Technology

PHP Support Services
Upgrades and patches without a rewrite.

We run PHP support services Australia wide, for teams stuck on an old version or left behind when their developer moved on. We handle PHP 5 to 8 upgrades, legacy PHP modernisation, security patching and framework migrations.

Codebase inherited from a previous agency? We audit it, document it, and take it over on a monthly plan.

  • AU-built Australian owned and operated
  • PHP 5.6 → 8.x Upgrades Stack we work with daily
  • Security Patching & Audits New builds + modernisation
  • Fixed Price scopes, no surprises
Australian owned and operated

Built here. Your data stays here.

  • No offshore development. Everything is written by our own team in Australia. Nothing is subcontracted overseas.
  • Your data stays onshore. Hosted in Australia, on infrastructure you own, under Australian law.
  • Every state, not just ours. Perth, Melbourne, Sydney, Brisbane, Adelaide and everywhere between.
PHP Support

Hand the ageing PHP app to someone who will fix it

PHP powers 77% of the web. But a PHP application that has not been maintained is a ticking clock. Old PHP versions have known security vulnerabilities. Outdated Composer packages have unpatched CVEs. Deprecated functions start throwing warnings and then errors as versions advance.

The most common scenario: a PHP application was built years ago by a freelancer or agency. It works fine. Then the hosting provider announces PHP 7.x end-of-life. Or a security scan flags vulnerabilities. Or the developer has moved on and nobody understands the code.

We upgrade PHP versions, patch security issues, migrate frameworks, take over codebases, and provide ongoing support. If your PHP application needs a developer, we are that developer.

What We Do

Fixes, upgrades and cover for your PHP app

Version upgrades, security fixes, framework migrations, ongoing support, and performance optimisation. Whatever your PHP application needs.

PHP Version Upgrades

PHP 5.6, 7.0, 7.1, 7.2, 7.3, 7.4: all end-of-life. No security patches, no bug fixes. Hosting providers are dropping support. If your application runs on an EOL PHP version, upgrading is not optional. It is a security requirement.

We upgrade PHP applications to PHP 8.1, 8.2, or 8.3. This means fixing deprecated functions, updating type declarations, handling strict typing changes, resolving incompatible library versions, and testing everything. It is not just changing a version number.

Security Patching & Vulnerability Remediation

PHP applications with known vulnerabilities: SQL injection, XSS, CSRF, insecure file uploads, session management issues, or outdated dependencies with CVEs. We audit, identify, and fix security issues.

Composer dependency audit. Every package checked against known vulnerability databases. Outdated packages updated or replaced. Abandoned packages swapped for maintained alternatives.

Framework Version Upgrades

Laravel 5.x, 6.x, 7.x, 8.x to Laravel 10 or 11. CakePHP 2.x to 5.x. Symfony 3.x to 7.x. CodeIgniter 3 to 4. Framework upgrades require migrating deprecated features, updating routing, handling breaking changes, and testing.

Laravel upgrades are the most common request. Each major version introduces breaking changes: middleware, routing, authentication, queue configuration, and Eloquent. We follow the official upgrade guides and test thoroughly.

Ongoing PHP Application Support

Monthly support plans for PHP applications. Bug fixes, security patches, performance monitoring, and small feature requests. A developer who knows your codebase, available when you need them.

Proactive monitoring: uptime checks, error tracking, performance metrics, and dependency vulnerability scanning. Issues caught before they become outages. Monthly reports showing what was done and what needs attention.

PHP Performance Optimisation

Slow PHP application? We profile, identify bottlenecks, and fix them. Common issues: N+1 database queries, missing indexes, no caching, synchronous processing of heavy tasks, and unoptimised Composer autoloading.

OPcache configuration, query optimisation, Redis or Memcached caching, queue workers for background processing, and CDN configuration for static assets. The combination of these improvements is usually dramatic.

Capabilities catalogue

Every kind of PHP help, in one place

Every capability below has been delivered for a real Australian business, from a single PHP 7 to PHP 8 upgrade to a full legacy framework rewrite on Laravel with parallel-run and zero-downtime cutover. If your scenario is not listed, ask, we build bespoke.

Legacy PHP 5 → PHP 8 upgrade

  • PHP 5.6 → PHP 8.3 full version upgrade with deprecated function fixes
  • PHP 7.0 / 7.1 / 7.2 → PHP 8.x compatibility remediation
  • PHP 7.4 → PHP 8.2 strict-type and union-type migration
  • mysql_* → mysqli / PDO conversion for PHP 7+ compatibility
  • Mcrypt → OpenSSL / Sodium replacement for PHP 7.2+
  • Each() / create_function() / curly-brace-string removal for PHP 7.4+
  • Laravel + PHP version dual upgrade path
  • Hosting provider EOL-deadline rescue migrations

Symfony 2/3 → Symfony 6/7 upgrade

  • Symfony 2.x → Symfony 6 LTS staged upgrade with bundle modernisation
  • Symfony 3.x → Symfony 7 with Flex recipes and modern config
  • Symfony 4 / 5 → Symfony 6 / 7 with attribute-based routing
  • Doctrine ORM 1.x / 2.x → Doctrine 3.x migration
  • Twig 1 / 2 → Twig 3 template upgrade
  • Composer 1 → Composer 2 dependency-graph rebuild
  • Symfony bundle deprecation audit and replacement plan
  • Symfony WebProfiler & monolog re-instrumentation post-upgrade

Old custom PHP framework → Laravel rewrite

  • Bespoke procedural PHP → Laravel 11 incremental strangle-fig rewrite
  • CodeIgniter 2 / 3 → Laravel 11 rebuild with route-by-route cutover
  • CakePHP 2 / 3 → Laravel rewrite with shared database staging
  • FuelPHP / Yii 1 / Kohana → Laravel 11 modernisation
  • WordPress-as-app → Laravel admin rebuild with WP front-end retained
  • Custom MVC frameworks → Laravel + Livewire / Inertia
  • Authentication / RBAC re-implementation in Laravel Sanctum
  • Background job migration to Laravel queues + Horizon

PHP security patching

  • SQL injection remediation across legacy mysql_* and raw-PDO calls
  • XSS / CSRF hardening with proper escaping and token handling
  • File-upload vulnerability remediation (MIME, size, path traversal)
  • Session-fixation, hijacking and cookie-flag remediation
  • Insecure deserialisation and unsafe unserialize() removal
  • Composer dependency CVE audit with Roave / Symfony security checks
  • Server-side PHP hardening (disable_functions, open_basedir, OPcache)
  • Hacked WordPress + PHP cleanup

Composer dependency modernisation

  • Composer 1 → Composer 2 migration with dependency-graph rebuild
  • Abandoned package replacement with maintained equivalents
  • PSR-0 → PSR-4 autoloading conversion
  • Lockfile audit and reproducible-build setup
  • Private Satis / Packagist mirror for Australian-hosted PHP teams
  • Renovate / Dependabot setup for ongoing dependency PRs
  • Vendor-folder cleanup and dev-dependency separation
  • Composer-based deployment pipeline (Deployer / Envoyer / GitHub Actions)

Long-term PHP support contracts

  • Monthly retainer covering security patches and dependency updates
  • On-call emergency PHP / Laravel / WordPress incident response
  • Quarterly PHP version compatibility audit
  • Proactive uptime, error-rate and PHP-FPM monitoring
  • Code-takeover after previous developer / agency exit
  • Documentation, runbook and CI/CD setup as part of onboarding
  • SLA-backed turnaround for bug fixes and small feature requests
  • Roadmap planning for next major PHP / framework upgrade window

PHP upgrade and modernisation work

  • PHP upgrade project scoped, fixed-price, with a tested rollback
  • PHP application developer work delivered locally, not offshored
  • PHP application modernization onto a supported framework
  • PHP 7 to PHP 8 migration including deprecated function fixes
Case Study

Client portal that cut email volume by 70%

We built a secure document exchange and task tracking portal for an accounting firm. Clients upload, review and approve, all in one place instead of email.

Read the full case study
70% Less email volume
3x Faster turnaround
400+ Active client accounts
Why Us

Why your PHP app is in safe hands

Deep PHP experience across frameworks and versions

We have worked with PHP since version 4. Laravel, Symfony, CakePHP, CodeIgniter, WordPress, Drupal, and plain PHP applications. From PHP 5.2 procedural code to PHP 8.3 with Fibers and enums. We know the language inside out.

This matters because PHP upgrades are not straightforward. Each version introduced changes that can break existing code in subtle ways. PHP 7 changed error handling. PHP 7.4 added typed properties. PHP 8.0 changed string-to-number comparisons. PHP 8.1 deprecated passing null to non-nullable internal function parameters. Experience means knowing where to look.

We also understand the Australian hosting landscape. Shared hosting on cPanel, VPS providers like Vultr and DigitalOcean, AWS, and Azure. Each has different PHP configuration options and constraints.

No lock-in: your code, your hosting, your choice

We work on your existing hosting, your existing codebase, and your existing deployment process. We do not require you to move to our infrastructure or use our tools. The code and the server are yours.

If you want to bring another developer on later, or take development in-house, everything is documented and accessible. No proprietary frameworks, no encrypted code, no dependency on our continued involvement.

Source code in your Git repository. Documentation in your wiki. Deployment scripts that anyone can run. We set things up so you are not dependent on any single provider, including us.

Honest advice about when to upgrade vs rebuild

Not every PHP application should be upgraded. Sometimes the codebase is so old, so poorly structured, or so far behind that a rebuild is cheaper and faster than trying to upgrade. We will tell you honestly which path makes sense.

The decision depends on: how old the PHP version is, the quality of the existing code, whether the framework is still actively maintained, and how much the application needs to change. An upgrade is usually cheaper. A rebuild is sometimes necessary.

We scope both options and give you a fixed-price quote for each. On clean code, the upgrade is almost always cheaper. On a messy codebase with no tests, an upgrade and a rebuild can end up close, at that point the rebuild gives you a better long-term result.

Thorough testing: upgrades do not break things

PHP upgrades can introduce subtle bugs. A function that returned false now throws an exception. A type coercion that worked in PHP 7 behaves differently in PHP 8. These are not always caught by automated tests.

We use a combination of automated testing (PHPUnit, Pest), static analysis (PHPStan, Psalm), and manual testing of critical workflows. Existing test suites are updated for the new PHP version. Missing tests are added for critical paths.

Staging environment testing before production deployment. The upgrade is verified on a copy of your production environment before touching the live system. Rollback plans in place. No surprises.

Support Services

From an urgent fix to a monthly plan

Emergency fixes, security audits, code takeovers, and monthly support plans. Whatever your PHP application needs, we handle it.

Emergency PHP Fixes

Site down? Security breach? Critical bug in production? We respond quickly to PHP emergencies. Diagnose, fix, and deploy, often same day.

Composer Dependency Management

Outdated packages, abandoned libraries, and version conflicts. We untangle Composer dependencies, update to maintained versions, and resolve conflicts.

Security Audit

Full security audit of your PHP application. SQL injection, XSS, CSRF, authentication, session management, file uploads, and dependency vulnerabilities.

Code Takeover

Previous developer left? We audit the PHP codebase, document the architecture, set up CI/CD, and start maintaining it. Bug fixes and feature development resume.

Server & Hosting Migration

Move from shared hosting to VPS, from old servers to AWS or DigitalOcean. PHP, database, files, cron jobs, and email configuration migrated with zero downtime.

Monthly Support Plans

Retainer-based support. Allocated hours for bug fixes, updates, security patches, and small feature requests. Proactive monitoring and regular dependency updates.

Common Scenarios

Does one of these sound like your week?

If one of these sounds familiar, we can help.

01

PHP 5.6/7.x → PHP 8

End-of-life PHP version upgraded to a supported version. Hosting provider deadline approaching, or security audit flagged the old version.

02

Laravel 5/6/7 → Laravel 11

Older Laravel application upgraded to the latest version. Middleware, routing, authentication, queue, and Eloquent changes handled.

03

Security Vulnerability Fix

Penetration test or security scan flagged vulnerabilities. SQL injection, XSS, outdated dependencies, or insecure configuration fixed.

04

Developer Left. Need a Takeover

Previous PHP developer or agency gone. Code needs to be understood, documented, and maintained by a new team.

05

Slow PHP Application

Performance degradation. Slow page loads, high server CPU, or database timeouts. Profiling, query optimisation, and caching implemented.

06

Legacy PHP Modernisation

Old procedural PHP code incrementally modernised. Introduce namespaces, Composer, OOP patterns, and eventually a framework, without a full rewrite.

How It Works

How a PHP upgrade runs, from audit to monitoring

From audit to post-upgrade monitoring. No surprises, no untested changes to production.

  1. 1. Code & Dependency Audit

    We clone the repository (or access the server), run static analysis, check PHP version compatibility, audit Composer packages, and identify deprecated function calls, removed features, and breaking changes. You get a detailed report.

  2. 2. Staging Environment Setup

    A copy of your production environment with the target PHP version. The application runs on staging first. Issues identified and fixed without touching production.

  3. 3. Compatibility Fixes

    Deprecated functions replaced. Type declarations updated. Composer packages upgraded to versions compatible with the target PHP version. Breaking changes in string handling, type coercion, and error handling addressed.

  4. 4. Testing

    Automated tests run against the updated code. Static analysis with PHPStan or Psalm. Manual testing of critical user workflows. Regression testing for edge cases that automated tests miss.

  5. 5. Production Deployment

    PHP version upgraded in production during a scheduled maintenance window. Deployment verified, monitoring active, rollback plan ready. Most upgrades deploy with zero issues because staging caught everything.

  6. 6. Post-Upgrade Monitoring

    Monitoring for 2 to 4 weeks after the upgrade. Error tracking active. Performance compared to pre-upgrade baseline. Issues caught and resolved quickly.

Technical Context

The rest of the setup behind your PHP app

PHP applications do not exist in isolation. These are the related technologies we handle as part of PHP support engagements.

Laravel

The most popular PHP framework. If your application is Laravel, version upgrades and PHP upgrades go hand in hand.

WordPress

WordPress sites need PHP upgrades too. Themes, plugins, and custom code all need to be compatible with the target PHP version.

MySQL / MariaDB

PHP application databases. MySQL version upgrades are often needed alongside PHP upgrades for compatibility and security.

Linux Server Administration

PHP runs on Linux. Server configuration, PHP-FPM tuning, OPcache, and security hardening.

AWS / DigitalOcean

Cloud hosting for PHP applications. EC2, Lightsail, or DigitalOcean droplets with proper PHP configuration.

PHPUnit / Pest

Testing frameworks for PHP. We write and maintain tests as part of the upgrade process to catch regressions.

Our hosting provider gave us 60 days to upgrade from PHP 7.2. Our old developer was gone. HELLO PEOPLE audited the codebase in a week, upgraded to PHP 8.2 in three weeks, and set us up with monthly monitoring. Smooth as. Should have called them sooner.

IT Manager Logistics company, Melbourne
FAQs

What people ask before handing over a PHP app

My hosting provider says I need to upgrade PHP. Is it urgent?

Yes. Once your host drops the version, the site stops working. And any PHP release past its end-of-life date gets zero security patches, so you're exposed to known exploits every day you delay. Treat it as urgent.

How do you scope and price a PHP upgrade?

We audit the codebase first (Composer dependencies, custom code, test coverage), then send a fixed-price quote. A small WordPress or CodeIgniter site on clean code is at the low end. A custom Laravel app with heavy business logic is the high end. You'll see the number before we start.

Will upgrading PHP break my website?

It can, which is why we never upgrade production directly. Every upgrade runs on a staging copy first. We fix compatibility issues, run automated and manual tests, and only cut over once staging is green. Rollback plan sits ready in case anything surfaces.

My PHP app is on version 5.6. Can it be upgraded?

Almost always, yes. The jump from PHP 5.6 to PHP 8 is big (deprecated functions, changed type behaviour, removed features), so it takes more effort than a 7.4 to 8 hop. We audit the code and tell you honestly whether an upgrade or a rebuild is cheaper.

What about my WordPress plugins?

Every active plugin gets checked against the target PHP version. Most major plugins already support PHP 8. Abandoned or single-author plugins sometimes need replacing, and we flag those in the audit before any work starts.

Can you take over our PHP application from another developer?

Yes, and it's one of our most common jobs. We audit the codebase, document the architecture, set up Git and CI/CD if missing, and start maintaining it. You get a working handover pack so you're never locked into us either.

Do you offer ongoing PHP support plans?

Yes. Monthly retainers cover security monitoring, dependency updates, bug fixes, and small features. Larger plans add proactive performance monitoring and more development hours. Plan size is set by app complexity and traffic, not a per-seat licence.

Should I upgrade my PHP application or rebuild it?

Upgrade if the code is reasonably clean, the framework is still maintained, and the app still fits your business. Rebuild if the codebase is a mess, the framework is abandoned, or the business has outgrown it. We'll scope both and give you the numbers side by side.

Tell us what is wrong with your PHP app

Describe the application, the PHP version, and what you need: upgrade, security fix, or ongoing support. We'll audit and come back with a plan.

Prefer a quick chat? Call 0425 531 127. We answer the phone in Perth.