AppSecNews
SAST Open source Established

PHPStan

by PHPStan project (Ondrej Mirtes and contributors)

Static analyzer for PHP that infers types and reports code that cannot work, configurable through escalating strictness levels.

Visit phpstan.org (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run PHPStan in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What we still need to verify : 1 point in this profile is not yet confirmed against vendor documentation.
  • Security oriented extensions and taint analysis add-ons are third party, confirm which are maintained

Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.

What it does

PHPStan analyzes PHP without running it. It builds a model of every class, function and property in the project, infers types from signatures, docblock annotations, assignments and control flow, then reports code that cannot behave as written: calling a method that does not exist on the inferred type, passing an argument of the wrong type, reading an array key that was never set, and values that may be null where null is not handled. Because PHP is dynamically typed and forgiving at runtime, this finds a lot that would otherwise surface as a production error.

Strictness is controlled by numbered levels. Lower levels catch only unambiguous errors, and each step up enables more inference and more demanding checks, ending with strict treatment of mixed types and union narrowing. Framework specific behavior is handled through extensions, which teach the analyzer about magic methods, container resolution and dynamic return types in Symfony, Doctrine, Laravel and similar. A baseline file lets you record all existing violations and fail the build only on new ones, which is how most teams adopt it on an existing codebase.

Where it fits

It runs as a composer installed command line tool: on a developer machine before committing, in a pre-commit hook, and as a required check in continuous integration. The IDE plugin surfaces the same findings while editing. Nothing needs to be deployed and no application needs to be running. Developers operate it, not the security team, and it is usually adopted for code quality reasons, with the security benefit arriving as a side effect of eliminating classes of type confusion and null handling bugs.

Strengths

  • Type inference strong enough to find real defects in untyped legacy PHP, not just style violations.
  • Levels and baselines give a genuine incremental adoption path on a large existing codebase.
  • A mature extension ecosystem means framework magic is understood rather than producing noise.

Limitations

  • This is a correctness tool, not a security scanner. It does not ship taint analysis for injection classes, and it will not tell you about cross site scripting, SQL injection or insecure deserialization on its own.
  • PHP only, so it covers one part of a typical web stack and nothing else.
  • Higher levels on an old codebase generate a very large baseline, and that baseline can quietly become permanent technical debt nobody revisits.

Who it suits

Every serious PHP team should be running something in this space, and PHPStan is a reasonable default for a team that wants strong type checking with a gradual adoption path. It is the wrong tool if you need vulnerability detection: pair it with a scanner that does taint analysis rather than expecting it to cover that ground.

Used PHPStan? Recommend it under your own name and title.

Recommend this tool