All skills
asyrafhussin avatar

/php-best-practices

@e7ea05d

PHP 8.x modern patterns, PSR standards, and SOLID principles. Use when reviewing PHP code, checking type safety, auditing code quality, or ensuring PHP best practices. Triggers on "review PHP", "check PHP code", "audit PHP", or "PHP best practices".

Use this Skill: https://skilld.dev/gh/asyrafhussin/agent-skills/php-best-practices

This session only. Nothing lands on disk.

rulesmodern-readonly-classes.md

≈851 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Readonly Classes

Use readonly classes when all properties should be immutable (PHP 8.2+).

Bad Example

<?php

declare(strict_types=1);

// Marking each property as readonly individually
class EmailAddress
{
    public function __construct(
        public readonly string $local,
        public readonly string $domain,
    ) {}
}

// Easy to forget readonly on new properties
class PersonName
{
    public function __construct(
        public readonly string $firstName,
        public readonly string $lastName,
        public string $middleName = '', // Oops! Forgot readonly
    ) {}
}

// Verbose for classes with many properties
class ShippingAddress
{
    public function __construct(
        public readonly string $street,
        public readonly string $city,
        public readonly string $state,
        public readonly string $zipCode,
        public readonly string $country,
    ) {}
}

Good Example

<?php

declare(strict_types=1);

// Readonly class - all properties are automatically readonly
readonly class EmailAddress
{
    public function __construct(
        public string $local,
        public string $domain,
    ) {
        if (!filter_var("$local@$domain", FILTER_VALIDATE_EMAIL)) {
            throw new InvalidArgumentException('Invalid email address');
        }
    }

    public function toString(): string
    {
        return "{$this->local}@{$this->domain}";
    }

    public function equals(self $other): bool
    {
        return $this->local === $other->local
            && $this->domain === $other->domain;
    }
}

readonly class PersonName
{
    public function __construct(
        public string $firstName,
        public string $lastName,
        public string $middleName = '',
    ) {}

    public function getFullName(): string
    {
        return trim("{$this->firstName} {$this->middleName} {$this->lastName}");
    }
}

readonly class ShippingAddress
{
    public function __construct(
        public string $street,
        public string $city,
        public string $state,
        public string $zipCode,
        public string $country,
    ) {}

    public function format(): string
    {
        return implode("\n", [
            $this->street,
            "{$this->city}, {$this->state} {$this->zipCode}",
            $this->country,
        ]);
    }
}

// DTOs are perfect candidates for readonly classes
readonly class CreateUserRequest
{
    public function __construct(
        public string $email,
        public string $password,
        public string $name,
        public ?string $phone = null,
    ) {}
}

// Event objects should be immutable
readonly class UserCreatedEvent
{
    public function __construct(
        public int $userId,
        public string $email,
        public DateTimeImmutable $occurredAt,
    ) {}
}

Why

  • Less Verbose: No need to repeat readonly on each property
  • Enforced Immutability: New properties are automatically readonly
  • Value Objects: Ideal for implementing value object pattern
  • DTOs: Perfect for data transfer objects
  • Events: Event objects should be immutable by design
  • Clear Intent: Class declaration signals complete immutability

Source: SKILL.md on GitHub

No alerts17d5 checks · Risk SAFE
  • Gen Agent Trust Hub17d

    This skill is a comprehensive and safe resource for PHP 8.x best practices. It provides structured guidance on type safety, modern PHP syntax, PSR standards, and secure coding practices (such as prepared statements and password hashing). The agent is instructed to use standard environment detection commands (php -v, grep) to tailor its advice. No malicious patterns or security risks were identified.

  • Socket17d

    No alerts

  • Snyk17d

    Risk: LOW · No issues

  • Runlayer6mo

    39 files scanned · No issues

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at e7ea05d. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub last month.

Steadyupdated 7 months ago
Other metadata
metadata
{
  "author": "php-community",
  "version": "2.1.0",
  "phpVersion": "8.0 - 8.5"
}

README badge

README badge for asyrafhussin/agent-skills/php-best-practices