All skills
wordpress avatar

/wp-phpstan

@20324d2 official
by wordpresswordpress/agent-skills2.2k stars
327

Use when configuring, running, or fixing PHPStan static analysis in WordPress projects (plugins/themes/sites): phpstan.neon setup, baselines, WordPress-specific typing, and handling third-party plugin classes.

Use this Skill: https://skilld.dev/gh/wordpress/agent-skills/wp-phpstan

This session only. Nothing lands on disk.

referencesthird-party-classes.md

≈726 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Third-party classes and ignore patterns

When PHPStan reports legitimate classes as missing (e.g. because WordPress or a plugin is not installed in the analysis environment), prefer fixing discovery first and only then add targeted ignores.

Before adding ignoreErrors

  • Confirm the dependency is real (installed/required in this environment).
  • Prefer stubs/extensions already used by the repo.
  • Prefer a narrow ignore for the vendor prefix over a broad ignore.

Recommended stub packages

Stubs are useful when the analysis environment does not include WordPress (or a plugin API) but you still want real type checking (instead of blanket ignores).

Common packages:

composer require --dev szepeviktor/phpstan-wordpress
composer require --dev php-stubs/wordpress-stubs
composer require --dev php-stubs/woocommerce-stubs
composer require --dev php-stubs/acf-pro-stubs

When stubs are useful (and sometimes necessary):

  • Running PHPStan in a plugin/theme repo without a full WordPress checkout.
  • PHPStan reports unknown WordPress core functions (e.g. add_action(), get_option()).
  • Integrations with optional plugins (WooCommerce, ACF Pro) that are not installed during analysis.
  • You want method/property existence checks and accurate return types instead of ignoreErrors.

Notes:

  • Prefer stubs that match the runtime versions; mismatches can cause false positives.
  • Adding Composer dependencies changes the repo; confirm it is acceptable for the task.

Ensure stubs are loaded

Installing stubs is not enough if PHPStan does not scan them. Add stub paths in phpstan.neon.

parameters:
    bootstrapFiles:
        - %rootDir%/../../php-stubs/woocommerce-stubs/woocommerce-stubs.php
    scanFiles:
        - %rootDir%/../../php-stubs/wordpress-stubs/wordpress-stubs.php
        - %rootDir%/../../php-stubs/acf-pro-stubs/acf-pro-stubs.php
        - %rootDir%/../../woocommerce/action-scheduler/functions.php

Targeted ignore patterns (examples)

parameters:
    ignoreErrors:
        # Admin Columns Pro
        - '#.*(unknown class|invalid type|call to method .* on an unknown class) AC\\ListScreen.*#'

        # Elementor
        - '#.*(unknown class|invalid type|call to method .* on an unknown class) Elementor\\.*#'

        # Yoast SEO
        - '#.*(unknown class|invalid type|call to method .* on an unknown class) WPSEO_.*#'

Pattern creation rules:

  • Cover error variations: unknown class, invalid type, call to method .* on an unknown class.
  • Keep patterns specific enough to target only intended classes.
  • Add a short comment naming the plugin/theme.
  • Group related patterns for the same dependency.

When to add exceptions:

  • Only for legitimate third-party dependencies your code integrates with.
  • Document each pattern with a comment.
  • Re-run PHPStan to ensure the ignore does not hide unrelated issues.

Source: SKILL.md on GitHub

1 warning16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The wp-phpstan skill is well-structured and safe. It provides utility scripts and references to configure and run PHPStan static analysis within WordPress codebases using standard, trusted community stubs and tools.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    5/5 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 20324d2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 3 months ago
compatibility
Targets WordPress 7.0+ (PHP 7.4.0+). Requires Composer-based PHPStan.
  • phpstan
  • wordpress
  • php
  • static-analysis
  • composer
  • plugins
  • themes
  • type-checking
  • php-stubs

README badge

README badge for wordpress/agent-skills/wp-phpstan

Configures and fixes PHPStan static analysis in WordPress projects, handling phpstan.neon setup, baselines, WordPress-specific type annotations for hooks and REST endpoints, and third-party plugin class resolution. Targets WordPress 6.9+ with Composer-based PHPStan and integrates WordPress core stubs to resolve built-in function signatures.

Generated from the current SKILL.md.

Does this skill work with WordPress versions before 6.9?
No. The skill targets WordPress 6.9+ with PHP 7.2.24+. Older WordPress versions are not supported.
What WordPress stub package does this skill assume?
The skill expects either szepeviktor/phpstan-wordpress or php-stubs/wordpress-stubs to be installed. Without one of these, PHPStan will report errors on core WordPress functions.
Can this skill fix errors in third-party plugins and themes?
The skill can handle third-party classes via targeted ignores or plugin-specific stubs (like woocommerce-stubs or acf-pro-stubs), but only for dependencies that are actually installed or required in the project.
Does this skill generate or update baselines?
Yes, the skill can generate and update phpstan-baseline.neon files, but treats baselines as migration tools for legacy code. It will not baseline newly introduced errors.
What inputs do I need to provide before using this skill?
You should run wp-project-triage first, and confirm whether the agent is allowed to add Composer dev dependencies (stubs) and modify the baseline for the current task.

Generated from the current SKILL.md. These answers refresh after source changes.