On shared hosting, your server neighbor hits a WooCommerce spike — and your blog slows because mod_php multiplies Apache processes bloated with PHP memory. On a well-administered VPS, each site has its FPM pool under distinct Unix user: one client's leak or saturation does not crush others.
mod_php embeds PHP in Apache process. PHP-FPM runs PHP in separate workers, Apache or Nginx passing requests via FastCGI. For multiple sites, question is not religious: what memory and security isolation between tenants?
mod_php vs PHP-FPM
| Aspect | mod_php | PHP-FPM |
|---|---|---|
| Process model | Apache + PHP coupled | Independent PHP pools |
| Memory under load | Explodes (workers × PHP) | pm.max_children per pool |
| Multi-site isolation | Weak | Strong (user + pool) |
| Web server | Apache mostly | Nginx or Apache |
| Tuning | Limited | pm, slowlog, status page |
| Shared hosting legacy | Historical | VPS/dedicated standard |
Hosting ten WordPress sites in mod_php on one VPS stacks ten memory bombs with one detonator.
mod_php: when still visible
Legacy shared hosting. No choice — host manages.
Single monolithic app, low traffic. Acceptable with OPcache and large RAM margin.
Rare plugin constraint requiring mod_php — increasingly exceptional.
Migration recommended once root access and second site.
PHP-FPM: multi-site best practices
One Unix user per client (site_a, site_b). One pool per site in /etc/php/8.x/fpm/pool.d/. pm.on-demand or dynamic by traffic; avoid oversized static. open_basedir limited to docroot. Slowlog enabled. Unix socket or localhost TCP — never FPM exposed on Internet.
Typical stack: Nginx → Unix socket FPM → PHP 8.x plus OPcache plus Redis WordPress object cache. Apache equivalent: disable mod_php, enable proxy_fcgi to pools.
Performance and security
OPcache mandatory both modes. Homogeneous PHP version per pool. PHP CVE: OS patch; FPM allows reload without killing entire Apache or Nginx. Site A compromise in shared mod_php → site B files readable; separate FPM user limits blast radius.
The summit: isolation is not optional multi-tenant
Decide and move forward without blind spots
Single site on personal VPS: PHP-FPM by habit plus tuning margin. Multi-client agency: mandatory pool plus user, annual slowlog audit. Shared hosting: migrate sensitive clients to FPM VPS or managed offer. Measure RAM per pool via pm.status_path before next peak period. See Apache or Nginx WordPress and VPS directory.
Frequently asked questions
Is mod_php obsolete?
Discouraged multi-site and under load. PHP-FPM recommended with Nginx and Apache event MPM for years.
Does a single site need PHP-FPM?
Not strictly; better memory control on modern VPS. OPcache plus separate pools remain sensible default.
How do you isolate two clients?
Dedicated FPM pool plus Unix user plus open_basedir plus separate vhost — never shared mod_php.
PHP-FPM with Apache?
Yes via proxy_fcgi — Apache serves HTTP, FPM runs PHP without embedded mod_php.
How many PHP sites run on your server? If answer is greater than one and you are still on mod_php, FPM migration is not luxury — it is neighborhood insurance.
