• 6 min read

Governments Run on PHP. Here Is How You Can Help Fund and Fix It

Germany is spending 108 million euros on a PHP CMS while the PHP Foundation raised $730K. What that gap means and how PHP developers can close it.

Featured image for "Governments Run on PHP. Here Is How You Can Help Fund and Fix It"

Most of us think of PHP as the thing underneath our Laravel or Symfony apps. The PHP Foundation’s Sebastian Bergmann recently made a different argument: a lot of Europe’s public sector has already standardized on PHP applications, and almost nobody is paying for the maintenance of the language underneath them.

The numbers he lays out in Digital Sovereignty Is Written in PHP are worth a look, and so is what you can do about them this week.

The numbers

Germany is budgeting about €108 million for version 11 of the Government Site Builder, the federal administration’s standard CMS. According to the post, that breaks down as €26.88 million for product development and support, €73.2 million for migration and relaunch, and €8 million for operations, phased over four years. The Government Site Builder is based on TYPO3, and the post says the evaluation shortlist for that decision was Drupal and TYPO3. Both are PHP.

That is not a one-off. The same article points to:

  • The European Commission’s Europa Web Publishing Platform on Drupal, described at Drupal4Gov EU in January 2026 as 770 live sites for 44 Commission services.
  • Australia’s GovCMS, hosting more than 370 sites for 115 agencies.
  • Nextcloud, a PHP application, inside the German federal cloud and the openDesk sovereign workplace.

Against that, the PHP Foundation’s 2025 Impact and Transparency Report shows $730,534 in total contributions from 536 organisations and individuals. Bergmann notes that this was fewer contributors than the previous year, and that expenses exceeded donations by roughly $139,000, a deliberate choice to keep technical headcount. The Foundation’s structure page lists thirteen contracted engineers.

Bergmann is careful to say nobody in this story acted badly. His point is that the gap is structural: the institutions most dependent on PHP have no routine way to turn that dependency into maintenance funding.

A model that already works

One mechanism does exist. The German Sovereign Tech Agency commissioned work that produced the PHP-FPM Web Services Tool and the evolution of PHP’s stream layer. Public money went in, and shipped capability came out. The post says the mechanism works and lacks only the habit of being used.

Bergmann also passes along three procurement ideas from Tiffany Farriss, presented at Drupal4Gov EU:

  1. Give verified open-source contributions real weight in tender scoring, for example 20 percent of evaluation points.
  2. Budget a share of contract value for upstream maintenance, which she estimates at 2 to 5 percent, and up to 10 percent on complex projects.
  3. Contribute non-sensitive code written under public contract back upstream within 30 days.

If you write bids for agencies or government clients, item two costs you one line in a spreadsheet.

What a working developer can do

You probably do not write tenders. You still have levers.

See what your project depends on

Composer can already tell you which dependencies ask for funding:

composer fund

The command prints funding links that package authors have declared in their composer.json. It is a five-second way to find out which of your dependencies have a sponsor page. Composer stores that same data in vendor/composer/installed.json, so you can turn it into a rough report:

<?php

declare(strict_types=1);

$installed = json_decode(
    file_get_contents(__DIR__ . '/vendor/composer/installed.json'),
    true,
    flags: JSON_THROW_ON_ERROR,
);

// Composer 2 wraps the list in a "packages" key.
$packages = $installed['packages'] ?? $installed;

$fundable = [];

foreach ($packages as $package) {
    foreach ($package['funding'] ?? [] as $link) {
        $fundable[$package['name']][] = $link['url'] ?? '';
    }
}

ksort($fundable);

printf("%d of %d packages declare funding links\n", count($fundable), count($packages));

foreach ($fundable as $name => $urls) {
    printf("  %-40s %s\n", $name, implode(', ', $urls));
}

Run it on a real project and you will likely find that only a fraction of your tree has a sponsor link. That is useful information for a budget conversation, whether the budget is yours or your employer’s.

Put a number on it

The PHP Foundation sponsor page is where organisations can contribute. If your company ships products on PHP, compare what you spend on hosting, observability, and licences with what you spend on the language itself. Bergmann’s tender suggestions are a useful yardstick: a couple of percent of a project’s value is a small number for the client and a large one for maintainers.

Learn how to contribute code

Money is one path. Contributions are another, and the Foundation has started a new program for exactly that. On August 31 it announced The PHP Foundation Community Hour, a monthly one-hour interactive podcast hosted with PHP Architect. Full disclosure: I work at PHP Architect, so weigh my enthusiasm accordingly.

The details from the announcement:

  • It airs on the second Thursday of every month on the PHP Architect podcast platform.
  • Each episode features Foundation staff, contractors, and friends sharing tips on different contribution paths.
  • You can submit questions in advance through a form linked from the announcement.
  • The first episode was scheduled for September 10, 2026, on getting started with contributing to PHP, with guest Matt Stauffer and host Elizabeth Barron.

If your calendar matches the announcement, the next episode lands on the second Thursday of October, which is October 8. You can subscribe to the public calendar linked in the post to see upcoming guests.

Why bother?

Here is the argument I find most persuasive, and it is not charity. If you earn a living from PHP, you have a stake in the language having enough maintainers. Every security fix, every stream-layer improvement, every release that does not break your build is work somebody was paid or volunteered to do.

The Foundation’s own numbers say that work is funded by a few hundred donors while governments and enterprises lean on the result. You do not have to solve the procurement problem to move the needle. You can:

  1. Run composer fund and sponsor one maintainer whose package you would be stuck without.
  2. Ask your employer whether a sponsorship line exists, and if not, whether one can.
  3. Listen to one Community Hour episode and pick a small contribution path, such as documentation, testing a release candidate, or triaging an issue.

None of that requires a procurement office.

A caveat

The sovereignty article is an advocacy piece from a Foundation board member, and it says so in its framing. The contribution figures come from the Foundation’s own report, and the procurement proposals are one speaker’s suggestions, not policy. The post also notes that PHP is not the whole stack: Nextcloud has moved performance-critical file handling into Rust, and its newer data access engine spans PHP, Go, and Rust. PHP carries the application logic in these systems, while some I/O-bound paths increasingly do not.

That nuance makes the case stronger, not weaker. The layer that carries the business logic of a national CMS is exactly the layer where a language that stays healthy matters.

Sources