What we still need to verify : 1 point in this profile is not yet confirmed against vendor documentation.
- Security oriented extensions and taint analysis add-ons are third party, confirm which are maintained
Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.
What it does
PHPStan analyzes PHP without running it. It builds a model of every class, function and property in the project, infers types from signatures, docblock annotations, assignments and control flow, then reports code that cannot behave as written: calling a method that does not exist on the inferred type, passing an argument of the wrong type, reading an array key that was never set, and values that may be null where null is not handled. Because PHP is dynamically typed and forgiving at runtime, this finds a lot that would otherwise surface as a production error.
Strictness is controlled by numbered levels. Lower levels catch only unambiguous errors, and each step up enables more inference and more demanding checks, ending with strict treatment of mixed types and union narrowing. Framework specific behavior is handled through extensions, which teach the analyzer about magic methods, container resolution and dynamic return types in Symfony, Doctrine, Laravel and similar. A baseline file lets you record all existing violations and fail the build only on new ones, which is how most teams adopt it on an existing codebase.
Where it fits
It runs as a composer installed command line tool: on a developer machine before committing, in a pre-commit hook, and as a required check in continuous integration. The IDE plugin surfaces the same findings while editing. Nothing needs to be deployed and no application needs to be running. Developers operate it, not the security team, and it is usually adopted for code quality reasons, with the security benefit arriving as a side effect of eliminating classes of type confusion and null handling bugs.
Strengths
- Type inference strong enough to find real defects in untyped legacy PHP, not just style violations.
- Levels and baselines give a genuine incremental adoption path on a large existing codebase.
- A mature extension ecosystem means framework magic is understood rather than producing noise.
Limitations
- This is a correctness tool, not a security scanner. It does not ship taint analysis for injection classes, and it will not tell you about cross site scripting, SQL injection or insecure deserialization on its own.
- PHP only, so it covers one part of a typical web stack and nothing else.
- Higher levels on an old codebase generate a very large baseline, and that baseline can quietly become permanent technical debt nobody revisits.
Who it suits
Every serious PHP team should be running something in this space, and PHPStan is a reasonable default for a team that wants strong type checking with a gradual adoption path. It is the wrong tool if you need vulnerability detection: pair it with a scanner that does taint analysis rather than expecting it to cover that ground.
Used PHPStan? Recommend it under your own name and title.
Recommend this tool