All skills
automattic avatar

/wp-phpstan

@4904f8c official
by automatticautomattic/agent-skills211 stars
37

Use when configuring, running, or fixing PHPStan static analysis in WordPress projects (plugins/themes/sites): phpstan.neon setup, baselines, WordPress-specific typing, and handling third-party plugin classes.

Use this Skill: https://skilld.dev/gh/automattic/agent-skills/wp-phpstan

This session only. Nothing lands on disk.

referenceswordpress-annotations.md

≈761 tokens on demand. Your agent reads this file only when SKILL.md points to it.

WordPress-specific type annotations

These patterns help PHPStan understand WordPress code where runtime behavior and dynamic typing make inference difficult.

REST API request typing

PHPStan cannot infer valid request parameters from REST API schemas. Provide explicit type hints for request params.

/**
 * Handle REST API request.
 *
 * @param WP_REST_Request $request Full details about the request.
 * @return WP_REST_Response|WP_Error Response object on success, error on failure.
 *
 * @phpstan-param WP_REST_Request<array{
 *     post?: int,
 *     orderby?: string,
 *     meta_key?: string,
 *     per_page?: int,
 *     status?: array<string>
 * }> $request
 */
public function get_items( $request ) {
    $post_id = $request->get_param( 'post' );
    // PHPStan now knows $post_id is int|null.
}

For complex schemas, define reusable types.

/**
 * @phpstan-type PostRequestParams array{
 *     title?: string,
 *     content?: string,
 *     status?: 'publish'|'draft'|'private',
 *     meta?: array<string, mixed>
 * }
 *
 * @phpstan-param WP_REST_Request<PostRequestParams> $request
 */

Hook callbacks

/**
 * Handle status transitions.
 *
 * @param string $new_status
 * @param string $old_status
 * @param WP_Post $post
 */
function handle_transition( string $new_status, string $old_status, WP_Post $post ): void {
    // ...
}

add_action( 'transition_post_status', 'handle_transition', 10, 3 );

Database and iterables

/**
 * @return array<WP_Post> WP_Post objects.
 */
function get_custom_posts(): array {
    $posts = get_posts( [ 'post_type' => 'custom_type', 'numberposts' => -1 ] );
    return $posts;
}

/**
 * @return array<object{id: int, name: string}> Database results.
 */
function get_user_data(): array {
    global $wpdb;

    $results = $wpdb->get_results( "SELECT id, name FROM users", OBJECT );
    return $results ?: [];
}

Hooks (apply_filters() and do_action())

Docblocks for apply_filters() and do_action() are validated. The type of the first @param is definitive.

If a third party returns the wrong type for a filter, a PHPStan error is expected and does not require defensive code.

/**
 * Allows hooking into formatting of the price.
 *
 * @param string $formatted The formatted price.
 * @param float  $price     The raw price.
 * @param string $locale    Locale to localize pricing display.
 * @param string $currency  Currency symbol.
 */
return apply_filters( 'autoscout_vehicle_price_formatted', $formatted, $price, $locale, $currency );

Action Scheduler argument shapes

/**
 * Process a scheduled email.
 *
 * @param array{user_id: int, email: string, data: array<string, mixed>} $args
 */
function process_scheduled_email( array $args ): void {
    $user_id = $args['user_id'];
    // ...
}

as_schedule_single_action(
    time() + 3600,
    'process_scheduled_email',
    [
        'user_id' => 123,
        'email' => 'user@example.com',
        'data' => [ 'key' => 'value' ],
    ]
);

Source: SKILL.md on GitHub

1 warning17d4 checks · Risk SAFE
  • Gen Agent Trust Hub17d

    The skill provides standard guidance and a local utility script for configuring and running PHPStan static analysis in WordPress projects. It recommends using well-known community stubs and follows best practices for development tooling. No security issues were detected.

  • Socket17d

    No alerts

  • Snyk17d

    Risk: LOW · No issues

  • Runlayer7mo

    3/5 files flagged

Signed by skilld at 4904f8c. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 5 months ago.

Dormantupdated 9 months ago
compatibility
Targets WordPress 6.9+ (PHP 7.2.24+). Requires Composer-based PHPStan.
  • wordpress
  • phpstan
  • static-analysis
  • php
  • type-checking
  • composer
  • plugins
  • themes
  • php-stubs

README badge

README badge for automattic/agent-skills/wp-phpstan

Configures and runs PHPStan static analysis in WordPress projects, handling phpstan.neon setup, baselines, WordPress-specific type annotations, and third-party plugin classes. Targets WordPress 6.9+ with Composer-based PHPStan and includes helpers for REST endpoints, hook callbacks, and database query typing.

Generated from the current SKILL.md.

Does this skill work with WordPress versions before 6.9?
No. The skill targets WordPress 6.9+ with PHP 7.2.24+. Older versions may have different typing patterns and stub compatibility.
What WordPress stubs package does this skill assume?
The skill expects either szepeviktor/phpstan-wordpress or php-stubs/wordpress-stubs to be installed. Without stubs, you'll see many errors about unknown WordPress core functions.
Can this skill fix PHPStan errors in third-party plugins integrated into my codebase?
The skill handles third-party plugin/theme classes by using plugin-specific stubs (like php-stubs/woocommerce-stubs) or targeted ignore patterns, but prefers not to analyze code outside your first-party directories.
Does this skill generate or modify phpstan-baseline.neon?
Yes, the skill can generate or update baselines, but treats baselines as a migration tool for legacy code—not a way to suppress newly introduced errors. Baseline changes require user permission.
What input do I need to provide before using this skill?
You should run wp-project-triage first, and confirm whether the user allows adding Composer dev dependencies (stubs) and changing the baseline for the task.

Generated from the current SKILL.md. These answers refresh after source changes.