← All articles
SecurityPHPWordPressTeaching

PHP Is a Loose Language

October 15, 2013 · Jonathan EllisPosted July 20, 2026
Photo by Yusuf Onuk on Pexels
Share thisXLinkedInFacebookEmail

I have been teaching security to designers, which sounds stranger than it is.

The course started with WordPress and drifted outward, into content management more broadly. How to theme it so it holds together. How to structure it so a client can actually live inside it. And how to keep it from being torn open — the part nobody signs up for, and the part everybody turns out to need.

Here is the plain version. PHP is a loose language. It is forgiving to a fault. It will let you do almost anything, including a great many things you shouldn't, and it won't say a word as you go past. That looseness is why so much of the web runs on it. It is also why so much of the web can be pried open.

Most designers would rather not think about any of this, and I understand the reflex. Security feels like someone else's job, a thing for the people who live in the terminal. But if you built the site, you built the door too, and you don't really get to be surprised about who comes through it.

So I teach it. Not to turn designers into engineers — that isn't the point — but so they stop being intimidated by the parts of the trade that look like machinery. Knowing why a plugin is a risk, why an update matters, why you never trust what a user types — that isn't engineering. It's hygiene.

The most useful thing I can hand a student isn't a technique. It's the sense that the machinery is learnable, because it is. It's rarely as hard as it's made to sound. And it's a steadier way to work, understanding the room you're in rather than leaving it to whoever else does.

Want this for your business?

Brand, web, SEO and automation, built by one operator in Edmonton.

Start a conversation →

Subscribe

Get new essays by email.

One note when something new goes up. No newsletter, no digest, no selling your address on. Leave whenever you like — every email has the link.