application/x-httpd-php

All MIME types
Application · Unregistered tree.php .phtml

Media type / application

application/x-httpd-php

PHP source files, which a correctly configured server executes rather than serves.

Served inline: Browsers have no renderer for this, so it downloads even without a Content-Disposition header. That makes it the quiet default for anything you do not want opened in place.

Browser behaviour

Downloads

Charset

charset required

Compression

Compress in transit

Send it like this

Content-Type: application/x-httpd-php; charset=utf-8

Send `; charset=utf-8`. Without it the receiver falls back to its own default — for some text types that default is us-ascii, and any non-ASCII character then renders wrong.

Handling verdict

InlineDownloads

Browsers have no renderer for this, so it downloads even without a Content-Disposition header. That makes it the quiet default for anything you do not want opened in place.

Charsetcharset required

Send `; charset=utf-8`. Without it the receiver falls back to its own default — for some text types that default is us-ascii, and any non-ASCII character then renders wrong.

CompressionCompress in transit

The payload is text-like or otherwise repetitive, so gzip or Brotli removes real bytes. Enable it at the server or CDN.

NameUnregistered tree

An `x-` prefix marks a type that was never registered. RFC 6838 discourages new ones, but several — like application/x-www-form-urlencoded — are now too widespread to change.

Anatomy of the name

RFC 6838

Top-level type

application

Application

Subtype

x-httpd-php

Registered in the unregistered tree.

Structured syntax

none

No suffix, so the payload format is defined entirely by the subtype itself.

Parameters

charset

Beyond the charset rule above, this type defines no parameters of its own.

What trips people up

1 note
  • If a browser downloads .php source instead of a rendered page, the interpreter is not wired up — and every secret in that file has just been published.

Response headers

Content-Type: application/x-httpd-php; charset=utf-8
X-Content-Type-Options: nosniff
Content-Disposition: attachment; filename="example.php"
Vary: Accept-Encoding

nosniff stops the browser second-guessing the type you declared, which is what makes the rest of this reliable. Content-Disposition: attachment names the saved file and removes any doubt about rendering.

Server configuration

extension mapping

nginx

types {
    application/x-httpd-php  php phtml;
}

Apache

AddType application/x-httpd-php .php .phtml
AddCharset UTF-8 .php .phtml

Caddy

@type path *.php *.phtml
header @type Content-Type "application/x-httpd-php; charset=utf-8"

Extensions and other spellings

declared

File extensions

.php.phtml

File signature

No fixed signature — this format has no reliable magic number, so identify it by parsing rather than by the first few bytes.

Related media types

8
Familyapplication
Treeunregistered
Suffix
Inlinedownload