PHP source protection
Ship PHP code without shipping your source.
Compile PHP into encrypted bytecode, lock each build to a domain, server IP and expiry date, and check licenses against your own license server.
Before you buy:setup guide and requirements

Once PHP source is on a customer's server it can be copied, modified and redeployed on other domains. Obfuscators only rename variables; the logic stays readable.
PHP source is compiled into Darwvin bytecode and encrypted, so protected files contain no readable PHP. A loader extension runs the code on the target server.
Each build can be bound to a domain, a server IP address and an expiry date. Moved or expired code refuses to run.
Payload keys are wrapped per customer and builds carry a signed manifest, so one customer's build can't be used to unlock another's.
Protected code can check its license token against a license server — ours or one you run — so you can revoke access remotely.
Encode whole project directories in one run, keeping the folder structure intact.
A desktop app for batch jobs and saved profiles. It also minifies and obfuscates JavaScript and CSS assets that ship alongside your PHP.
Sell per-domain licenses and stop one purchase from running on every site.
Install on a client's server with an expiry date until the final invoice is paid.
Offer a self-hosted version of your SaaS without handing over the codebase.
The setup guide lists every requirement and shows the exact configuration, so you can check compatibility before you buy.
Encoding as a managed service by Darwvin, or a self-hosted setup for teams whose source must not leave their own infrastructure. We agree the model with each customer.
Onboarding, help integrating license checks, and loader builds for your target PHP versions.
See how licensing and buying work, the software license and the refund policy.
No. PHP is compiled to bytecode and encrypted; the original source is not in the protected files. No protection is absolute, but this raises the cost of copying far beyond renaming variables.
Yes — the Darwvin loader extension for their PHP version on a Linux server.
Browsers must be able to read JavaScript and CSS, so they can't be encrypted. The desktop app minifies and obfuscates them to make copying harder.
No. Darwvin Encoder targets PHP 8.0 and newer.
Something not answered here? Ask us directly.
Need changes or a custom integration? Start a project
A sales CRM your team will actually keep up to date.
A cloud call center for sales and support teams.
A unified remote-operations workspace — not just another terminal.
Asterisk calling inside Perfex CRM.