.PHTML

PHTML File

PHP Web Page
Ask a question
QUICK ANSWER

A .phtml file is a server-side PHP script - plain text mixing HTML and PHP code. The web server runs the PHP and sends plain HTML to the browser; end users never receive the .phtml source. To read or edit one, use a text editor or PHP IDE. The most common place to encounter .phtml today is in Magento (Adobe Commerce) theme templates.

Developer: The PHP Group (PHP language); Apache Software Foundation (server association) Category: Web Files MIME: application/x-httpd-php
OPENS ON Windows macOS Linux

On this page

19k+ extensions indexed
Last reviewed Jul 30, 2026

Not sure what your file is?

Drop any file into our identifier - we read just the first bytes to name the format.

Identify a file

What is the PHTML file format?

A .phtml file is a server-side PHP script that mixes HTML markup with PHP code blocks, functionally identical to a standard .php file. The only meaningful difference is the file extension.

When a web server receives a request for a .phtml file, it passes the file through the PHP interpreter. PHP executes the embedded <?php ... ?> blocks and emits the resulting HTML to the client's browser - the browser never sees the PHP source. For this to work, the server must be explicitly configured to treat .phtml as PHP. In Apache this requires an AddHandler application/x-httpd-php .phtml directive (in .htaccess or httpd.conf); in Nginx a corresponding fastcgi_param mapping is needed. Without that configuration the server may deliver raw PHP source to visitors, an information-disclosure risk.

The .phtml extension originated in the late 1990s during the PHP 3 / early Zend Engine era, when PHP was commonly embedded directly in HTML template files. It gained lasting adoption in the Zend Framework and remains actively used in Magento (now Adobe Commerce) for its view layer template files.

From a security standpoint, .phtml is a classic file-upload bypass target: filters that block .php uploads often overlook .phtml, .php5, .php3, and similar variants, allowing arbitrary PHP execution.

Related formats include plain .php scripts and .phps files (PHP source display). There are no magic bytes and no internal versioning; the PHP runtime version is determined entirely by the server configuration.

Security & safety

RISK: HIGH

.phtml files execute arbitrary PHP code on the server - same risk as .php. Critical security issues: (1) If a file upload form on a web app allows .phtml uploads while blocking .php, an attacker can upload a PHP webshell with a .phtml extension and gain remote code execution on the server. (2) If a server inadvertently exposes .phtml source (no PHP handler configured), credentials and database connection strings in the code become public. Server admins should: explicitly list .phtml in the PHP handler config, and deny script execution in upload directories for .php, .phtml, .phar, .php3, .php4, .php5.

Format details

in a nutshell
FULL NAMEPHP Web Pageaka PHP HTML file, PHP template
DEVELOPERThe PHP Group (PHP language); Apache Software Foundation (server association)since circa 1997-1998 (early PHP 3/Zend era)
CATEGORYWeb Files
MIME TYPEapplication/x-httpd-php
TYPEserver-side PHP script (text, HTML+PHP mixed)

Programs that open PHTML files

Windows4 apps
Notepad Open-source Open .phtml file; set language to PHP for syntax highlighting (Language menu → P → PHP).
Visual Studio Code Open-source Open the .phtml file; PHP syntax is highlighted natively. Install 'PHP Intelephense' extension for full IntelliSense.
PhpStorm Paid Natively associates .phtml with PHP+HTML; full IDE support for Magento templates.
Apache + PHP (XAMPP) Open-source Place .phtml in htdocs, ensure Apache config has 'AddHandler application/x-httpd-php .phtml', then access via http://localhost/file.phtml.
macOS1 app
PhpStorm Paid Full Magento template support; file associations include .phtml out of the box.
Linux3 apps
Zend Studio Paid PHP IDE with .phtml support; open project containing .phtml templates.
Visual Studio Code Open-source Open .phtml file for editing; PHP syntax built-in.
Apache + PHP Open-source Add 'AddType application/x-httpd-php .phtml' to apache2.conf or .htaccess; then .phtml files execute as PHP.

Technical details

deep spec
Execution modelProcessed server-side by PHP interpreter; client receives only the rendered HTML output
EncodingPlain text, UTF-8 recommended; historically ASCII or Latin-1
Code delimiters<?php ... ?> (standard); <?= ... ?> (short echo); <? ... ?> (short tag, deprecated)
MIME typeapplication/x-httpd-php; also text/html and text/x-php depending on server config
Apache configurationAddHandler application/x-httpd-php .phtml in .htaccess or httpd.conf required for execution
Nginx configurationfastcgi_param or location block mapping .phtml to PHP-FPM required
Primary use caseMagento (Adobe Commerce) view layer templates; legacy Zend Framework views
Functional difference from .phpNone - processing is identical; only the file extension differs
Security riskClassic file-upload filter bypass: blocks .php but may overlook .phtml, enabling arbitrary PHP execution
File size1 KB - 500 KB typical
PHP version supportCompatible with PHP 4 through PHP 8.x; no format-level changes between versions
Associated OSLinux (Apache/Nginx), Windows (IIS/Apache), macOS
Releasedcirca 1997-1998 (early PHP 3/Zend era)
Latest versionPHP 8.x (2024); .phtml itself has no versioning
Specificationwww.php.net

PHTML conversions

Community Q&A

asked by users
Ask a quick question
Get help from people who work with PHTML files. Be specific - include your system and software version.
No account needed · answers usually within a day

No questions yet - be the first to ask about PHTML files.

Frequently asked questions

What is a .phtml file?
A server-side PHP web page - HTML mixed with PHP code, executed by the web server. End users see only the resulting HTML. Most commonly found in Magento (Adobe Commerce) theme templates.
How do I open a .phtml file?
To read/edit the source: use VS Code, Notepad++, or PhpStorm. To execute it: place it on a web server with PHP configured for .phtml and access via a browser.
Why does my browser show raw PHP code when I open a .phtml file?
Browsers cannot execute PHP. The file must be served through a PHP-enabled web server (Apache/Nginx with PHP module). Opening directly from disk shows raw source.
Is .phtml the same as .php?
Functionally yes - the file content and PHP processing are identical. The difference is only the extension. Apache/Nginx must be explicitly configured to execute .phtml as PHP.
What programs use .phtml files?
Primarily Magento (Adobe Commerce) for view templates. Historically the Zend Framework used .phtml for views. Any PHP-based application can use this extension.
Is it safe to allow .phtml file uploads?
No - allowing .phtml uploads carries the same risk as allowing .php uploads, since both execute on the server. Block .phtml in upload directories.

References

1PHP Manual - Apache configuration for PHPwww.php.net
2PortSwigger - File upload vulnerabilities (covers .phtml bypass)portswigger.net

Keep exploring

across the database

Top extensions this week

1.AQQAQQ Instant Messenger File
2.CRDOWNLOADChrome Partial Download File
3.PARTPartial Download File
4.DATProgram Data File (generic)
5.EXEWindows Executable (Portable Executable)
6.NOMEDIAAndroid No-Media Marker File
7.RPMSGRestricted Permission Message
8.TMPTemporary File
9.MDMarkdown Document
10.BINCD/DVD Disc Image (BIN/CUE)

Related extensions

.CRDOWNLOADChrome Partial Download File
.JNLPJava Network Launch Protocol file
.WEBARCHIVESafari Web Archive
.PARTPartial Download File
.DOWNLOADPartial / Incomplete Download File
.ASPXActive Server Page Extended (ASP.NET Web Form)

Free file tools

An in-browser file identifier and image converter - everything runs on your device.

Open the toolbox

Browse file extensions A-Z