The recent post about what people are using for webmail got me thinking about a perhaps irrational policy I have with my own self-hosted software: I donāt install anything written in PHP, because I have this vague notion that PHP software is often insecure. I think I probably got this idea because years ago I saw all the vulnerabilities in PHP webmail clients and PHP software like Wordpress and decided that it was the languageās faultāor at least a contributing factor.
Maybe this isnāt fair. Maybe PHP is just more accessible to new devs and so theyāre more likely to gravitate to it and make security mistakes. Maybe my perception isnāt even accurate, and webmail / blog software written in other languages is just as badābut PHP gets all the the negative attention because itās so prevalent for web apps. Maybe my policy was a good idea, years ago, but now itās just out of date.
To be clear, Iām not trying to stoke the flames of a language holy war here or anything. Iām honestly asking: Is it maybe time to revisit my anti-PHP policy? Iām looking longingly at some federated software like Pixelfed and wondering if maybe Iām just being a little too close-minded.
So Iām interested in your own experiences and polices here. Where do you draw the security line for what you will or wonāt host, and what made you make that choice?