All skills
wordpress avatar

/wp-phpstan

@20324d2 official
by wordpresswordpress/agent-skills2.2k stars
327

Use when configuring, running, or fixing PHPStan static analysis in WordPress projects (plugins/themes/sites): phpstan.neon setup, baselines, WordPress-specific typing, and handling third-party plugin classes.

Use this Skill: https://skilld.dev/gh/wordpress/agent-skills/wp-phpstan

This session only. Nothing lands on disk.

referencesconfiguration.md

≈342 tokens on demand. Your agent reads this file only when SKILL.md points to it.

PHPStan configuration (WordPress)

This reference documents a minimal, WordPress-friendly PHPStan setup and baseline workflow.

Minimal phpstan.neon template

Use the repo’s existing layout. The example below is intentionally conservative and should be adapted to the project’s actual directories.

# Include the baseline only if the file exists.
includes:
    - phpstan-baseline.neon

parameters:
    level: 5
    paths:
        - src/
        - includes/

    excludePaths:
        - vendor/
        - vendor-prefixed/
        - node_modules/
        - tests/

    ignoreErrors:
        # Add targeted exceptions only when necessary.

Guidelines:

  • Prefer analyzing first-party code only.
  • Exclude anything generated or vendored.
  • Keep ignoreErrors patterns narrow and grouped by dependency.

Baseline workflow

Baselines help you adopt PHPStan in legacy code without accepting new regressions.

# Generate a baseline (explicit filename)
vendor/bin/phpstan analyse --generate-baseline phpstan-baseline.neon

# Update an existing baseline (defaults)
vendor/bin/phpstan analyse --generate-baseline

Best practices:

  • Avoid adding new errors to the baseline; fix the new code instead.
  • Treat baseline changes like code changes: review in PRs.
  • Chip away at the baseline gradually (remove entries as you fix root causes).

Source: SKILL.md on GitHub

1 warning16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The wp-phpstan skill is well-structured and safe. It provides utility scripts and references to configure and run PHPStan static analysis within WordPress codebases using standard, trusted community stubs and tools.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    5/5 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 20324d2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 3 months ago
compatibility
Targets WordPress 7.0+ (PHP 7.4.0+). Requires Composer-based PHPStan.
  • phpstan
  • wordpress
  • php
  • static-analysis
  • composer
  • plugins
  • themes
  • type-checking
  • php-stubs

README badge

README badge for wordpress/agent-skills/wp-phpstan

Configures and fixes PHPStan static analysis in WordPress projects, handling phpstan.neon setup, baselines, WordPress-specific type annotations for hooks and REST endpoints, and third-party plugin class resolution. Targets WordPress 6.9+ with Composer-based PHPStan and integrates WordPress core stubs to resolve built-in function signatures.

Generated from the current SKILL.md.

Does this skill work with WordPress versions before 6.9?
No. The skill targets WordPress 6.9+ with PHP 7.2.24+. Older WordPress versions are not supported.
What WordPress stub package does this skill assume?
The skill expects either szepeviktor/phpstan-wordpress or php-stubs/wordpress-stubs to be installed. Without one of these, PHPStan will report errors on core WordPress functions.
Can this skill fix errors in third-party plugins and themes?
The skill can handle third-party classes via targeted ignores or plugin-specific stubs (like woocommerce-stubs or acf-pro-stubs), but only for dependencies that are actually installed or required in the project.
Does this skill generate or update baselines?
Yes, the skill can generate and update phpstan-baseline.neon files, but treats baselines as migration tools for legacy code. It will not baseline newly introduced errors.
What inputs do I need to provide before using this skill?
You should run wp-project-triage first, and confirm whether the agent is allowed to add Composer dev dependencies (stubs) and modify the baseline for the current task.

Generated from the current SKILL.md. These answers refresh after source changes.