Key facts
- Plain text, usually UTF-8; PHP code sits inside <?php ... ?> tags and can be mixed with HTML.
- Executed by mod_php under Apache or by PHP-FPM behind Nginx or Apache; also runs on the command line with the php binary.
- Common MIME/handler names are application/x-httpd-php and text/x-php; the server must never serve it as a download.
- Typical size is a few KB to a few hundred KB; frameworks and plugins contain thousands of .php files.
- Written by developers or installed by Composer, CMS updates and plugin/theme packages.
How to open a .php file
Edit in VS Code (with a PHP extension), PhpStorm or Notepad++. To run it, install PHP or a local stack such as XAMPP or Laragon and run php file.php in a terminal.
Edit in VS Code, PhpStorm or BBEdit. Install PHP with Homebrew (brew install php), then run php file.php or serve the folder with php -S localhost:8000.
Edit with nano, vim or VS Code. Install the CLI (sudo apt install php-cli on Debian/Ubuntu), check syntax with php -l file.php and run it with php file.php.
Common problems and fixes
- Browser downloads the .php file or shows raw source code
- The web server is not handing .php files to PHP. Enable mod_php or PHP-FPM and check the PHP handler or fastcgi_pass block in your Apache or Nginx config.
- Blank white page or HTTP 500 error
- A fatal error is being hidden. Read the PHP or web server error log (or temporarily enable display_errors on a non-production site) and lint the file with php -l.
- Call to undefined function after upgrading to PHP 8
- The function was removed (for example mysql_*, each() or create_function()) or lives in a disabled extension. Replace it with the modern equivalent or enable the extension, then retest.
- Cannot modify header information - headers already sent
- Something was output before header() or session_start(), often whitespace or a UTF-8 BOM before <?php. Remove the stray output and save the file as UTF-8 without BOM.
- Unknown .php file with eval(), base64_decode() or gzinflate() appeared on the server
- This is a common webshell pattern. Do not run it; scan the file, compare against a clean copy of your CMS or plugin, and rotate passwords if it is malicious.
Often converted to or from: HTML (rendered output), PDF (via the rendered page), PHP 5/7 to PHP 8 code, PHP array to JSON