Article
Replacing create_function()
Remove create_function() safely: lifecycle, modern replacements, and migration examples for legacy PHP apps.
create_function() built an anonymous function from string code at runtime. It was slow, hard to analyze statically, and a vector for injection when strings were concatenated from user input.
Lifecycle (php.net)
- Deprecated: PHP 7.2.0
- Removed: PHP 8.0.0
Modern replacement
Use real closures or first-class callables. Never eval user-controlled strings to recreate it.
Migration example
# LEGACY — create_function()
$mul = create_function('$a,$b', 'return $a * $b;');
echo $mul(3, 4);
# MODERN
$mul = static fn(int $a, int $b): int => $a * $b;
echo $mul(3, 4);
Scan before cutover
Search the tree for create_function() and paste samples into the PHP Version Compatibility Checker and PHP Deprecated Checker.
Related tools
- Composer.json Validator Validate composer.json structure and common mistakes without running composer install.
- Legacy PHP Risk Checker Paste PHP source for a static scan that classifies removed APIs, deprecated calls, and security-sensitive leg…
- PHP Deprecated Checker Find deprecated functions and patterns in pasted PHP to prioritize modernization work.
- PHP Environment Compare Compare two PHP environment summaries to find directive and extension mismatches.
- PHP Modernization Roadmap Build an ordered migration stage list from your PHP version, framework, Composer, database API, and deploymen…
- PHP Version Compatibility Checker Scan pasted PHP for version-sensitive syntax and APIs to plan upgrades across PHP releases.
Related reading
- Composer Modernization Center Add Composer to legacy PHP projects, migrate includes to autoloading, set platform constraints, and replace a…
- PHP 5 to Modern PHP: Complete Incremental Migration Guide A deep, production-minded path from PHP 5.x codebases to supported PHP 8.x: removed extensions, charset, PDO,…
- PHP Security Modernization for Legacy Applications Upgrade inherited PHP security practices: prepared statements, password hashing, sessions, CSRF, XSS escaping…
- PHP 7 to PHP 8 Migration Guide Deep guide to PHP 8.0 breaking changes that matter for PHP 7 applications, with upgrade tactics through suppo…
- Inheriting a Legacy PHP Application A first-30-days playbook for developers handed an unfamiliar PHP codebase: runtime truth, risk triage, and sa…