How to vet a PHP developer
PHP experience ranges from modern framework development to maintaining code written many years ago, so test for both depending on your needs. A strong PHP developer writes typed, object-oriented code for PHP 8, uses Composer and PSR standards, writes tests with PHPUnit or Pest and uses static analysis tools such as PHPStan. Ask candidates which recent PHP features they actually use and why.
For legacy work, look for patience and method. Good developers add tests before changing behavior, upgrade PHP versions step by step with tools such as Rector, and fix security issues such as SQL injection and missing output escaping first. Ask how they approached a large legacy codebase and what they changed in the first month. Our PHP development page outlines our modernization approach.
Security knowledge is non-negotiable. Candidates should explain prepared statements, password hashing, CSRF protection, file upload validation and secure session handling without hesitation, since many PHP applications handle payments, personal data or administrative functions. A short code review exercise tests this quickly.
- Writes modern, typed PHP 8 code.
- Uses Composer, PSR standards and static analysis.
- Tests code with PHPUnit or Pest.
- Has upgraded legacy applications step by step.
- Applies secure coding practices by default.
- Comfortable with Laravel, Symfony or plain PHP as needed.


