Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To highlight PHP code on a server-rendered page, use PHP’s built-in highlight_string() for source held in a string or highlight_file() for a file. Both return HTML when their second argument is true. For other languages or browser-side highlighting, consider GeSHi, Highlight.js, or Prism.

Use PHP’s built-in highlighter for PHP source

The PHP Documentation Group describes highlight_string() as outputting or returning HTML markup for a syntax-highlighted version of PHP code, using colors defined in PHP’s built-in highlighter. Its first argument is the source string, which should include the opening <?php tag. Set the second argument to true to get the generated HTML as a return value instead of printing it directly. See the PHP manual for highlight_string().

<?php
$source = file_get_contents(__DIR__ . '/example.php');
echo highlight_string($source, true);

For a file, use highlight_file() with its path. Its second argument also controls whether the markup is returned rather than printed. See the PHP manual for highlight_file().

<?php
echo highlight_file(__DIR__ . '/example.php', true);

These functions are a straightforward choice when the content is PHP and you want to render it on the server without an additional highlighter package.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Check compatibility when upgrading PHP

The PHP manual warns that the generated markup is subject to change. PHP 8.4 also changed the return type of highlight_string(). If your application depends on the returned value or on particular markup, test it against the PHP versions you deploy rather than treating the HTML structure as a stable interface.

Choose a highlighter based on where and what you render

Need Starting option Why it fits
PHP only, rendered on the server highlight_string() or highlight_file() Built into PHP; no additional package is required.
Several languages in a PHP-only rendering pipeline GeSHi PHP-based and supports choosing a language to produce highlighted output.
Browser highlighting, including automatic discovery Highlight.js Can process pre code blocks with highlightAll(); explicit language labels are more predictable for PHP.
Client-side highlighting with selected language grammars Prism Uses language classes such as language-php and lets you include the grammars you need.
Static HTML generation outside the browser Prism through Node.js, or a PHP/server-side option Prism documents Node.js use; PHP built-ins and GeSHi are other server-side approaches.

GeSHi for a PHP-based multi-language pipeline

GeSHi (Generic Syntax Highlighter) is written in PHP. You provide source and a language choice, and it produces XHTML syntax-highlighted output. It can suit a backend that needs several languages without relying on browser JavaScript. Check the project’s maintenance status and license suitability before adopting it.

Highlight.js for browser or server use

Highlight.js can run in browsers and on servers. In the browser, its quick start processes code blocks with highlightAll(); its API also accepts code and a language and returns highlighted HTML. Automatic language detection is available, but an explicit PHP language class is a more predictable choice when you know the snippet’s language.

Prism for explicit language grammars

Prism is a JavaScript highlighter. Its API provides highlight() for source text and a grammar, while highlightAll() processes marked elements such as language-php. Prism also documents Node.js use for server-side or static HTML generation. Include only the language grammars you need. Its documentation says the project is working on v2 and currently accepts only security-relevant pull requests, so consider that maintenance context before selecting it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Render code as code, not executable page markup

Use semantic <pre> and <code> elements. In raw source placed directly inside a code block, escape at least < and & as &lt; and &amp;. Prism explicitly warns that unescaped characters can be interpreted by the browser as tags or entities.

<pre><code class="language-php">&lt;?php echo htmlspecialchars($name, ENT_QUOTES, 'UTF-8'); ?&gt;</code></pre>

When inserting source into HTML, escape it before placing it inside a code element unless the chosen highlighter explicitly documents that it performs the conversion. Treat the output of a highlighter as HTML, not plain text: review its output and do not send untrusted highlighted HTML through an unsafe HTML sink.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Restrict which files your application can display

highlight_file() reads the path you pass to it. Do not let a visitor supply an arbitrary filesystem path to display. Map requests to an allowlist of files or otherwise constrain access, and make sure the files you expose do not contain credentials or other secrets. The same review applies when loading a source string from a file before passing it to highlight_string().

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.