All skills
wordpress avatar

/wp-phpstan

@20324d2 official
by wordpresswordpress/agent-skills2.2k stars
327

Use when configuring, running, or fixing PHPStan static analysis in WordPress projects (plugins/themes/sites): phpstan.neon setup, baselines, WordPress-specific typing, and handling third-party plugin classes.

Use this Skill: https://skilld.dev/gh/wordpress/agent-skills/wp-phpstan

This session only. Nothing lands on disk.

referenceswordpress-annotations.md

≈761 tokens on demand. Your agent reads this file only when SKILL.md points to it.

WordPress-specific type annotations

These patterns help PHPStan understand WordPress code where runtime behavior and dynamic typing make inference difficult.

REST API request typing

PHPStan cannot infer valid request parameters from REST API schemas. Provide explicit type hints for request params.

/**
 * Handle REST API request.
 *
 * @param WP_REST_Request $request Full details about the request.
 * @return WP_REST_Response|WP_Error Response object on success, error on failure.
 *
 * @phpstan-param WP_REST_Request<array{
 *     post?: int,
 *     orderby?: string,
 *     meta_key?: string,
 *     per_page?: int,
 *     status?: array<string>
 * }> $request
 */
public function get_items( $request ) {
    $post_id = $request->get_param( 'post' );
    // PHPStan now knows $post_id is int|null.
}

For complex schemas, define reusable types.

/**
 * @phpstan-type PostRequestParams array{
 *     title?: string,
 *     content?: string,
 *     status?: 'publish'|'draft'|'private',
 *     meta?: array<string, mixed>
 * }
 *
 * @phpstan-param WP_REST_Request<PostRequestParams> $request
 */

Hook callbacks

/**
 * Handle status transitions.
 *
 * @param string $new_status
 * @param string $old_status
 * @param WP_Post $post
 */
function handle_transition( string $new_status, string $old_status, WP_Post $post ): void {
    // ...
}

add_action( 'transition_post_status', 'handle_transition', 10, 3 );

Database and iterables

/**
 * @return array<WP_Post> WP_Post objects.
 */
function get_custom_posts(): array {
    $posts = get_posts( [ 'post_type' => 'custom_type', 'numberposts' => -1 ] );
    return $posts;
}

/**
 * @return array<object{id: int, name: string}> Database results.
 */
function get_user_data(): array {
    global $wpdb;

    $results = $wpdb->get_results( "SELECT id, name FROM users", OBJECT );
    return $results ?: [];
}

Hooks (apply_filters() and do_action())

Docblocks for apply_filters() and do_action() are validated. The type of the first @param is definitive.

If a third party returns the wrong type for a filter, a PHPStan error is expected and does not require defensive code.

/**
 * Allows hooking into formatting of the price.
 *
 * @param string $formatted The formatted price.
 * @param float  $price     The raw price.
 * @param string $locale    Locale to localize pricing display.
 * @param string $currency  Currency symbol.
 */
return apply_filters( 'autoscout_vehicle_price_formatted', $formatted, $price, $locale, $currency );

Action Scheduler argument shapes

/**
 * Process a scheduled email.
 *
 * @param array{user_id: int, email: string, data: array<string, mixed>} $args
 */
function process_scheduled_email( array $args ): void {
    $user_id = $args['user_id'];
    // ...
}

as_schedule_single_action(
    time() + 3600,
    'process_scheduled_email',
    [
        'user_id' => 123,
        'email' => 'user@example.com',
        'data' => [ 'key' => 'value' ],
    ]
);

Source: SKILL.md on GitHub

1 warning16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The wp-phpstan skill is well-structured and safe. It provides utility scripts and references to configure and run PHPStan static analysis within WordPress codebases using standard, trusted community stubs and tools.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    5/5 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 20324d2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 3 months ago
compatibility
Targets WordPress 7.0+ (PHP 7.4.0+). Requires Composer-based PHPStan.
  • phpstan
  • wordpress
  • php
  • static-analysis
  • composer
  • plugins
  • themes
  • type-checking
  • php-stubs

README badge

README badge for wordpress/agent-skills/wp-phpstan

Configures and fixes PHPStan static analysis in WordPress projects, handling phpstan.neon setup, baselines, WordPress-specific type annotations for hooks and REST endpoints, and third-party plugin class resolution. Targets WordPress 6.9+ with Composer-based PHPStan and integrates WordPress core stubs to resolve built-in function signatures.

Generated from the current SKILL.md.

Does this skill work with WordPress versions before 6.9?
No. The skill targets WordPress 6.9+ with PHP 7.2.24+. Older WordPress versions are not supported.
What WordPress stub package does this skill assume?
The skill expects either szepeviktor/phpstan-wordpress or php-stubs/wordpress-stubs to be installed. Without one of these, PHPStan will report errors on core WordPress functions.
Can this skill fix errors in third-party plugins and themes?
The skill can handle third-party classes via targeted ignores or plugin-specific stubs (like woocommerce-stubs or acf-pro-stubs), but only for dependencies that are actually installed or required in the project.
Does this skill generate or update baselines?
Yes, the skill can generate and update phpstan-baseline.neon files, but treats baselines as migration tools for legacy code. It will not baseline newly introduced errors.
What inputs do I need to provide before using this skill?
You should run wp-project-triage first, and confirm whether the agent is allowed to add Composer dev dependencies (stubs) and modify the baseline for the current task.

Generated from the current SKILL.md. These answers refresh after source changes.