What is the PHTML file format?
A .phtml file is a server-side PHP script that mixes HTML markup with PHP code blocks, functionally identical to a standard .php file. The only meaningful difference is the file extension.
When a web server receives a request for a .phtml file, it passes the file through the PHP interpreter. PHP executes the embedded <?php ... ?> blocks and emits the resulting HTML to the client's browser - the browser never sees the PHP source. For this to work, the server must be explicitly configured to treat .phtml as PHP. In Apache this requires an AddHandler application/x-httpd-php .phtml directive (in .htaccess or httpd.conf); in Nginx a corresponding fastcgi_param mapping is needed. Without that configuration the server may deliver raw PHP source to visitors, an information-disclosure risk.
The .phtml extension originated in the late 1990s during the PHP 3 / early Zend Engine era, when PHP was commonly embedded directly in HTML template files. It gained lasting adoption in the Zend Framework and remains actively used in Magento (now Adobe Commerce) for its view layer template files.
From a security standpoint, .phtml is a classic file-upload bypass target: filters that block .php uploads often overlook .phtml, .php5, .php3, and similar variants, allowing arbitrary PHP execution.
Related formats include plain .php scripts and .phps files (PHP source display). There are no magic bytes and no internal versioning; the PHP runtime version is determined entirely by the server configuration.
Security & safety
RISK: HIGH.phtml files execute arbitrary PHP code on the server - same risk as .php. Critical security issues: (1) If a file upload form on a web app allows .phtml uploads while blocking .php, an attacker can upload a PHP webshell with a .phtml extension and gain remote code execution on the server. (2) If a server inadvertently exposes .phtml source (no PHP handler configured), credentials and database connection strings in the code become public. Server admins should: explicitly list .phtml in the PHP handler config, and deny script execution in upload directories for .php, .phtml, .phar, .php3, .php4, .php5.
Format details
in a nutshellPrograms that open PHTML files
Technical details
deep spec| Execution model | Processed server-side by PHP interpreter; client receives only the rendered HTML output |
| Encoding | Plain text, UTF-8 recommended; historically ASCII or Latin-1 |
| Code delimiters | <?php ... ?> (standard); <?= ... ?> (short echo); <? ... ?> (short tag, deprecated) |
| MIME type | application/x-httpd-php; also text/html and text/x-php depending on server config |
| Apache configuration | AddHandler application/x-httpd-php .phtml in .htaccess or httpd.conf required for execution |
| Nginx configuration | fastcgi_param or location block mapping .phtml to PHP-FPM required |
| Primary use case | Magento (Adobe Commerce) view layer templates; legacy Zend Framework views |
| Functional difference from .php | None - processing is identical; only the file extension differs |
| Security risk | Classic file-upload filter bypass: blocks .php but may overlook .phtml, enabling arbitrary PHP execution |
| File size | 1 KB - 500 KB typical |
| PHP version support | Compatible with PHP 4 through PHP 8.x; no format-level changes between versions |
| Associated OS | Linux (Apache/Nginx), Windows (IIS/Apache), macOS |
| Released | circa 1997-1998 (early PHP 3/Zend era) |
| Latest version | PHP 8.x (2024); .phtml itself has no versioning |
| Specification | www.php.net |
PHTML conversions
Community Q&A
asked by usersNo questions yet - be the first to ask about PHTML files.