To highlight PHP code on a server-rendered page, use PHP’s built-in highlight_string() for source held in a string or highlight_file() for a file. Both return HTML when their second argument is true. For other languages or browser-side highlighting, consider GeSHi, Highlight.js, or Prism.
Use PHP’s built-in highlighter for PHP source
The PHP Documentation Group describes highlight_string() as outputting or returning HTML markup for a syntax-highlighted version of PHP code, using colors defined in PHP’s built-in highlighter. Its first argument is the source string, which should include the opening <?php tag. Set the second argument to true to get the generated HTML as a return value instead of printing it directly. See the PHP manual for highlight_string().
<?php
$source = file_get_contents(__DIR__ . '/example.php');
echo highlight_string($source, true);
For a file, use highlight_file() with its path. Its second argument also controls whether the markup is returned rather than printed. See the PHP manual for highlight_file().
<?php
echo highlight_file(__DIR__ . '/example.php', true);
These functions are a straightforward choice when the content is PHP and you want to render it on the server without an additional highlighter package.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
Check compatibility when upgrading PHP
The PHP manual warns that the generated markup is subject to change. PHP 8.4 also changed the return type of highlight_string(). If your application depends on the returned value or on particular markup, test it against the PHP versions you deploy rather than treating the HTML structure as a stable interface.
Choose a highlighter based on where and what you render
| Need | Starting option | Why it fits |
|---|---|---|
| PHP only, rendered on the server | highlight_string() or highlight_file() |
Built into PHP; no additional package is required. |
| Several languages in a PHP-only rendering pipeline | GeSHi | PHP-based and supports choosing a language to produce highlighted output. |
| Browser highlighting, including automatic discovery | Highlight.js | Can process pre code blocks with highlightAll(); explicit language labels are more predictable for PHP. |
| Client-side highlighting with selected language grammars | Prism | Uses language classes such as language-php and lets you include the grammars you need. |
| Static HTML generation outside the browser | Prism through Node.js, or a PHP/server-side option | Prism documents Node.js use; PHP built-ins and GeSHi are other server-side approaches. |
GeSHi for a PHP-based multi-language pipeline
GeSHi (Generic Syntax Highlighter) is written in PHP. You provide source and a language choice, and it produces XHTML syntax-highlighted output. It can suit a backend that needs several languages without relying on browser JavaScript. Check the project’s maintenance status and license suitability before adopting it.
Rank #2
Highlight.js for browser or server use
Highlight.js can run in browsers and on servers. In the browser, its quick start processes code blocks with highlightAll(); its API also accepts code and a language and returns highlighted HTML. Automatic language detection is available, but an explicit PHP language class is a more predictable choice when you know the snippet’s language.
Prism for explicit language grammars
Prism is a JavaScript highlighter. Its API provides highlight() for source text and a grammar, while highlightAll() processes marked elements such as language-php. Prism also documents Node.js use for server-side or static HTML generation. Include only the language grammars you need. Its documentation says the project is working on v2 and currently accepts only security-relevant pull requests, so consider that maintenance context before selecting it.
Render code as code, not executable page markup
Use semantic <pre> and <code> elements. In raw source placed directly inside a code block, escape at least < and & as < and &. Prism explicitly warns that unescaped characters can be interpreted by the browser as tags or entities.
<pre><code class="language-php"><?php echo htmlspecialchars($name, ENT_QUOTES, 'UTF-8'); ?></code></pre>
When inserting source into HTML, escape it before placing it inside a code element unless the chosen highlighter explicitly documents that it performs the conversion. Treat the output of a highlighter as HTML, not plain text: review its output and do not send untrusted highlighted HTML through an unsafe HTML sink.
Rank #4
Restrict which files your application can display
highlight_file() reads the path you pass to it. Do not let a visitor supply an arbitrary filesystem path to display. Map requests to an allowlist of files or otherwise constrain access, and make sure the files you expose do not contain credentials or other secrets. The same review applies when loading a source string from a file before passing it to highlight_string().
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errors

