All skills
automattic avatar

/wp-phpstan

@4904f8c official
by automatticautomattic/agent-skills211 stars
37

Use when configuring, running, or fixing PHPStan static analysis in WordPress projects (plugins/themes/sites): phpstan.neon setup, baselines, WordPress-specific typing, and handling third-party plugin classes.

Use this Skill: https://skilld.dev/gh/automattic/agent-skills/wp-phpstan

This session only. Nothing lands on disk.

referencesthird-party-classes.md

≈726 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Third-party classes and ignore patterns

When PHPStan reports legitimate classes as missing (e.g. because WordPress or a plugin is not installed in the analysis environment), prefer fixing discovery first and only then add targeted ignores.

Before adding ignoreErrors

  • Confirm the dependency is real (installed/required in this environment).
  • Prefer stubs/extensions already used by the repo.
  • Prefer a narrow ignore for the vendor prefix over a broad ignore.

Recommended stub packages

Stubs are useful when the analysis environment does not include WordPress (or a plugin API) but you still want real type checking (instead of blanket ignores).

Common packages:

composer require --dev szepeviktor/phpstan-wordpress
composer require --dev php-stubs/wordpress-stubs
composer require --dev php-stubs/woocommerce-stubs
composer require --dev php-stubs/acf-pro-stubs

When stubs are useful (and sometimes necessary):

  • Running PHPStan in a plugin/theme repo without a full WordPress checkout.
  • PHPStan reports unknown WordPress core functions (e.g. add_action(), get_option()).
  • Integrations with optional plugins (WooCommerce, ACF Pro) that are not installed during analysis.
  • You want method/property existence checks and accurate return types instead of ignoreErrors.

Notes:

  • Prefer stubs that match the runtime versions; mismatches can cause false positives.
  • Adding Composer dependencies changes the repo; confirm it is acceptable for the task.

Ensure stubs are loaded

Installing stubs is not enough if PHPStan does not scan them. Add stub paths in phpstan.neon.

parameters:
    bootstrapFiles:
        - %rootDir%/../../php-stubs/woocommerce-stubs/woocommerce-stubs.php
    scanFiles:
        - %rootDir%/../../php-stubs/wordpress-stubs/wordpress-stubs.php
        - %rootDir%/../../php-stubs/acf-pro-stubs/acf-pro-stubs.php
        - %rootDir%/../../woocommerce/action-scheduler/functions.php

Targeted ignore patterns (examples)

parameters:
    ignoreErrors:
        # Admin Columns Pro
        - '#.*(unknown class|invalid type|call to method .* on an unknown class) AC\\ListScreen.*#'

        # Elementor
        - '#.*(unknown class|invalid type|call to method .* on an unknown class) Elementor\\.*#'

        # Yoast SEO
        - '#.*(unknown class|invalid type|call to method .* on an unknown class) WPSEO_.*#'

Pattern creation rules:

  • Cover error variations: unknown class, invalid type, call to method .* on an unknown class.
  • Keep patterns specific enough to target only intended classes.
  • Add a short comment naming the plugin/theme.
  • Group related patterns for the same dependency.

When to add exceptions:

  • Only for legitimate third-party dependencies your code integrates with.
  • Document each pattern with a comment.
  • Re-run PHPStan to ensure the ignore does not hide unrelated issues.

Source: SKILL.md on GitHub

1 warning17d4 checks · Risk SAFE
  • Gen Agent Trust Hub17d

    The skill provides standard guidance and a local utility script for configuring and running PHPStan static analysis in WordPress projects. It recommends using well-known community stubs and follows best practices for development tooling. No security issues were detected.

  • Socket17d

    No alerts

  • Snyk17d

    Risk: LOW · No issues

  • Runlayer7mo

    3/5 files flagged

Signed by skilld at 4904f8c. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 5 months ago.

Dormantupdated 9 months ago
compatibility
Targets WordPress 6.9+ (PHP 7.2.24+). Requires Composer-based PHPStan.
  • wordpress
  • phpstan
  • static-analysis
  • php
  • type-checking
  • composer
  • plugins
  • themes
  • php-stubs

README badge

README badge for automattic/agent-skills/wp-phpstan

Configures and runs PHPStan static analysis in WordPress projects, handling phpstan.neon setup, baselines, WordPress-specific type annotations, and third-party plugin classes. Targets WordPress 6.9+ with Composer-based PHPStan and includes helpers for REST endpoints, hook callbacks, and database query typing.

Generated from the current SKILL.md.

Does this skill work with WordPress versions before 6.9?
No. The skill targets WordPress 6.9+ with PHP 7.2.24+. Older versions may have different typing patterns and stub compatibility.
What WordPress stubs package does this skill assume?
The skill expects either szepeviktor/phpstan-wordpress or php-stubs/wordpress-stubs to be installed. Without stubs, you'll see many errors about unknown WordPress core functions.
Can this skill fix PHPStan errors in third-party plugins integrated into my codebase?
The skill handles third-party plugin/theme classes by using plugin-specific stubs (like php-stubs/woocommerce-stubs) or targeted ignore patterns, but prefers not to analyze code outside your first-party directories.
Does this skill generate or modify phpstan-baseline.neon?
Yes, the skill can generate or update baselines, but treats baselines as a migration tool for legacy code—not a way to suppress newly introduced errors. Baseline changes require user permission.
What input do I need to provide before using this skill?
You should run wp-project-triage first, and confirm whether the user allows adding Composer dev dependencies (stubs) and changing the baseline for the task.

Generated from the current SKILL.md. These answers refresh after source changes.