My temporary PHP fix from 2014 has nearly 20M installs. Today I'm deprecating it
- ID
- 25604
- Status
- summarized
- Published
- 16 Sep 2026, 4:53 AM
- Fetched
- 18 Sep 2026, 1:55 AM
- Provider
- Hacker News
- Category
- dev-community
- Original URL
- https://jakeasmith.com/blog/http-build-url/
- Source URL
- https://hnrss.org/best
Summary
- Score
- 4.5
- Created
- 18 Sep 2026, 1:57 AM
- Tags
- Audience
- developersdatabase_learners
What happened
A 174-line PHP polyfill written in 2014 to replace pecl_http's http_build_url() during an AOL CMS upgrade has accumulated nearly 20M Packagist installs and is bundled inside WPML (1.5M+ WordPress sites), SPIP, Debian, and Ubuntu. The author is now deprecating it, noting a known bug where trailing-slash URL joining strips every letter 'a' from the path due to a crude find-and-replace workaround.
Why it matters
If you maintain PHP projects that depend on 'http_build_url' polyfills—directly or transitively via WPML, idna-convert, or SPIP—check your dependency tree now, as this package is deprecated and carries a path-corruption bug that could silently mangle URLs containing the letter 'a'. For everyone else, it's a cautionary tale: 'temporary' shims in package registries can outlive you by a decade.
Discussion angle
The 'temporary' code that becomes permanent infrastructure—how do you decide when a shim is safe to publish vs. when it creates a long-tail maintenance burden for the ecosystem?