My temporary PHP fix from 2014 has nearly 20M installs. Today I'm deprecating it
A 174-line PHP stopgap written in 2014 to support a CMS migration has grown into a widely embedded dependency with nearly 20 million Packagist installs, illustrating how “temporary” code can become critical infrastructure and create long-lived operational risk. The maintainer is deprecating it because modern, standards-compliant alternatives now exist in the ecosystem and in PHP itself, and because leaving an old, widely used package in place can create security and support exposure that downstream teams may not be prepared to manage. For IT organizations, the key implication is that legacy shims and libraries must be treated as strategic assets with lifecycle governance, not one-off fixes, because they can persist across products, vendors, and even operating systems.
