A complete, self-contained, and comprehensive curriculum in Vanilla / Pure PHP (no frameworks, no external composer dependencies needed). Every topic contains working, well-commented code with modern best practices (PHP 8.x), practical examples, security considerations, and architectural design patterns.
Run the central verification runner from the root directory:
# Run all topics and verify syntax & execution:
php runner.php
# List all lesson files:
php runner.php list
# Run a specific lesson:
php runner.php 01_PHP_Basics/01_syntax_and_tags.phpOr execute any script directly with standard PHP:
php 04_Object_Oriented_PHP_Intermediate/09_enums.phpPHP for Beginner/
├── 01_PHP_Basics/
│ ├── 01_syntax_and_tags.php # Tags, echo vs print, comments, string interpolation
│ ├── 02_variables_and_constants.php # Variable scope, references (&$x), define() vs const
│ ├── 03_data_types_and_casting.php # Scalar, compound, special types, type casting, truthy/falsy
│ ├── 04_operators.php # Comparison (== vs ===), spaceship (<=>), null coalescing (??)
│ ├── 05_control_structures_conditionals.php # if/else, switch vs PHP 8 match expressions
│ ├── 06_control_structures_loops.php # for, while, do-while, foreach with reference trap & unset()
│ ├── 07_functions_basics.php # Arguments, named arguments, variadics (...), return types
│ └── 08_include_and_require/ # include vs require, include_once vs require_once
│ ├── helpers.php
│ └── main.php
│
├── 02_Data_Structures_and_Builtins/
│ ├── 01_indexed_and_associative_arrays.php # Destructuring, spread unpacking (...), array_key_exists vs isset
│ ├── 02_array_functions.php # array_map, array_filter, array_reduce, usort, array_is_list
│ ├── 03_string_manipulation.php # str_contains, regex PCRE, mb_* UTF-8 multibyte, Heredoc/Nowdoc
│ ├── 04_math_and_numbers.php # Float precision traps, secure randomness, BCMath financial math
│ ├── 05_date_and_time.php # DateTimeImmutable vs DateTime, Timezones, UTC best practices
│ └── 06_json_and_serialization.php # json_encode flags, JsonSerializable, unserialize security warning
│
├── 03_Web_Basics_and_HTTP/
│ ├── 01_superglobals.php # $_SERVER, $_GET, $_POST, $_COOKIE, why to avoid $_REQUEST
│ ├── 02_form_handling_and_validation.php # Form sanitization vs validation, filter_var, error collection
│ ├── 03_sessions_and_cookies.php # Secure cookie flags, session fixation defense, safe teardown
│ ├── 04_file_uploads.php # $_FILES structure, MIME verification with finfo, safe filenames
│ └── 05_headers_and_status_codes.php # http_response_code, JSON headers, redirects, security headers
│
├── 04_Object_Oriented_PHP_Intermediate/
│ ├── 01_classes_and_objects.php # Classes, $this, typed properties, PHP 8 nullsafe operator (?->)
│ ├── 02_constructors_and_destructors.php # PHP 8 Constructor Property Promotion, __destruct lifecycle
│ ├── 03_visibility_modifiers.php # public, protected, private, readonly properties & classes
│ ├── 04_inheritance_and_polymorphism.php # extends, parent::, method overriding, final classes/methods
│ ├── 05_abstract_classes_and_interfaces.php # Abstract classes ("IS-A") vs Interfaces ("CAN-DO")
│ ├── 06_traits.php # Horizontal reuse, conflict resolution (insteadof, as)
│ ├── 07_static_and_late_static_binding.php # static properties, self:: vs static:: (Late Static Binding)
│ ├── 08_magic_methods.php # __get, __set, __call, __toString, __invoke, __clone
│ └── 09_enums.php # Pure Enums, Backed Enums (string/int), methods in Enums
│
├── 05_Advanced_PHP_and_Modern_Features/
│ ├── 01_namespaces_and_psr4_autoloading/ # Namespaces, imports, pure PHP PSR-4 autoloader without Composer
│ │ ├── src/App/Services/PaymentService.php
│ │ └── index.php
│ ├── 02_strict_types_and_type_system.php # declare(strict_types=1), union, intersection, DNF types, variance
│ ├── 03_anonymous_functions_and_arrow_functions.php # Closures, use(), arrow functions fn(), first-class callables
│ ├── 04_generators_and_iterators.php # yield, yield from, streaming 100k items in constant memory
│ ├── 05_attributes_and_reflection.php # Native #[Attribute] declarations, ReflectionClass API
│ ├── 06_error_and_exception_handling.php # Throwable hierarchy, custom domain exceptions, error handlers
│ └── 07_fibers_and_concurrency.php # PHP 8.1+ Fibers, cooperative multitasking, suspend & resume
│
├── 06_Database_and_Data_Persistence/
│ ├── 01_pdo_connection_and_configuration.php # PDO DSNs, ATTR_EMULATE_PREPARES security, exception modes
│ ├── 02_prepared_statements_crud.php # CRUD with named/positional placeholders, PDO::FETCH_CLASS
│ ├── 03_transactions_and_acid.php # ACID transactions, beginTransaction, commit, rollBack
│ └── 04_repository_pattern_pure_php.php # Decoupled Repository Pattern & Entity mapping without ORM
│
├── 07_Security_Best_Practices/
│ ├── 01_sql_injection_prevention.php # SQLi attack demonstration vs parameterized queries, whitelisting
│ ├── 02_xss_prevention.php # Contextual escaping, htmlspecialchars flags, script tag safety
│ ├── 03_csrf_protection.php # Synchronizer Token pattern, hash_equals timing-safe validation
│ ├── 04_password_hashing.php # password_hash(), password_verify(), Argon2id, Bcrypt, rehashing
│ └── 05_data_sanitization_validation.php # Whitelist validation engine class in pure PHP
│
├── 08_Design_Patterns_and_Clean_Code_Senior/
│ ├── 01_creational_patterns.php # Singleton (with safeguards), Factory Method, Builder Pattern
│ ├── 02_structural_patterns.php # Adapter Pattern, Decorator Pattern, Facade Pattern
│ ├── 03_behavioral_patterns.php # Strategy Pattern, Observer / Event Dispatcher, Middleware Chain
│ └── 04_solid_principles.php # Single Responsibility, Open/Closed, Liskov, ISP, DIP
│
└── 09_Senior_Architecture_and_Engineering/
├── 01_mini_mvc_framework/ # Standalone lightweight MVC framework (Router, Controller, Views)
│ ├── Core/Router.php
│ ├── Core/Controller.php
│ ├── Controllers/HomeController.php
│ ├── Views/home.php
│ └── index.php
├── 02_dependency_injection_container.php # Auto-wiring IoC container using PHP Reflection API
├── 03_logging_system.php # PSR-3 styled structured file logger with daily rotation
├── 04_caching_engine.php # PSR-16 cache interface, file-based cache with TTL & Cache-Aside
└── 05_benchmarking_and_memory_profiling.php# hrtime() nanosecond profiling, memory metrics, O(1) vs O(N)
- 100% Vanilla PHP: Zero external dependencies. Everything runs natively using the built-in PHP CLI engine.
- Modern PHP 8+ Standards: Utilizes constructor property promotion, match expressions, enums, attributes, fibers, readonly classes, and first-class callables.
- Production Senior Architect Topics: Includes an IoC container with reflection auto-wiring, a miniature MVC router, a PSR-3 structured logger, a cache engine, and SOLID architecture principles.
- Security by Default: Covers SQLi, XSS, CSRF, timing attacks (
hash_equals), and secure password hashing.