Open-source project
bobthecow/mustache.php avatar
bobthecow/mustache.php

Mustache.php: A Logic-Less PHP Template Engine for Rendering Views

A Mustache implementation in PHP.

3,285 stars430 forksPHPMIT

At a glance

What is it?
Mustache.php is a PHP implementation of the Mustache template language, installed with Composer and rendered through a single Engine class. It fits teams that want templates without embedded PHP logic, though a few v3 configuration defaults changed what counts as a valid lambda.
Who is it for?
Adopt Mustache.php if you want templates that stay free of PHP control flow and you are running PHP 5.5 or newer. Do not adopt it if you need template inheritance, compiled templates, or a template language that can call arbitrary PHP.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 64 days ago.
What is it written in?
Mainly PHP, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The problem Mustache.php removes: PHP logic inside templates

Templates written in plain PHP let anyone with edit access put queries, conditionals and method calls into the view layer. That works until the person editing markup is not the person who owns the data access code. Mustache.php takes the opposite position. A template can interpolate a value, iterate a list, and branch on a boolean, and that is close to the whole vocabulary. Everything else has to be prepared in PHP before the render call.

The intended user is a PHP developer who already has data assembled as an object or an associative array and wants to hand it to a template without exposing the rest of the application. The README's canonical example is exactly this shape: a Chris object with public properties and one method, handed to the engine alongside a template string. The project is a rendering library, not a framework. It does not route requests, talk to a database, or manage a cache. It takes a template and a context and returns a string.

That narrow scope is the point. It also means the library will not help you if what you actually want is a full view layer with layouts, partials inheritance and compiled output. The README points elsewhere for that.

How the Engine class resolves a context and renders a template

The public surface is small. You construct a \Mustache\Engine, optionally passing a configuration array, and call render() with a template string and a context. The README shows the constructor taking entity_flags, and the same call passing an associative array in the quick example and an object in the longer one.

Context resolution is the mechanism worth understanding. When the engine walks a template and hits a tag, it looks the name up on the context. If the context is an object, the README notes that methods are usable where plain associative arrays are weaker, which is why the in-depth example defines taxed_value() as a method returning a computed number. Sections such as {{#in_ca}} branch on a truthy value and iterate when the value is a list. Higher-order sections can be backed by lambdas, and the v3 release notes describe how those return values are handled: by default the result of a lambda-rendered section is no longer double-rendered.

The repository layout backs this up: src/ holds the engine, spec/ holds the shared Mustache specification files used for conformance, and test/ holds the PHPUnit suite. The spec directory is the interesting one, because it means the project is tested against the same behavioral descriptions other Mustache implementations use, not only against its own expectations.

Installing Mustache.php and a first render

Installation is a single Composer command. The package name is mustache/mustache, and the README gives no alternative installation path, so Composer is the supported route.

bash
composer require mustache/mustache

After that, the quickest working example is the one from the README. It builds an engine with entity_flags set to ENT_QUOTES and renders a one-tag template.

php
<?php
$m = new \Mustache\Engine(['entity_flags' => ENT_QUOTES]);
echo $m->render('Hello {{planet}}', ['planet' => 'World!']); // "Hello World!"

The output is the string Hello World!. The entity_flags option is not decoration: the README states it recommends ENT_QUOTES as a default to decrease the chance of cross-site scripting, so leaving it out changes how interpolated values are escaped.

A more realistic first use is the canonical template with a section and a computed value. Define the context as a class, because the README notes associative arrays do not do functions quite as well.

php
<?php
class Chris {
    public $name  = "Chris";
    public $value = 10000;

    public function taxed_value() {
        return $this->value - ($this->value * 0.4);
    }

    public $in_ca = true;
}

Rendering that object against the template from the README produces the greeting, the prize value, and the taxed line, because in_ca is true and the section body is evaluated. Setting in_ca to false removes the taxed line entirely. That is the whole workflow: prepare data, write a template with tags, call render.

Where Mustache.php is the wrong tool

The logic-less design is a constraint you cannot opt out of. If your templates need to format dates, pluralize words, or decide which partial to include based on runtime state, that logic has to live in the context object or in a lambda. Teams that expect a template engine to carry helper functions will find themselves writing more PHP, not less.

There is also no template compilation step described in the README. The engine renders template strings. If you are serving high-volume pages and expect the template to be compiled once and cached as PHP, that is not what this library advertises, and the README does not document a compiled-template cache.

The upgrade path from v2.x carries its own traps. The v3 release dropped support for PHP 5.2 through 5.5, so an older deployment cannot move. Beyond that, three behaviors changed. The strict_callables option now defaults to true, so lambda sections should use closures or callable objects; array-style callables such as [$this, 'foo'] stop working unless you set strict_callables to false. A context shadowing bug from v2.x was fixed, and the README says you can restore the old behavior with buggy_property_shadowing if you depend on it. Higher-order section return values are no longer double-rendered by default, and the README explicitly says preserving the old behavior with double_render_lambdas is not recommended. If you extend the engine, the README warns that a few interfaces changed to keep a wide PHP version range, pointing at a specific commit rather than documenting the diffs inline.

Mustache.php against Twig's approach

The obvious alternative in PHP is Twig, and the difference is philosophical rather than cosmetic. Twig gives templates a real expression language with filters, functions, inheritance through extends and block, and a compilation step that turns templates into PHP classes. Mustache.php gives templates tags and sections and stops there. Nothing in the Mustache.php README describes inheritance or filters, and the Mustache language itself, as described in the mustache(5) man page the README links to, is built around interpolation and sections.

That makes the choice concrete. If your templates are maintained by people who should not be writing conditionals beyond a boolean check, Mustache.php enforces that boundary for you. If your templates need layout inheritance, reusable macros, or a filter pipeline, you will be rebuilding those in PHP around Mustache.php, and Twig already has them. The trade is expressiveness in the template for a smaller set of things a template can do wrong.

Maintenance, licence and the cost of staying current

The repository is not archived, and the last push was on 2026-07-28. The most recent release listed is v3.2.0 on 2026-05-10, preceded by v3.1.0 on 2026-04-30 and v3.0.0 on 2025-06-28, so the project has shipped within the last few months.

The licence is MIT, which is permissive and places few obligations on how you redistribute the library. That is a statement about the licence identifier in the repository, not legal advice; if you vendor or modify the code, read LICENSE yourself.

The upgrade cost is the real maintenance item. Moving from v2 to v3 is described as backwards compatible apart from the dropped PHP versions, but the three configuration defaults mean you should audit lambda sections and any code that relied on the old shadowing behavior. The README offers config flags to restore each old behavior, which lowers the cost of the move but also means a codebase can sit on compatibility shims indefinitely. The double_render_lambdas restoration is explicitly discouraged, so that one is worth fixing rather than flagging.

Editorial conclusion

Adopt Mustache.php if you want templates that stay free of PHP control flow and you are running PHP 5.5 or newer. Do not adopt it if you need template inheritance, compiled templates, or a template language that can call arbitrary PHP. Before upgrading from v2, verify each lambda section still passes a closure or callable object rather than an array-style callable, and confirm whether any view relies on the v2 property shadowing behavior that v3 fixed.

Frequently asked questions

What is Mustache.php?

It is a PHP implementation of the Mustache template language, distributed as the mustache/mustache package. You create a \Mustache\Engine and call render() with a template string and a context object or array.

Is it moustache or mustache in Mustache.php?

The project, its package name and its namespace all use the spelling mustache, as in mustache/mustache and \Mustache\Engine. The README never uses the moustache spelling.

Is Mustache.php open source?

Yes. The repository carries the MIT licence, and the README points to the Packagist package mustache/mustache for installation.

Does Mustache.php work with PHP 5?

Not on the v3 line. The README states that v3.x drops support for PHP 5.2 through 5.5, so an older PHP deployment cannot upgrade to v3.

How do I install Mustache.php?

Run composer require mustache/mustache. The README gives no other installation method.

Official sources

  1. bobthecow/mustache.php on GitHub
  2. License: MIT
  3. Project website
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/bobthecow-mustache-php.svg)](https://hysenlabs.com/projects/bobthecow-mustache-php)