Stanislav Khromov

Stanislav Khromov

Sep 17, 2026

Scott Keck-Warren Stanislav Khromov

In this episode, Scott talks with Stanislav Khromov about his project bun-php, which allows PHP to be run through the Bun JavaScript runtime.

Links:

Stanislav's Links:

Scott's Links:

PHP Architect Social Media:

Subscribe to our magazine: https://www.phparch.com/subscribe/

Partners

This podcast is made a little better thanks to our partners.

Displace

Infrastructure Management, Simplified Automate Kubernetes deployments across any cloud provider or bare metal with a single command. Deploy, manage, and scale your infrastructure with ease. https://displace.tech/

PHPScore

Put Your Technical Debt on Autopay with PHPScore https://phpscore.com/

CodeRabit

CodeRabbit - Cut code review time & bugs in half instantly with CodeRabbit. https://www.coderabbit.ai/

Music Provided by Epidemic Sound https://www.epidemicsound.com/

phpc #php #communityCornerPodcast #podcast #phptek

Transcript

Scott Keck-Warren Scott Keck-Warren 0:05
Hello developers, and welcome to the PHP Architect Community Corner, where we have conversations with members of the web development community. I'm your host, Scott Keck Warren, and today we're talking to Stanislav Koromov about his project BunPHP, which allows you to run PHP inside of Bun. Stanislav Koromov is a full-stack software engineer from Stockholm, Sweden. He works at Schibsted as a software engineer in the text experience team, powering article delivery across major Nordic publications. His tech reaches millions of readers daily. He's also, oh, I don't want to cut that piece out. Thank you so much for finding some time to talk to us today.
Stanislav Khromov Stanislav Khromov 0:45
Thank you so much for having me.
Scott Keck-Warren Scott Keck-Warren 0:47
Yes, absolutely. So you kind of came across, um, my like radar, um, because a couple of weeks ago, or maybe last week at this point, um, there was a post on r/php that talked about this new thing called BunPHP, and I tracked it down and you're the one who actually created that. And so can you just kind of explain to people what it is that BunPHP is doing?
Stanislav Khromov Stanislav Khromov 1:09
Well, essentially, if we, if we start with Bun, Bun is like a JavaScript runtime. So you might be familiar with Node, but there are also other JavaScript runtimes like Deno is one, Bun is another one. And so essentially it's a way of running PHP on this JavaScript runtime. And, uh, to do that, we use something called WebAssembly. So, uh, I don't know if you want to go into WebAssembly now or if we will save that for, for later.
Scott Keck-Warren Scott Keck-Warren 1:37
We can save that for later, I guess. I guess so. So ultimately, like, so Bun is a runtime for JavaScript, right? So, so we were doing some JavaScript something or other. And then what, what your project BunPHP does is basically allow for PHP to run inside of Bun.
Stanislav Khromov Stanislav Khromov 1:55
Yeah, exactly. So the background to this was that like many years ago, I was working on a project that was doing like static code analysis for, in this case, it was for WordPress plugins and themes. So we would look at like how well written they are. And this project, I never had quite time to finish it, but now finally, after many years, I came around to it. And originally I was writing it in Laravel, but now I had like kind of shifted over. to writing more JavaScript and TypeScript. I thought, oh, it would be so cool if we could use all these PHP tools that obviously like are much better on, written in PHP. So stuff like CodeSniffer, PHPStan, static code analysis, be kind of cool if we could use those tools, but I wouldn't have to like ship a separate PHP runtime. So I thought, oh, would it actually work to like embed the entire PHP runtime in Bun? and run it that way. And then I also was, what came to my mind was this tweet from a while ago, which was that Bun is doing a lot of memeing. And one of the meme tweets that was circulating was like, that in the next version of Bun, you could run PHP. Now, of course, this is a joke, right? So you can't, because it would be like, say, like, then the next version of PHP and PHP 9, you'll be able to run JavaScript. I mean, it's kind of like, I mean, you can kind of run JavaScript in PHP, but through third-party modules. But I thought, what if we combine this and like actually make the tweet like come true? And actually, in the same way, at the same time, I'm solving like a problem that I'm having right now.
Scott Keck-Warren Scott Keck-Warren 3:32
Yeah, I find it really fascinating because like in the PHP ecosystem, we have like several projects where they're like, we're just gonna take PHP and like just stick it in some other thing. So it's always interesting to like to see that that also is kind of happening here. And so I just kind of want to unpeel that a little bit. So, so the idea is like you already had some PHP code and, and you wanted to run the static analysis tools using like through Bun, run it on the PHP code. Is that, is that kind of like how that worked?
Stanislav Khromov Stanislav Khromov 4:01
Yeah, exactly. It's not like that different from if you're running like PHP on Apache, you know, you have mod_php, which is basically Apache is the runtime, right? That provides the, the web server and all of the like lifecycle of requests and you're saying, okay, I want to like hook in PHP and PHP kind of lives like a little parasite is the wrong word, but it lives like an embed inside of Apache, as opposed to like PHP-FPM, where, you know, you have like a separate server and they communicate through like the CGI interface or whatever that's called. This is quite similar. Bun provides the runtime, Bun provides the like serving of requests if you want to have that. And then PHP lives as like a little embedded engine of PHP, lives as an embedded entity inside, inside of Bun. So it can do the same things as, uh, as, uh, PHP can do in other places, but it's kind of like embedded within the runtime. And additionally, because it's using WebAssembly, WebAssembly is kind of like, it's kind of like a universal language where you can compile any code into like a JavaScript-like representation. So somebody has actually, compile the entirety of PHP into this sort of like portable blob of JavaScript-like code that can be embedded in different JavaScript runtimes. And so this is what actually runs. So it also provides like a sort of isolation layer. So for example, the file system is virtualized. Some of the function calls are virtualized. Like if you do, what do we do? Like environment, like you call environment API. So you call like— exec into shells, you know, that won't actually be an actual shell on the machine that you would execute into because you're inside this wrapped WebAssembly container. So there's also some security things there that actually has good security properties. So for example, if I were to want to run user code that I haven't vetted, like having that extra, it's not That's not enough to get full protection, but it's enough to get a lot of protection out of the box and make it easier to kind of isolate those, uh, um, cases where people might do things that you don't want them to do.
Scott Keck-Warren Scott Keck-Warren 6:22
So, so, and I, I guess maybe like I'm, I'm misunderstanding this a tiny bit. So, so, so is the PHP executing in the user's web browser or is it executing on the server?
Stanislav Khromov Stanislav Khromov 6:32
Well, it's in this case, in this package, it's executed on the server. So, so WebAssembly, but WebAssembly, that's the thing that is sometimes tricky is that WebAssembly is isomorphic, as it's called, what a nice name. You can run the same exact same WebAssembly blob that has PHP in the browser. In fact, there's the people who compiled this. This is an underlying package that has like the different PHP versions that are compiled to WebAssembly. It's compiled by the WordPress project. And actually they have a, like a demo where they will actually boot up WordPress, like in your browser. Like there's no backend, like the whole of WordPress with SQLite and all the PHP code is running in your browser. So it's basically this, exactly that same runtime, but on the server side with Bun. Like there's no, not really any, there's no like client side part in this particular project. So everything runs on your server and you can interface. between BUN, so between JavaScript code and PHP code easily. And in fact, that's like, what is like people, what one person asked, like, what does the package actually do? Can't you do it yourself? Like you can, but the majority of the package is actually like trying to, like when you send a string from JavaScript to PHP, strings can be different in different languages. Like some strings are always UTF coded, some strings can be ASCII. And so a lot of the to work is actually normalizing the data structure. So when somebody— now I don't remember, there are some special things about PHP with how it handles like null values and stuff like that. So like when somebody sends a null from a null versus undefined, for example, how do you normalize this when you send this to PHP from JavaScript and the other way around? If you get like a null from PHP and you want to send it to JavaScript, how do you like interpret that? So it's a lot of the packages kind of handling those situations where you don't get anything that you didn't expect when you convert from, from one language to the other.
Scott Keck-Warren Scott Keck-Warren 8:38
Hmm. That's, that's definitely fascinating. Like it's, because it's, so it's, so it's an, I don't know, a translation layer kind of in between the two of them.
Stanislav Khromov Stanislav Khromov 8:48
Well, at least in the terms of sending data back and forth, you, you have to have like a serial, like, because, you know, when you're inside the runtime, like when you're inside PHP, you can like have memory, uh, let's say allocations. So you can say like, oh, this points to that variable and so on. But when you cross this boundary between JavaScript and PHP or the other way around, you need to serialize it. It needs to have like a string representation, right? So because you cannot say, oh, this is a PHP object to JavaScript, it doesn't understand it. It needs to convert it to a JavaScript object in this like split where you're communicating between them. And so the majority, like 80% of the code is just like doing that in this particular library. I will mention like one of the things, so I did spend, I could do like the bare minimum to do the meme, right? But I did spend a little bit of time on it. So for example, it supports like Composer out of the box. So you can use that. You can run both like files and individual like small PHP snippets if you want. And to kind of prove it end to end, that there's also, I can send you a link to that after the podcast. There's also like an implementation of actually running WordPress on the backend on top of this Bun PHP package. So you run like all the WordPress server side with functioning MySQL and Postgres and like external communication with external servers, all that stuff, basically like feature parity with like a real PHP runtime, just to show that like, well, you can actually build like a whole application on this. Would you want to, like, I don't know, like it solved the problem for me and it wasn't like a giant package. But I also think, I hope that it might bring some people maybe to try out also Bun because Bun is quite a cool runtime. And one of the things that I like about Bun, one of the things that I don't like about JavaScript is that that ecosystem is not as mature in some ways as the PHP ecosystem. Like when you have PHP, you have Laravel and you have the PHP and it's great. Like everything, you have a way to do everything. In JavaScript, it's like, no, you need to use that package or that package. Nobody's kind of building, everybody just want to make money at the end of the day. So they're like, no, you have to use our database and our thing and our hosting. So it's very fragmented. And Bun is the first kind of runtime where I feel like they're trying to actually build like a toolbox to do something similar to what PHP and Laravel has, to make like one environment where you get a bunch of stuff out of the box to build like full-on applications without having like 50 third-party services.
Scott Keck-Warren Scott Keck-Warren 11:31
Yeah, that's really cool. We, unfortunately, like the PHP community kind of dunks on the JavaScript community for just those reasons. And it's not something that I like go along with, you know what I mean? It's like, it is unfortunately, fortunately there are people out there that are doing that, but everybody has hate against some other programming language. But it's interesting to like to see, from my perspective, it's always interesting to see like what other languages are doing. And that's like why I try to have you know, people on that are doing other languages rather than just PHP. Um, because it's, it is really fascinating, like the problems that, like, 'cause TypeScript and JavaScript as like a backend language is fairly new, right? It's not, you know, brand new, but it's also like PHP has 20-some years worth of, worth of like it being a server language essentially. So we've solved a bunch of the problems and then, and it is kind of interesting to see like JavaScript go like, oh no, we need to solve the same problems. But then there's no, like, it seems to me at least, is that everybody's trying like their own thing and there's just no standard for some, some of these things. So it is nice that somebody's, Vaadin is trying to do that.
Stanislav Khromov Stanislav Khromov 12:37
And that, I think that does come down to, to like the, the incentive structure, like, like with Laravel. I mean, uh, that, that came out of, I don't know how long, um, what was the name of, uh, the guy who wrote Laravel? I forget it.
Scott Keck-Warren Scott Keck-Warren 12:50
Taylor, Taylor, uh, I think it is.
Stanislav Khromov Stanislav Khromov 12:53
Yeah.
Scott Keck-Warren Scott Keck-Warren 12:54
Thank you.
Stanislav Khromov Stanislav Khromov 12:54
So he worked, uh, I remember because I was working a lot more with PHP like 7, 8 years ago. And so I know that he was working on Laravel for like a really long time and without really earning a lot of money on it. Like now, obviously, you know, he has the whole ecosystem, he has his own server hosting platforms, all that stuff. And he earns it, right? But I mean, like, you don't— nowadays everything is a little bit more cynical. It's like you have a product and you want people to use it and pay for it right away. There is no like, I'm gonna spend 5 years, 8 years, 10 years, like, like growing a community and trying to, to like do something that is not purely money-driven. And then later I can earn some money from it. And that's a lot of the contributing factor, I think, to the JavaScript ecosystem. So it's more maybe like the time it came at. It was a little bit later than PHP. And at that time, everybody was already like, like the VC market was already well established. So people were right away jumping to that. Whereas when like PHP and Laravel was just starting out. There was no really, there was really no path to earn a bunch of money right away. So people were more like altruistic, let's say, in their desires.
Scott Keck-Warren Scott Keck-Warren 14:08
Yeah. That's an interesting take on that. I didn't ever think about that, I guess, from my perspective. And we'll be back after this word from our partners. As a programmer, you know that code reviews are critical, but are also time-consuming. CodeRabbit acts as your AI copilot, providing instant code review comments and potential impacts of every pull request. Beyond just flagging issues, CodeRabbit provides one-click fix solutions and lets you define custom code quality rules using AST grep patterns, catching subtle issues that traditional static analysis tools might miss. CodeRabbit reviews 1 million pull requests every week across 3 million repositories and is used by 100,000 open source projects. CodeRabbit is free for all open source project repos. Get started today at phpa.me/coderabbit. That's phpa.me/coderabbit. Unfortunately, I do have to like let you go. Is there anything that you'd like to direct our listeners to before we say goodbye today?
Stanislav Khromov Stanislav Khromov 15:08
Um, yeah, I mean, if you, if you enjoyed the sort of, um, if you enjoyed this package or if you enjoyed PHP and/or Bun and I will welcome you to follow me. My website is stanislav.garden. And there you can find my social links to like Bluesky, Twitter, and stuff like that. And there you can also find more links because I do a lot of Svelte, which is like a frontend framework. And I'm actually also building my own Laravel-like framework. So, you know, Bun does a lot, but there's still a little bit more that to make that full toolkit. And that framework is called Mochi. And you can find a link on my website to that framework as well. Uh, so if you want to have more of the Laravel experience, but in the like TypeScript, uh, JavaScript world. Okay.
Scott Keck-Warren Scott Keck-Warren 15:57
And I, I will like put a link in the description for anybody who's interested in that so they don't have to try and spell that out essentially, especially since I couldn't. Um, but so thank you though. I do appreciate your time today.
Stanislav Khromov Stanislav Khromov 16:09
Yeah. Thanks for having me. Yeah.
Scott Keck-Warren Scott Keck-Warren 16:12
So that's, that's the end. And I, and I do really do appreciate like you finding some time to talk. talk us through this. It's really fascinating to me, um, like what you're doing, you know what I mean? Like it's an interesting, like, problem that you're trying to solve in, in like, and, and I think that like a lot of people would just be like, eh, I don't want to do that. And you found some cool way to make it available and make it for free, which is always a bonus. So, um, thank you. I do, I do appreciate it. And I am following, going to follow you on like all your social stuff. Yes. Um, and so I have to like finish the recording. If you just want to like hit the leave button in the bottom, um, and then I will, I will do all that so I don't have to bore you here with, with all of that nonsense.
Stanislav Khromov Stanislav Khromov 16:53
Sure.
Scott Keck-Warren Scott Keck-Warren 16:54
So thank you again.
Stanislav Khromov Stanislav Khromov 16:55
Browser running for a little bit, so it—
Scott Keck-Warren Scott Keck-Warren 16:57
Yeah, it'll say the upload is complete and then you can close it.
Stanislav Khromov Stanislav Khromov 16:59
Great. Well, thank you so much.
Scott Keck-Warren Scott Keck-Warren 17:02
Thank you.
Stanislav Khromov Stanislav Khromov 17:03
Have a good Friday.
Scott Keck-Warren Scott Keck-Warren 17:03
As, as you too. Have a good evening.
Stanislav Khromov Stanislav Khromov 17:06
All right.
Scott Keck-Warren Scott Keck-Warren 17:11
Oh, that was the other thing I forgot.
Stanislav Khromov Stanislav Khromov 17:12
Dang.
Scott Keck-Warren Scott Keck-Warren 17:14
Hello developers, and I need the pronunciation guide for this, or I'm gonna— I had to say another heartfelt thank you to Stanislav for all of his time, as well as for you for listening. If you're not already a subscriber, make sure you subscribe with whatever your preferred method is so you can get episodes as soon as they're released. And maybe share this with somebody who's using JavaScript might benefit from having PHP inside of their runtime. This podcast is available both as an audio version on the PHP Architect website, as well as a video version on our YouTube channel. This is Scott Keck Warren for the PHP Architect Community Corner signing off and reminding you to keep listening, keep coding, and keep reading.
Stanislav Khromov Stanislav Khromov 17:56
Thanks.