Change without breaking.
WHAT TO DO BEFORE ANY CHANGE
Version control A copy to work on A record of current behaviour
WHAT TO CHANGE FIRST
Security faults.
WHAT TO CHANGE NEXT
Anything preventing a supported PHP version.
WHAT APPROACH TO TAKE
Small changes, verified individually.
WHY
Large rewrites of code nobody understands fail.
WHAT TO ADD AS YOU GO
Tests around anything you change Documentation of what you learn
WHAT TO EXTRACT
Repeated logic, into functions or classes.
WHAT TO SEPARATE
Logic from markup, gradually.
WHAT TO INTRODUCE
Composer and autoloading A coding standard An error log rather than displayed errors
WHAT NOT TO DO
Rewrite everything at once Change formatting and behaviour in the same commit Improve code nobody executes
THAT LAST POINT
Establish what is actually used before investing effort in it.
WHAT TO VERIFY AFTER EVERY CHANGE
That the application still behaves as before.