What we still need to verify : 2 points in this profile are not yet confirmed against vendor documentation.
- Maintenance cadence: the project's activity level has varied since its original maintainer stepped back, confirm current status
- Integration list: confirm which editor and CI integrations are actively maintained
Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.
What it does
Psalm reads PHP source and builds a type model of the whole project, inferring types from signatures, docblocks, assignments and control flow, then reporting code that contradicts that model. It supports a richer annotation vocabulary than PHP's own type system: array shapes, literal string and integer types, class-string, template annotations for generics, and assertions that let you teach it what a custom validation function guarantees. Strictness is graded across error levels so an existing codebase can be adopted incrementally, and a baseline file can freeze existing violations while failing the build on new ones.
What sets it apart from a pure type checker is taint analysis, enabled explicitly rather than by default. In that mode Psalm treats data arriving from request superglobals and similar entry points as tainted, propagates the taint through assignments and function calls using the type graph it has already built, and reports when tainted data reaches a sink such as a database query, a shell execution, an include, or unescaped output. Annotations let you declare your own sources, sinks and sanitizers so the analysis understands your framework's escaping helpers instead of flagging every template write.
Where it fits
It is a composer installed command line tool run by developers locally and as a required continuous integration check. The taint pass is usually a separate, slower job than the type checking pass because it needs a full project graph. A language server lets editors show findings inline. For the taint results to be useful someone has to invest in annotating the codebase's own sanitizers, which means a security engineer and a developer working together for the first pass rather than turning a flag on and reading the output.
Strengths
- Taint analysis in an open source PHP tool, which is uncommon and reaches injection classes type checkers cannot.
- Expressive annotation system including generics and array shapes, allowing precise types where PHP itself has none.
- Baselines and error levels give a workable path onto a legacy codebase.
Limitations
- Taint mode is materially slower than plain analysis and needs custom sanitizer annotations before the false positive rate becomes tolerable.
- PHP only. It says nothing about the JavaScript, infrastructure or dependencies around your application.
- Project activity has been uneven, so verify maintenance status and the currency of PHP version support before making it a build gate.
Who it suits
A strong choice for a PHP team that wants type safety and is prepared to invest in annotations to get security findings from the same tool. If you want vulnerability detection with no configuration effort, or you need coverage beyond PHP, look at a dedicated scanner instead.
Used Psalm? Recommend it under your own name and title.
Recommend this tool