What does a freelance PHP developer work on today?
Mostly on systems that already exist. PHP runs a very large share of the web, including WordPress, and countless Indian businesses rely on PHP software written in the 2010s for ordering, billing, admissions or dealer management. Those systems still earn money, so the typical request to a freelance PHP developer is not “build something new” but “keep this working and make it safer”.
That work splits into four kinds. Maintenance: fixing bugs, applying patches, handling small feature requests. Upgrades: moving to a supported PHP version or a newer framework release. Migrations: shifting from one framework to another, or from shared hosting to a VPS. New builds: fresh applications, which we usually write in Laravel.
A good freelance PHP developer is comfortable across all four and honest about which one you actually need. Many owners arrive asking for a rewrite when a careful upgrade would cost a fraction and carry less risk.
- Bug fixes and error tracing in production
- PHP and framework version upgrades
- Framework or hosting migrations
- New modules added to an existing system
- Fresh Laravel or CodeIgniter 4 applications
- APIs for mobile apps and third-party tools
Legacy PHP maintenance: keeping an old system alive without surprises
Legacy PHP is not a problem in itself. Code that has run for ten years has survived real use, and there is knowledge baked into every odd condition. The risk lies elsewhere: unsupported PHP versions, missing backups, no version control, credentials hard-coded in files, and a single person who understood it and has since left.
Our first move on any legacy engagement is boring on purpose. We put the code into a Git repository you own, take a verified database backup, copy the whole thing to a staging server, and turn on error logging. Only then do we change anything. This order sounds slow; in practice it saves days, because every later fix can be tested and reversed.
Next comes a written map of the system: entry points, cron jobs, database tables that matter, third-party calls such as SMS or payment callbacks, and places where secrets live. That map becomes the document the next developer, whoever it is, will thank you for.
Week one on a legacy system
Repository, backup, staging copy, error logs, system map. Small urgent fixes only.
After that
A prioritised list of risks and improvements, each priced separately, so you choose the order.
Which PHP version is your site running, and why does it matter?
It matters because unsupported PHP versions no longer receive security fixes. PHP 7.4 reached end of life in November 2022, PHP 8.0 in November 2023, and PHP 8.1 stopped getting security patches at the end of 2025. As of this page, PHP 8.2 receives security fixes until the end of 2026, while 8.3, 8.4 and 8.5 are supported for longer.
Hosting providers eventually drop old versions, and that is when legacy sites break overnight. The quickest way to check your version is the hosting control panel’s PHP selector or a phpinfo page placed briefly on staging, never left on the live site.
If you are on PHP 7.x or older, plan an upgrade now rather than when the host forces it. A freelance PHP developer can usually move a mid-sized application to PHP 8.3 or later in stages, with the old version still available as a fallback until testing is complete.
Security fixes are only half the reason. Newer versions are noticeably faster for most applications, which often cuts hosting load without any other change.
How do you upgrade an old PHP application without breaking it?
Upgrade in small, reversible steps on a copy of the system, never directly on production. The rough sequence we follow is the same for core PHP, CodeIgniter or Laravel.
- Clone the live site to staging with a fresh database copy
- Add Composer if missing and pin current dependencies
- Run static analysis with PHPStan to list likely breakages
- Apply automated refactors with Rector for the target version
- Replace removed features, such as the old mysql_* functions dropped in PHP 7, with PDO or mysqli prepared statements
- Write smoke tests for the money paths: login, order, invoice, payment callback
- Switch staging to the new PHP version and fix what fails
- Schedule the production switch at a quiet hour with the old version ready for rollback
Automated tools do a large share of the mechanical changes, but not the judgement. Dynamic code, string-built SQL and old libraries still need a human to read them. Expect a few rounds of testing with your staff, because they know which screens matter on a Monday morning.
Laravel, CodeIgniter, Symfony or core PHP: which should a freelance PHP developer use?
For a new application, we default to Laravel unless there is a reason not to. It has built-in authentication scaffolding, queues, scheduled tasks, migrations and a very large ecosystem, and it is easy to find another Laravel developer later if you need one. Laravel ships a major version each year, with bug fixes for 18 months and security fixes for two years, so plan an upgrade roughly every year or two.
CodeIgniter 4 still suits smaller applications and teams that liked CodeIgniter 3’s lightness. Symfony fits large, long-lived systems and is also the foundation many Laravel components are built on. Core PHP without a framework makes sense for tiny scripts, and for legacy systems where adding a framework would mean a rewrite.
Pick Laravel when
You are building a portal, SaaS product or internal tool that will grow, need queues or scheduled jobs, and want a large hiring pool later.
Pick CodeIgniter 4 when
The app is small, the host is modest, or your team already knows CodeIgniter conventions.
Stay with core PHP when
The code works, is modest in size, and the cost of adding a framework outweighs the benefit. Clean it up instead.
CodeIgniter 3 to CodeIgniter 4: what the migration really involves
Treat it as a rebuild on a new structure rather than an update. CodeIgniter 4 changed namespaces, the folder layout, routing, the model layer and much of the core API, so there is no single command that converts a CodeIgniter 3 project.
The safest pattern is module by module. Stand up CodeIgniter 4 beside the old app, share the same database, and move one area at a time, for instance the customer login first, then orders, then reports. Your users keep working on the old screens until each new one is tested. Business rules buried in controllers get pulled out into services along the way, which makes the new code easier to test.
Sometimes the numbers point elsewhere. If most of the application will be rewritten anyway, moving straight to Laravel may cost about the same and give you a larger pool of developers later. We lay out both paths in the audit so you can compare, with each module priced.
Should you refactor your PHP code or rewrite it from scratch?
Refactor in most cases. Rewrites look clean on paper but throw away years of fixes for edge cases nobody documented, and they take longer than anyone estimates. A freelance PHP developer who recommends a rewrite in the first conversation, without having read your code, is guessing.
Rewriting does make sense in a few situations: the code has no structure at all and every change breaks something else; the business process has changed so much that most screens are obsolete; or the technology cannot be secured without replacing most of it. Even then, a phased rewrite, one module at a time, beats a big-bang switch.
- Refactor if the core logic is right and the pain is age, style or version
- Refactor if staff rely on current screens and retraining is costly
- Rewrite if every change breaks something unrelated
- Rewrite if most features no longer match how you work
- Either way, move in modules and keep the old system as fallback
How much does a freelance PHP developer cost in India?
Rates vary widely, and comparing hourly figures is less useful than comparing plans. A lower hourly rate on a codebase the developer does not understand can easily cost more than a higher one from someone who has done five similar upgrades.
With BtechWaleTech, a brand-new custom web app in PHP starts at ₹60,000 (US$900) and takes 6–12 weeks. A PHP-backed website starts at ₹10,000, an online store at ₹50,000. Ongoing maintenance, which covers patches, dependency updates, backups and small changes, starts at ₹8,000/mo per month. Legacy fixes, upgrades and migrations are priced after an audit, as separate lines you can accept one by one.
What pushes a PHP quote up: code size, no version control, no tests, very old PHP versions, custom frameworks written in-house, unclear database relationships and integrations with partners who are slow to respond. What pulls it down: clean access, a staging server, one decision-maker and staff available to test. For market context see freelance developer rates.
How to vet a freelance PHP developer before giving code access
Ask them to read something, not write something. A short, paid review of one file from your system tells you more than a coding test on a toy problem. Good reviewers spot SQL built from strings, passwords stored with MD5, missing CSRF checks and business logic tangled into views, and explain each in plain words.
Then ask process questions. How will they get the code into version control? What will they do before touching production? How do they handle secrets in configuration? Which PHP version would they target and why? The answers should mention staging, backups, a .env file outside the web root, and a supported version.
Give the minimum access needed at each stage: a read-only repository copy for the audit, staging credentials for the work, production only for deployments. Change passwords after any freelancer engagement ends, including ours. It is good hygiene, not an accusation.
- Paid review of one real file, with written findings
- Clear plan for version control, backups and staging
- Target PHP version named, with a reason
- Least-privilege access, stage by stage
- Written change log of every production deployment
Security fixes a freelance PHP developer should look for first
Older PHP systems tend to share the same handful of holes, and fixing them is usually quicker than owners fear. We check these on every audit and fix them in order of risk.
SQL injection
Queries built by joining user input into strings. Replace with prepared statements through PDO, mysqli or the framework’s query builder.
Weak password storage
MD5 or SHA1 hashes. Move to password_hash and password_verify, rehashing users gradually as they log in.
Unprotected forms
No CSRF tokens on actions that change data. Add them; frameworks include this out of the box.
File uploads
Uploads saved inside the web root with their original names. Validate type and size, rename, store outside public folders.
Exposed secrets and debug output
Database passwords in committed files, display_errors on in production, phpinfo pages left online. Move secrets to environment config and switch off public errors.
Outdated libraries
Old Composer packages or copied-in libraries with known issues. Update, or replace if abandoned.
If your site has already been compromised, see hacked website repair for the clean-up order.
Slow PHP pages are usually slow databases. Before touching code, we turn on the slow query log and look at which queries run most often and longest. Missing indexes and the classic “N+1” pattern, where a page runs one query per row in a list, account for most of the pain.
After the database, three quick wins: make sure OPcache is enabled, move to a current PHP 8 release, and cache results that rarely change, such as menu trees or price lists. For Laravel, route, config and view caching plus queued background jobs help a lot. If you are on crowded shared hosting and traffic has grown, a small VPS or an AWS instance with PHP-FPM behind Nginx is often the right step; another of us handles that side.
For public pages, check Core Web Vitals too. A fast server does not help if the page ships heavy images and scripts. Our speed optimisation page covers the front-end half.
What you should own when a PHP project changes hands
PHP systems are often lost not to bugs but to missing information: a cron job nobody knew about, an SMS gateway password in one person’s email, a database that exists only on a server whose login has expired. Handover is where you fix that permanently.
Whether you are taking over from a previous freelancer or leaving us, the checklist is the same. You should hold the Git repository with full history, the production server or hosting account login, database credentials plus a recent dump, the environment configuration with every third-party key listed, the list of scheduled tasks and what each does, DNS access, and a short runbook explaining how to deploy and roll back.
We leave that runbook in the repository as plain text, so it travels with the code. If the previous developer will not share one of these items, record the gap and plan how to recreate it, such as rotating keys with the provider, rather than waiting on someone who may never reply.
- Git repository with history, owned by you
- Server, hosting and database credentials
- Environment file contents and third-party keys
- Cron jobs and background workers documented
- Deploy and rollback runbook
PHP systems in Indian businesses: hosting, GST, UPI and Hindi text
Much Indian PHP software shares a pattern: shared cPanel hosting, a MySQL database, a billing or order module with GST calculations added over the years, and SMS or WhatsApp notifications bolted on. That pattern brings a few specific jobs.
GST logic deserves tests of its own, because rate or rule changes have to be applied without disturbing old invoices. UPI and card payments usually arrive via server callbacks, and those callbacks must verify signatures and handle repeats safely, or orders get marked paid twice. Hindi and regional-language text needs the utf8mb4 character set end to end; older databases created with latin1 show broken characters until the tables and connections are converted properly.
Finally, budget hosting often lags on PHP versions. Before any upgrade, confirm your host offers the target version, or plan a move. We can migrate you to a VPS in your own account, keeping downtime to a short window.
A worked example: rescuing a distributor’s CodeIgniter 3 portal
This is a hypothetical scenario, not a client story, to show how a freelance PHP developer would approach a typical rescue.
A wholesale distributor in Kanpur uses a CodeIgniter 3 portal where retailers place orders and staff print GST invoices. It runs on PHP 7.2 on shared hosting. The host has announced it will remove old PHP versions, and the original developer has moved on. There is no Git history, only a zip file.
Week one: we create a private repository in the distributor’s account, back up the database, build a staging copy and map the system: 40-odd controllers, three cron jobs, an SMS integration and one payment callback. Week two: we fix string-built SQL in the order search, move passwords to password_hash, and bring the code up to PHP 8.2 using Rector plus manual fixes, keeping CodeIgniter 3 for now. Staff test orders and invoices on staging.
The audit also prices two paths for later: a module-by-module CodeIgniter 4 migration, or a Laravel rebuild of the retailer side only. The owner picks the upgrade now and ongoing maintenance from ₹8,000/mo, and decides on the bigger move next year with real numbers in hand.
Freelance PHP developer services across India
PHP work is done entirely over secure access and screen-shares, so your location does not change the process or the pricing. City pages describe local business context.
North: Noida, Gurgaon, Kanpur, Jalandhar and Gwalior. West: Ahmedabad, Aurangabad, Jodhpur and Udaipur. South: Vijayawada, Warangal, Tiruchirappalli and Belagavi. East and Northeast: Kolkata, Dhanbad and Shillong.
Agencies and companies abroad also hand us PHP maintenance, billed in USD via Wise, bank wire or PayPal; see countries we work with and our white-label terms.
Purana PHP software chal raha hai? Seedhe shabdon mein kya karein
Agar aapka billing ya order software purane PHP version par hai, toh ghabraiye mat, lekin ignore bhi mat kijiye. Hosting company kabhi bhi purana version band kar sakti hai aur tab site achanak ruk jaati hai.
Pehla kadam: code ko Git mein daliye, database ka backup lijiye aur ek staging copy banwaiye. Phir PHP 8 par upgrade step by step hota hai, har step test karke. Poora naya software banana har baar zaroori nahi hota; aksar sudhaar sasta aur surakshit padta hai. Hum pehle audit karte hain, phir har kaam ki alag line wala quote dete hain. Naya custom web app ₹60,000 se shuru hota hai, maintenance ₹8,000/mo se.