice.

The request lifecycle and state

Determines whether they can reason about caching, sessions and long-running workers.

Working in legacy code

A large share of PHP work, and the area that separates useful hires from frustrated ones.

Performance diagnosis

PHP performance problems are usually database problems, and people who have not profiled tend to guess wrong.

Version upgrades

Common work, and genuinely risky in older codebases.

Warning signs in a PHP codebase

The fastest way to read a candidate is to ask what they have found wrong in code they inherited. These are the patterns that come up most often, what they cost, and what fixing them looks like. A developer who recognises three or four of these from their own experience is worth more than one who can recite the documentation.

SQL built by string concatenation

Business logic in template files

Suppressing errors

Ignoring the dependency manager

Global state and static everything

Running an unsupported version

What each level can own

Job titles are not comparable between companies, so it is more useful to describe levels by what a person can be left to own without supervision. These are the boundaries we use when we assess a PHP developer.

Junior
Implements features within an existing framework structure. Needs review on query safety and on separating logic from presentation.
Mid-level
Owns a feature area including its tests. Comfortable with the framework's conventions and can debug with a profiler rather than by guessing.
Senior
Owns application architecture, the caching and queue strategy, and can modernise a legacy codebase incrementally while it stays in service.
Staff
Owns the upgrade path, the static analysis and testing standard, and the decision about which legacy systems to modernise and which to replace.

How the work is usually scoped

Team shape follows the kind of work, not the headcount you happen to have budget for. These are the shapes that come up most often and the constraint that actually governs each one.

New Laravel or Symfony application

Legacy modernisation

Version upgrade

Performance remediation

Platform integration

Migration work you may actually be hiring for

A large share of PHP work is not new development. It is moving an existing system from one state to another while it stays in service. These are the migrations that come up most often, and each one asks for a different kind of experience from the person you hire.

An unsupported PHP version to a supported release

A custom legacy application to a framework

The traditional request model to a long-running worker

Untyped code to strict types with static analysis

Migration work rewards a different temperament from greenfield work. The useful question in an interview is not whether someone has done the specific migration you face, but whether they have ever run one incrementally: behind a flag, with both paths live, and with a way back. Developers who have only done big-bang cutovers tend to propose them again.

What a good brief for this role contains

Most of the time lost in hiring a PHP developer is lost before anyone is interviewed, in the gap between what the brief says and what the team actually needs. These are the points that, for this technology specifically, change who the right candidate is. A brief that answers them can be matched in days. One that does not produces a shortlist that looks reasonable and converts badly.

If you cannot answer some of these yet, that is normal and it is still worth writing down which ones are open. An unknown that is named can be worked around. An unknown that is papered over in a job specification turns into a rejected shortlist and a restart four weeks later.

What the US market pays for this work

PHP work is counted by the US Bureau of Labor Statistics under Software Developers. That classification is broader than the technology itself, so treat the figures as the shape of the market a PHP developer is hired into rather than as a rate card for the skill. Across the United States the Bureau counts 1,687,890 people in this occupation, with a median annual wage of $135,980.

US annual wages, Software Developers, May 2025
US annual wages, Software Developers, May 2025$135,980Median$82,460$214,67010th pct90th pctMiddle half $105K to $172K

The spread matters more than the midpoint. The 90th percentile is about 2.6 times the 10th, which is a wide band for a single occupation and tells you that the title on its own carries very little pricing information. Two people described as a PHP developer can sit at $82,460 and $214,670 in the same national dataset. When a budget is set from a median without asking which end of that range the work actually needs, the hire that follows is usually the wrong one in one direction or the other.

Related classifications are worth reading alongside it, because teams hiring for PHP frequently end up recruiting against these titles too:

US national wages, May 2025
OccupationEmployed25th percentileMedian75th percentile90th percentile
Software Developers1,687,890$105,210$135,980$171,980$214,670
Web Developers70,190$64,230$92,650$126,230$162,290
Computer Programmers92,230$75,850$100,390$130,680$160,460

Source: BLS Occupational Employment and Wage Statistics, May 2025. Figures cover all US employers and are not FuturByte rates.

These are employer-side wage figures for people on a US payroll. They exclude employer taxes, benefits, recruitment cost and the months a seat sits empty, all of which are real and none of which appear in a salary line. The useful way to read the table is as the cost of the alternative you are comparing against, not as a number to match.

How US metro markets compare for this role

The same job is priced very differently across the country. Ranked by median annual wage for Software Developers, the gap between the highest and lowest of the 28 metro areas covered here is a factor of about 1.7. San Jose sits at the top with a median of $213,110; Pittsburgh sits at the bottom with $124,500. A budget built from a national median will be wrong in both of those markets, in opposite directions.

Median wage for software developers, by US metro area
Median wage for software developers, by US metro areaSan Jose, CA: $213,110San Jose, CASan Jose, CA$213,110San Francisco, CA: $186,640San Francisco, CASan Francisco, CA$186,640Seattle, WA: $167,280Seattle, WASeattle, WA$167,280New York, NY: $166,830New York, NYNew York, NY$166,830Boston, MA: $166,090Boston, MABoston, MA$166,090San Diego, CA: $163,270San Diego, CASan Diego, CA$163,270Los Angeles, CA: $160,920Los Angeles, CALos Angeles, CA$160,920Portland, OR: $156,000Portland, ORPortland, OR$156,000Washington, D.C.: $154,930Washington, D.C.Washington, D.C.$154,930Baltimore, MD: $138,900Baltimore, MDBaltimore, MD$138,900Denver, CO: $137,610Denver, CODenver, CO$137,610Charlotte, NC: $135,920Charlotte, NCCharlotte, NC$135,920Chicago, IL: $134,380Chicago, ILChicago, IL$134,380Austin, TX: $134,120Austin, TXAustin, TX$134,120Dallas-Fort Worth, TX: $133,290Dallas-Fort Worth, TXDallas-Fort Worth, TX$133,290Philadelphia, PA: $133,040Philadelphia, PAPhiladelphia, PA$133,040Atlanta, GA: $132,960Atlanta, GAAtlanta, GA$132,960Raleigh, NC: $132,770Raleigh, NCRaleigh, NC$132,770Miami, FL: $132,650Miami, FLMiami, FL$132,650Phoenix, AZ: $131,750Phoenix, AZPhoenix, AZ$131,750Minneapolis-St. Paul, MN: $130,920Minneapolis-St. Paul, MNMinneapolis-St. Paul, MN$130,920Detroit, MI: $130,760Detroit, MIDetroit, MI$130,760Tampa, FL: $130,450Tampa, FLTampa, FL$130,450Orlando, FL: $129,620Orlando, FLOrlando, FL$129,620Salt Lake City, UT: $129,600Salt Lake City, UTSalt Lake City, UT$129,600Houston, TX: $129,440Houston, TXHouston, TX$129,440Kansas City, MO: $124,990Kansas City, MOKansas City, MO$124,990Pittsburgh, PA: $124,500Pittsburgh, PAPittsburgh, PA$124,500
Software Developers by metro area, May 2025, ranked by median wage
Metro areaEmployedMedian wagevs US medianLocation quotient
San Jose, CA87,350$213,110+57%7.09
San Francisco, CA69,030$186,640+37%2.68
Seattle, WA92,770$167,280+23%4.10
New York, NY121,000$166,830+23%1.17
Boston, MA42,310$166,090+22%1.44
San Diego, CA20,610$163,270+20%1.23
Los Angeles, CA55,540$160,920+18%0.82
Portland, OR18,260$156,000+15%1.39
Washington, D.C.69,060$154,930+14%2.03
Baltimore, MD16,850$138,900+2%1.14
Denver, CO27,010$137,610+1%1.55
Charlotte, NC20,820$135,9200%1.41
Chicago, IL40,370$134,380-1%0.82
Austin, TX31,960$134,120-1%2.28
Dallas-Fort Worth, TX67,030$133,290-2%1.52
Philadelphia, PA28,480$133,040-2%0.91
Atlanta, GA36,300$132,960-2%1.16
Raleigh, NC12,580$132,770-2%1.56
Miami, FL18,900$132,650-2%0.62
Phoenix, AZ29,380$131,750-3%1.14
Minneapolis-St. Paul, MN27,410$130,920-4%1.29
Detroit, MI24,870$130,760-4%1.20
Tampa, FL14,230$130,450-4%0.91
Orlando, FL13,440$129,620-5%0.88
Salt Lake City, UT19,040$129,600-5%2.12
Houston, TX22,940$129,440-5%0.64
Kansas City, MO12,160$124,990-8%1.02
Pittsburgh, PA10,320$124,500-8%0.85

Location quotient compares how concentrated this occupation is in the metro against the national average. A value above 1 means the metro has more of this work than its size would predict.

The location quotient column is the more useful one for hiring. A high median tells you what a role costs; a high quotient tells you whether the people exist. San Jose, San Francisco, Seattle, Washington, D.C., Denver, Austin each have a quotient of 1.5 or above, meaning the work is concentrated there well beyond what the size of the local economy would predict. Those are the markets where a search is likely to be quick and competitive at the same time, and where a counter-offer is most likely to take a candidate off the table late in the process.

The opposite case is worth planning for too. In a metro with a low quotient, the total pool is small even when wages look reasonable, so the realistic options are to widen the search radius, accept a longer time to hire, or bring the capability in from outside the local market entirely. That last option is what most teams are weighing when they come to us.

Hiring risks worth naming

Every one of these has produced a bad hire somewhere. They are written down so that the process tests for them deliberately rather than discovering them in month three.

Legacy habits in a modern codebase. Ask about their tooling: dependency manager, static analysis, tests. The answer is very hard to fake.

Security practice formed in an older era. Ask about injection and output escaping specifically. This is the one area where an outdated habit is dangerous rather than merely inefficient.

Framework knowledge without language depth. Ask what happens between requests. Framework familiarity can hide a shallow model of the runtime.

Reluctance to work in old code. Much PHP work is maintenance. Ask directly, because a mismatch here produces an unhappy hire rather than a bad one.

Hiring PHP developers by metro area

Wages for this occupation vary more between US metro areas than most budget models assume. Each page below sets out the published employment and wage figures for that market, how it compares with the national picture, and what the local industry mix means for the kind of PHP developer who will be available.

Frequently asked questions

Is PHP still a reasonable choice in 2026?

For web applications, yes. Modern PHP is fast, properly typed, well tooled and supported by two mature frameworks, and the hiring pool is large. The strongest arguments for it are practical: an enormous ecosystem, cheap and ubiquitous hosting, and the fact that if your site is on WordPress or Magento the decision has already been made for you.

How do we tell modern PHP experience from legacy experience?

Ask about tooling rather than about the language. Someone who names their dependency manager, their static analysis level, their test framework and their local environment setup is describing modern practice. Someone who cannot is describing something else, and it will show up in the first week.

Our site is on an old PHP version. How bad is that?

If it is past its security support date, it is a genuine risk rather than a theoretical one, because PHP applications are among the most probed surfaces on the internet. The upgrade is usually much less painful than teams fear, particularly with static analysis to find the breakages in advance. Deferring makes it worse, since each year adds another version to cross.

Should we use Laravel or Symfony?

Laravel for speed of delivery and a larger hiring pool, particularly for applications that fit its conventions. Symfony where you want explicit configuration, reusable components and a structure that scales to large teams. Both are strong. Laravel is the more common answer for a product; Symfony is the more common answer inside a large organisation.

Is PHP fast enough for a high-traffic site?

Yes, and the evidence is that a large share of the highest-traffic sites in the world run on it. Modern PHP is dramatically faster than its reputation, and where PHP applications are slow it is almost always the database or missing caching rather than the language. Long-running worker models close most of the remaining gap where it matters.

Can a WordPress developer work on our Laravel application?

Sometimes, and it should be tested rather than assumed. WordPress development is often plugin and theme work within a fixed system, which is a different skill from building an application with a framework, a domain model and a test suite. Some WordPress developers are excellent application engineers. Many have not needed to be.

What does bad PHP look like in review?

Concatenated SQL, business logic inside templates, error suppression, no dependency manager, no tests, and static state everywhere. All six are visible in minutes, and any two of them together predict that changes to this codebase will be slow and risky for as long as it exists.

Should we rewrite our legacy PHP application?

Usually no, or at least not all at once. Rewrites of systems that are still earning money have a poor record, because the old system's behaviour is never fully documented and the new one has to reproduce it exactly. Strangling it incrementally, one module at a time behind a stable interface, is slower to feel satisfying and much more likely to finish.