Analyze, secure and upgrade grown PHP applications to current PHP and Symfony, then keep developing them – AI-assisted, secured with tests.
Modernize Legacy PHP Software
Many companies have a PHP application that has been running reliably for years – and precisely for that reason nobody wants to touch it anymore. Old PHP version, no framework or a long-discontinued one, no tests, knowledge only in the head of the original developer. That works until a server update, a security vulnerability or a new requirement comes along.
I bring such applications into the present in a controlled way – without a big-bang rewrite, in stages that do not interrupt operations.
How I proceed
- Inventory: codebase, dependencies, database, deployment, integrations. Where are the risks, where is business logic nobody documented?
- Security and stability review: outdated libraries, SQL injection and XSS risks, error handling, logging, performance traps. You get a prioritized list, not just a warning.
- Securing with tests: before I change code, I capture the existing behaviour in tests – this is the step that makes modernization safe in the first place.
- Upgrade in stages: raise the PHP version, update dependencies, introduce or migrate a framework (usually Symfony), untangle the structure step by step. Each stage goes live before the next one starts.
- Further development: once the foundation is stable, we get to the features that have been waiting for years.
AI-assisted – with experience as the control
For analysis, test generation, mechanical migrations and documentation I use AI-assisted development tools. That speeds up exactly the work that used to mean weeks of grind: capturing existing behaviour in tests, replacing outdated syntax and APIs, explaining undocumented code.
The decisions stay with me: what is real business logic and what is historical accident? Which structure will carry the next years? Where is a risk for live operations? Tools deliver speed, experience delivers judgement – together they make modernization fast and reliable.
Typical starting points
- Store connections, inventory systems or portals from the PHP 5.x or 7.x years that no longer run on current servers
- In-house developments without a framework, with grown includes and global configuration
- Applications on discontinued frameworks (Zend Framework 1, old Symfony versions, CakePHP 2 and the like)
- Systems whose original developer is no longer available
Typical tasks
Upgrade PHP 5.6, 7.x or 8.0 to current PHP
Your host is retiring the old version, the application stops running or throws warnings. I lift the codebase to current PHP in a controlled way – with tests that first capture what the application is supposed to do.
Developer no longer available, agency gone
You have a running application but nobody left who knows it. I take over the codebase, do an inventory and carry it on – see also the fixed-price legacy assessment.
Framework migration
Zend Framework 1, Symfony 2 to 4, CakePHP 2, Laravel 5, Yii 1, Slim 2 or in-house code without a framework: step-by-step migration to current Symfony without interrupting operations.
Keeping Shopware 5 custom code running
Plugins and customizations still needed before the migration – or that have to be rebuilt in Shopware 6 afterwards. I know both sides.
Fixing security findings
You have a penetration test report or a warning from your host on the table. I work through the findings, prioritized by risk, and document the fixes.
Application getting slow
Missing database indexes, N+1 queries, no caching, blocking third-party calls: I measure instead of guessing and fix the bottlenecks with the biggest effect.
Cleaning up dependencies
Discontinued libraries, Composer conflicts, outdated extensions: update, replace or remove – secured with tests.
Modern deployment pipeline
From FTP upload to reproducible deployments with Git, Docker and CI – including a staging environment so changes are checked before go-live.
Catching up on documentation
Capturing from code, database and conversations with users what the application really does – so knowledge no longer depends on one person.
GDPR adjustments in existing software
Deletion concept, data export, logging, access restrictions – built in cleanly after the fact.
How I work
Three principles that apply in every project
Understand before building
First the short technical assessment: what is the actual problem, where is the lever, what makes economic sense? Then the implementation.
Build instead of forwarding
You talk to the developer who does the work – no handover chain, no black box, clear status updates and early warning about risks.
Hand over instead of holding on
Code in your repository, tests, documentation and a deployment process your team understands. No vendor lock-in – your system does not depend on me afterwards.
Background
Experience at a glance
- Today
- Senior freelancer in ongoing Shopware projects of several agencies and merchants – at home in foreign repos, processes and deadlines.
- Since 2021
- Self-employed as Stefan Pilz Ltd. – remote for merchants and agencies: Shopware 5 and 6, Symfony, migrations, maintenance.
- 2015 – 2020
- E-commerce backends: inventory, PIM and Amazon/eBay integrations for around 3.5 million products, then the Drillisch mobile-carrier web stores.
- Since 2012
- Full-time web developer – first at an agency: websites and stores with Joomla, xt-Commerce and Shopware.
- 2002
- Completed vocational training as a software developer (C/C++). First own PHP websites from 2004.
See current and completed projects Career and stack in the CV
Good fit
Works well when...
- you have a concrete business requirement that standard software does not cover cleanly.
- you need an experienced PHP/Symfony developer who implements directly instead of forwarding tickets.
- you run existing systems, stores or integrations that have to work together.