bobthecow/psysh
64.6
Adequate · 26 September 2026
57.2k
lines of production code
PHP
primary language
4
measurements over time
What this system is
PsySH is an interactive PHP shell (REPL) that provides a robust environment for code exploration, debugging, and execution. It features a modern, context-aware tab completion engine, syntax highlighting, and autosuggestions to enhance the interactive coding experience. The system supports advanced capabilities such as hot-reloading of source code, bypassing visibility restrictions for introspection, and managing runtime configuration and documentation updates directly within the session.
How it got here
2012–2018 — Interactive shell rewrite
40 changes.
This period focused on a comprehensive architectural overhaul of the PsySH interactive shell, replacing legacy token-based parsing and command structures with a modern AST-based engine. The work introduced advanced features such as context-aware tab completion, syntax highlighting, and robust code validation, while simultaneously removing outdated core components to establish a cleaner, more maintainable codebase.
2019–2026 — Interactive readline overhaul and test expansion
38 changes.
This period focused on replacing the legacy input system with a new, modular interactive readline engine featuring fuzzy tab completion, autosuggestions, and smart editing. The work was heavily supported by extensive test coverage for the new components and significant infrastructure updates, including PHP 8.4 compatibility fixes and downstream integration smoke tests.
Features
Add --cwd and project trust configuration to PsySH CLI
The PsySH binary now supports a --cwd option to change the working directory before execution, and introduces project trust controls via --trust-project, --no-trust-project, and the PSYSH\_TRUST\_PROJECT environment variable. It also implements logic to locate and read a trusted\_projects.json configuration file from standard config directories (such as XDG\_CONFIG\_HOME or Windows APPDATA) to determine trust settings for untrusted projects.
bin · high confidence
Add manual updater and --update-manual command
Users can now update the Psy Shell manual directly from the REPL using the new --update-manual command. This feature introduces a new ManualUpdater component that checks for new manual versions via the GitHub releases API, downloads the appropriate tarball, and installs it into the configured data directory. It supports both PHP and SQLite manual formats, handles language/format mismatches, and includes caching to avoid redundant network checks.
src/ManualUpdater · high confidence
Add runtime configuration commands (config-get, config-list, config-set)
Users can now inspect and modify PsySH settings during an interactive session using the new config-get, config-list, and config-set commands. These commands expose a set of runtime-configurable options—such as verbosity, unicode support, error logging level, clipboard command, and semicolon-based return suppression—allowing users to adjust the shell's behavior on the fly without restarting. The config-set command validates input against accepted values and applies changes immediately, with some options triggering a shell refresh.
src/Command/Config · high confidence
Add self-update capability for PsySH Phar installations
Users can now update their installed PsySH Phar to the latest version directly from the command line. This change introduces a new VersionUpdater component that checks for newer releases on GitHub, downloads the updated archive, creates a backup of the current version, and replaces the existing executable. The update process includes validation of the downloaded file, error handling for network or permission issues, and automatic restoration of the backup if the installation fails.
src/VersionUpdater · high confidence
Improved tab completion via autoload warming
Tab completion now leverages an autoload warmer to proactively load classes at startup, significantly improving the availability of completions for user-defined and vendor classes. This feature introduces a new \AutoloadWarmerInterface\ and a \ComposerAutoloadWarmer\ implementation that scans the Composer classmap and PSR-4 directories to preload classes. Users can configure this behavior via \setWarmAutoload\, with options to include/exclude vendor packages, test namespaces, and specific namespaces, while automatically excluding known problematic namespaces like \Composer\\\ and Symfony Console DI components to prevent conflicts and ensure stability.
src/TabCompletion/AutoloadWarmer · high confidence
Initial project scaffolding and build configuration
This change establishes the foundational structure for the PsySH project, introducing a Makefile to automate building PHARs, running tests, and performing static analysis with PHPStan and Phan. It adds configuration files for code style (StyleCI, EditorConfig), testing (PHPUnit), and PHAR packaging (Box, PHP-Scoper), alongside standard repository files like README, LICENSE, and .gitignore to support development and distribution workflows.
(repo-wide) · high confidence
Introduce Phan static analysis with version-aware baselines and CI enforcement
This change adds the Phan static analysis tool to the project, providing a \make phan\ target for local development and a CI check that prevents new issues from being introduced. To handle the project's wide dependency version ranges (php-parser 4.0–5.x, symfony 3.4–7.x), the configuration uses a modular baseline strategy: separate files suppress false positives from minimum versions, future deprecations from latest versions, internal backward-compatibility deprecations, and issues related to optional external dependencies. These are merged into a single baseline for local runs, while a separate CI baseline enforces a 'no new issues' policy by combining the canonical baselines with a snapshot of current known issues.
.phan · high confidence
Introduce PsySH-specific VarDumper components
Adds a new VarDumper subsystem (Cloner, Dumper, DumperBase, Presenter, and PresenterAware interface) that customizes Symfony's VarDumper for PsySH. The Cloner filters verbose data and excludes verbose resource details based on a filter flag. The Dumper and DumperBase classes provide runtime-compatible shims for Symfony CliDumper methods (enterHash, dumpString, style, dumpLine, dumpKey) to handle signature changes across versions, while also supporting heredoc-style multiline strings, explicit array index display, and specific styling for integers and floats. The Presenter service ties these together, applying locale-safe numeric formatting, filtering exceptions to show only important fields, and escaping output to handle Symfony Console's backslash-escaping behavior.
src/VarDumper · high confidence
Introduce experimental interactive readline and pager
Adds a new experimental interactive readline implementation and an interactive pager to the PsySH shell. The interactive readline provides a pure-PHP input loop with features including reverse history search (Ctrl-R), filtered history navigation, autosuggestions, live syntax highlighting, and tab completion overlays. The interactive pager allows users to scroll through long output in the terminal's alternate screen buffer, supporting mouse scrolling, incremental search, and clickable PHP manual links. These components are opt-in and managed via a mode stack for extensible input handling.
src/Readline/Interactive · high confidence
Introduce new AutoCompleter for readline tab completion
Added a new AutoCompleter class in src/TabCompletion that serves as a readline tab completion service. It integrates with the CompletionEngine to handle tab completion callbacks, allowing users to register matchers and activate readline completion functionality.
src/TabCompletion · high confidence
Introduce new shell commands and refactor command infrastructure
This release adds several new commands to the Psy Shell: \buffer\ to inspect and clear the multi-line input buffer, \clear\ to reset the terminal screen, \config\ to inspect and update runtime settings (with sub-actions \list\, \get\, and \set\), \copy\ to export values to the system clipboard, and \edit\ to open an external editor for code execution. It also introduces \CodeArgumentParser\ for robust code parsing and refactors the base \Command\ class to enforce \Psy\\Shell\ application types and lazy-boot shell dependencies when context-aware commands run.
src/Command · high confidence
Introduces AST-based tab completion with new completion sources and interfaces
The shell now uses a new AST-based completion engine powered by a set of dedicated completion sources (e.g., \CatalogSource\, \MethodSource\, \VariableSource\) and a \SourceInterface\, replacing the legacy token-based matcher system. This change adds support for more accurate completions, including command argument completions via \CommandArgumentSource\ and \CommandArgumentCompletionAware\, and provides a \MatcherAdapterSource\ to maintain backward compatibility with existing custom matchers. Additionally, the \CodeCleaner\ now supports implicit \use\ statements and strict types, and the \Configuration\ class exposes new settings to control these behaviors.
src · high confidence
Introduces autosuggestion support in the interactive readline shell
The interactive shell now provides ghost-text autosuggestions as you type. Suggestions are drawn from three sources: command history (ranked by recency), context-aware completions from the existing completion engine, and function/method parameter signatures when typing a function call. A frecency index (frequency + recency) ranks history-based suggestions, while a scoring filter ensures suggestions are valid for the current PHP context. The engine caches results and prioritizes sources, with call signatures taking precedence over history and context-aware completions.
src/Readline/Interactive/Suggestion · high confidence
New build, manual-fetching, and downstream smoke-test scripts
The project adds several new scripts to the scripts/ directory to support PHAR building, documentation bundling, and integration testing. build-stub generates the PHAR stub by injecting autoload and license information into the binary. fetch-manual downloads the latest English PHP-format manual from GitHub releases for inclusion in PHAR builds. A suite of new smoke tests validates PsySH compatibility with downstream projects: test-downstream runs integration checks against Laravel Tinker, Drush, Codeception, Magerun2, CakePHP REPL, Composer REPL Lib, BDF Prime Shell, and MediaWiki; dedicated PTY smoke tests (test-downstream-laravel-tinker-smoke, test-downstream-composer-repl-lib-smoke, test-downstream-mediawiki-smoke) verify interactive REPL behavior in those environments.
scripts · high confidence
New clipboard backend architecture with OSC 52 and command-based support
The clipboard subsystem has been refactored to support multiple backend strategies via a new \ClipboardMethod\ interface. Users can now leverage OSC 52 escape sequences for terminal-native clipboard access (with automatic tmux compatibility handling) or configure external clipboard commands via the \clipboardCommand\ setting. The system includes robust fallback messaging that clearly explains why clipboard access might be unavailable (e.g., SSH sessions, missing \proc\_open\, or no configured command) and guides users on how to enable features like \useOsc52Clipboard\.
src/Clipboard · high confidence
New code validation and AST transformation passes for PsySH
The CodeCleaner now includes a suite of new validation passes that enforce PHP language rules and improve code safety in the interactive shell. Users are now prevented from re-assigning $this, using call-time pass-by-reference, or calling get\_class/get\_called\_class outside a class context. The cleaner also validates abstract and final class usage, ensures list assignments are valid, restricts isset() to variables and property fetches, and checks that break/continue statements are used within loops. Additionally, the ImplicitReturnPass automatically adds return statements to the last expression in user input, and the ImplicitUsePass can automatically add use statements for unqualified class names based on configured namespaces.
src/CodeCleaner · high confidence
New execution loop listener architecture with hot-reloading and signal handling
Psy Shell introduces a new extensible listener system for the execution loop, allowing code to hook into various stages of the REPL lifecycle (beforeRun, onInput, onExecute, afterRun). This includes a new ProcessForker that isolates user code execution in a child process to prevent fatal errors from crashing the shell, and a SignalHandler that enables graceful Ctrl-C interruption when forking is unavailable. Additionally, the system now supports hot-reloading of modified source files via two new reloaders: UopzReloader for modern PHP (using the uopz extension) and RunkitReloader for legacy PHP 7.x (using runkit/runkit7). A new 'yolo' command allows bypassing safety checks in the UopzReloader to force-reload code that was previously skipped due to structural changes. Logging capabilities are also added via ExecutionLoggingListener and InputLoggingListener.
src/ExecutionLoop · high confidence
New input handling classes for code arguments and filtering
Added four new classes in src/Input to enhance command-line input processing: CodeArgument, which allows commands to accept raw code as the final argument without complex escaping; FilterOptions, which introduces --grep, --insensitive, and --invert options for filtering command output; ShellInput, a specialized StringInput subclass that handles tokenization and parsing specifically for code arguments; and SilentInput, an internal class for representing non-user-generated code that should not be echoed or saved to history.
src/Input · high confidence
New interactive layout engine with soft-wrap and hyperlink support
This change introduces a new layout subsystem for the interactive readline interface, adding support for soft-wrapping text based on terminal width and correctly handling OSC 8 hyperlinks in rendered output. The new \DisplayString\ and \SoftWrapCalculator\ classes provide precise grapheme-aware width calculations, ANSI stripping, and row/column normalization, ensuring that long lines wrap correctly and clickable links are preserved in the interactive pager.
src/Readline/Interactive/Layout · high confidence
New interactive readline input engine with PHP-aware editing
Psy Shell introduces a new interactive readline input engine in src/Readline/Interactive/Input that replaces the legacy system with a discrete event model. This engine provides PHP-aware editing capabilities, including smart auto-indentation and dedentation based on syntax context, grapheme-cluster-aware text manipulation, and statement completeness detection via PHP-Parser integration. It features a robust history manager with filtered navigation (up/down arrows filter by text in the buffer), a comprehensive keybinding system supporting Emacs-style shortcuts and smart bracket pairing, and visual navigation policies for soft-wrapped lines. The input layer also handles mouse events (scrolling), bracketed paste, and escape sequence normalization, enabling a more responsive and context-aware interactive coding experience.
src/Readline/Interactive/Input · high confidence
New interactive readline with syntax highlighting, autosuggestions, and bracketed paste
PsySH now includes a new interactive readline implementation that provides live syntax and command highlighting, context-aware tab completion, and inline autosuggestions. This implementation also supports bracketed paste for safer pasting of multi-line code and includes an interactive documentation pager for navigating help text. The feature is opt-in and requires a TTY, falling back to the existing legacy readline for non-interactive or unsupported environments.
src/Readline · high confidence
New reflection classes for constants, language constructs, and magic members
Added new classes in the \src/Reflection\ namespace to expose reflection capabilities for PHP features previously unsupported by the standard library or PsySH's internal tools. \ReflectionConstant\ allows inspecting global and namespaced constants, including magic constants like \\_\FILE\\_\. \ReflectionLanguageConstruct\ and \ReflectionLanguageConstructParameter\ provide introspection for language constructs such as \isset\, \unset\, and \echo\. \ReflectionMagicMethod\ and \ReflectionMagicProperty\ enable uniform handling of magic methods and properties defined via docblock annotations (\@method\, \@property\) in commands like \ls\ and tab completion. Additionally, the legacy \Signature\ class was refactored and moved to \ReflectionNamespace\ to serve as a basic reflector for namespace names.
src/Reflection · high confidence
New utility classes for reflection, terminal styling, and string handling
This change introduces several new utility classes in the src/Util directory to enhance the shell's capabilities. DependencyChecker provides static methods to verify the availability and disabled status of PHP functions. Docblock gains support for detecting and caching magic methods and properties, alongside fixes for parsing single-line docblocks. Mirror is updated to use the native ReflectionClassConstant where available and adds namespace reflection support. TerminalColor enables dynamic input frame styling by querying the terminal's background color via OSC escape sequences and blending tints for both light and dark themes. Additionally, new classes Str, Json, and Tty provide string validation, standardized JSON encoding with unescaped slashes, and robust terminal width and TTY detection with graceful fallbacks.
src/Util · high confidence
SudoVisitor enables bypassing private constructors and visibility restrictions
A new SudoVisitor class has been added to the src/Sudo directory. This PHP Parser node visitor rewrites property and method access patterns to use the Psy\\Sudo visibility bypass methods, allowing users to interact with private or protected members of objects during interactive sessions.
src/Sudo · high confidence
Removals
Removal of custom exception classes and interface
The custom exception hierarchy in src/Psy/Exception has been removed. The files for BreakException, ErrorException, FatalErrorException, ParseErrorException, RuntimeException, and the Exception interface are deleted. This eliminates the custom getRawMessage() contract and the specific formatting wrappers (e.g., 'Exit:', 'PHP error:') that previously surrounded raw messages, meaning users will now see the underlying standard PHP exception messages directly without these custom prefixes.
src/Psy/Exception · high confidence
Removal of legacy PsySH command classes
The \src/Psy/Command\ directory has been cleared of its previous command implementations, including \ClearInputCommand\, \Command\, \DocCommand\, \ExitCommand\, \HelpCommand\, \HistoryCommand\, \InspectCommand\, \ListCommand\, \PsyVersionCommand\, \ReflectingCommand\, \ShowInputCommand\, and \WtfCommand\. This change removes the specific command logic and base classes that previously handled shell interactions, documentation, history, inspection, and exception tracing within this location.
src/Psy/Command · high confidence
Removal of legacy reflection and documentation utilities
The \src/Psy/Util\ directory has been completely removed, eliminating the \Inspector\, \Documentor\, \Docblock\, and \Signature\ classes. This change removes the internal utilities previously used to reflect on classes, inspect object properties and methods, and parse or format PHPDoc comments and code signatures, indicating a shift away from this specific reflection-based introspection approach in the shell.
src/Psy/Util · high confidence
Removed DocblockFormatter and ObjectFormatter classes
The \DocblockFormatter\ and \ObjectFormatter\ classes in \src/Psy/Formatter\ have been removed. This eliminates the previous logic for formatting PHPDoc blocks and object property dumps, meaning users will no longer see output generated by these specific formatters.
src/Psy/Formatter · high confidence
Removed legacy PsySH core components
The \Application\, \Autoloader\, \CodeCleaner\, \Configuration\, \Output\, \Shell\, and \ShellAware\ classes have been removed from \src/Psy\. This eliminates the previous internal implementation of the interactive shell, its configuration management, code parsing, and output formatting, indicating a significant architectural shift or migration away from this legacy codebase.
src/Psy · high confidence
Behavioural changes
Complete rewrite of tab completion matchers with context awareness and default parameter support
The tab completion system in src/TabCompletion/Matcher has been entirely rewritten to provide more accurate and context-aware suggestions. A new AbstractContextAwareMatcher base class allows matchers to access the current interactive session context, enabling VariablesMatcher to complete variables and ObjectMethodsMatcher/ObjectAttributesMatcher to complete properties and methods of objects currently in scope. New matchers have been added to support completion for magic methods and properties defined via docblock annotations (MagicMethodsMatcher, MagicPropertiesMatcher), as well as MongoDB database and collection names (MongoClientMatcher, MongoDatabaseMatcher). The system now also supports completion for default parameter values for functions, static methods, and instance methods (FunctionDefaultParametersMatcher, ClassMethodDefaultParametersMatcher, ObjectMethodDefaultParametersMatcher), helping users fill in function signatures more easily. Additionally, ClassNamesMatcher now includes interfaces and traits alongside classes, and CommandsMatcher provides completion for registered Psy Shell commands and their aliases.
src/TabCompletion/Matcher · high confidence
Improved completion for incomplete input and command arguments
The completion system now provides more responsive suggestions when typing is incomplete or syntactically invalid, recovering useful completions for object members, static members, variables, and class names even before the parser succeeds. Additionally, command argument completions are now supported, allowing the shell to delegate argument suggestions to commands that implement the \CommandArgumentCompletionAware\ interface, ensuring command-specific rules and vocabulary are followed.
src/Completion/Refiner · high confidence
Improved timeit profiling accuracy with dedicated AST visitor
The \timeit\ command now uses a new \TimeitVisitor\ class to instrument code execution, ensuring that \markEnd\ is called correctly even when code throws exceptions or contains nested function returns. This change fixes previous issues where profiling results were missing for throwing code and provides more accurate timing measurements by properly handling top-level return statements and expression boundaries.
src/Command/TimeitCommand · high confidence
Introduce cURL-based downloader with PHP 8 compatibility and fallback
The version updater now uses a new CurlDownloader implementation that leverages the cURL extension for downloading updates, including a specific check to skip curl\_close() on PHP 8.0.0+ to prevent deprecation warnings. A Factory class automatically selects this cURL-based downloader when the required functions are available, falling back to the existing FileDownloader (which uses allow\_url\_fopen) if cURL is not present, ensuring the self-update mechanism works across different server configurations.
src/VersionUpdater/Downloader · high confidence
Introduce shared buffer analysis cache for interactive code evaluation
The interactive shell now uses a new \BufferAnalyzer\ with a small LRU cache to store and reuse analysis results (tokens, AST, and error states) for code buffers. This optimization reduces redundant parsing overhead when users alternate between full-buffer and partial (before-cursor) text inputs, improving responsiveness during interactive sessions.
src/CodeAnalysis · high confidence
New tab completion engine with fuzzy matching and type awareness
The tab completion system has been replaced with a new pipeline-based engine that provides more accurate and context-aware suggestions. This new engine analyzes the PHP syntax at the cursor position to determine the completion context (e.g., variable, method, class name) and uses a fuzzy matching algorithm to rank results, similar to modern IDEs. It also resolves types from expressions to offer completions specific to the object or class being interacted with, significantly improving the relevance of suggestions.
src/Completion · high confidence
New theming system and robust output paging
The output layer now supports a configurable Theme system with built-in 'modern', 'compact', and 'classic' presets, allowing users to customize prompt strings, line numbering styles, and formatter colors (such as the new 'whisper' style for code comments). Additionally, the output pager has been refactored with a new \OutputPager\ interface and three implementations: \BuiltinOutputPager\ for interactive userland paging, \ProcOutputPager\ for external commands like \less\, and \PassthruPager\ for no-op output. This change also improves reliability by handling pager closure gracefully and prevents O(n²) performance issues when formatting large strings.
src/Output · high confidence
Refactored exception hierarchy to expose raw error messages
The exception classes in src/Exception have been restructured to implement a new Psy Exception interface that exposes a getRawMessage() method. This allows the Psy Shell to distinguish between the user-facing formatted error message and the original raw message, improving how errors are displayed and handled within the REPL environment.
src/Exception · high confidence
Refactored formatter architecture with new components and manual v3 support
The formatter subsystem has been restructured to improve code organization and expand display capabilities. The previous Formatter interface has been renamed to ReflectorFormatter, and several specialized formatters have been introduced: CodeFormatter for syntax-highlighted code blocks, DocblockFormatter for structured PHPDoc output, LinkFormatter for terminal hyperlinks (OSC 8) to php.net, and ManualFormatter for rendering structured manual v3 data with CJK-aware text wrapping. SignatureFormatter now delegates hyperlink styling to LinkFormatter and supports magic methods and properties. TraceFormatter has been simplified and now uses FilterOptions for trace line filtering. These changes enhance the visual presentation of code, documentation, and error traces in the interactive shell.
src/Formatter · high confidence
Refactored interactive readline input handling into discrete, composable actions
The interactive readline input loop has been restructured from a monolithic state machine into a modular system of discrete action classes (e.g., \AcceptSuggestionAction\, \ClearBufferAction\, \InsertOpenBracketAction\). This change introduces an \ActionInterface\ and a \FallbackAction\ chain, allowing keypresses to be handled by specific, reusable components. This architecture enables new interactive features such as smart bracket auto-closing, Allman-style indentation support, history expansion on Tab, and token-based navigation, while simplifying the core input state management.
src/Readline/Interactive/Actions · high confidence
Refactored interactive readline rendering into a widget-based system
The interactive readline renderer has been restructured to use a composable widget architecture, replacing the previous monolithic rendering logic. This change introduces a \WidgetInterface\ and specific implementations for the input frame (\InputFrameWidget\), tab completion (\CompletionMenuWidget\), history search (\HistorySearchOverlayWidget\), and an interactive pager (\PagerWidget\). The new system uses a \Frame\ object to track the visual state and a \FrameRenderer\ to diff and emit minimal terminal updates, which improves layout stability and soft-wrap handling. It also centralizes line-metrics and viewport calculations, allowing overlays like completion menus and search results to correctly respect terminal boundaries and compact mode constraints.
src/Readline/Interactive/Renderer · high confidence
Refactored list command into dedicated enumerator classes
The \ListCommand\ internals have been restructured into a set of specialized enumerator classes (ClassConstant, Class, Constant, Function, GlobalVariable, Method, Property, and Variable) that each handle the enumeration of a specific category of symbols. This change introduces support for listing class constants and magic methods/properties derived from docblock annotations, allows filtering global constants by extension category (e.g., OpenSSL, JSON), and enables filtering classes, interfaces, and traits by user/internal status and namespace prefix. The refactoring also adds a \--no-inherit\ option to exclude inherited members and improves the resilience of the function enumerator by suppressing errors during signature formatting.
src/Command/ListCommand · high confidence
Refined PHPStan static analysis configuration
The PHPStan static analysis setup in the vendor-bin directory has been restructured to improve accuracy and maintainability. A new baseline file (baseline.neon) has been introduced to explicitly ignore specific legacy issues in the Hoa library and unused constructor parameters in Readline classes, while the previous ignore.neon file has been updated to handle optional dependencies (PSR-3, Runkit, Uopz) and ensure compatibility with wider version ranges for PHP-Parser (4.x–5.x) and Symfony Console. Additionally, a dedicated bootstrap file (bootstrap.php) now ensures both the project and PHPUnit autoloaders are loaded before analysis runs.
vendor-bin · high confidence
Support for reloading PHP manual documentation without restarting the shell
The manual documentation system now supports live reloading, allowing users to update the PHP manual without restarting the Psy Shell session. This is achieved by introducing a unified ManualInterface and two loader implementations: V2Manual, which reads from SQLite databases, and V3Manual, which loads structured data from pre-built PHP files. The V3 loader includes robust validation to ensure file integrity and version compatibility, as well as a reload mechanism that clears caches and invalidates OPcache to reflect changes on disk immediately.
src/Manual · high confidence
Updated vendored Hoa console library for PHP 8.4 compatibility
The vendored Hoa console library in src/Readline/Hoa has been updated to the latest release, bringing fixes for PHP 8.4 implicit nullability deprecations and other compatibility improvements. This update ensures the interactive shell remains stable and warning-free on newer PHP versions.
src/Readline/Hoa · high confidence
Test coverage
Added test coverage for ListCommand enumerators; Added test coverage for Psy Shell exception classes; Added test coverage for PsySH command implementations; Added test coverage for Readline implementations; Added test coverage for SudoVisitor; Added test coverage for Util components; Added test coverage for core shell components and build integrity; Added test coverage for input handling components; Added test coverage for reflection classes; Added test fixtures for class inspection, tab completion, and command testing; Added test tooling for String::unvis fixture generation; Added tests for BufferAnalyzer caching and syntax helpers; Added tests for PendingInputState; Added tests for ProcessForker, SignalHandler, and UopzReloader; Added tests for TimeitVisitor code transformation; Added tests for V2 and V3 manual loaders; Added tests for VarDumper string escaping and formatting; Added tests for clipboard backend methods; Added tests for clipboard configuration behavior; Added tests for interactive readline layout string handling; Added tests for interactive readline suggestion components; Added tests for output subsystem components; Added tests for tab completion matchers; Added tests for the Composer Autoload Warmer; Added tests for the Manual Updater components; Added tests for the new CompletionEngine-based tab completion system; Added tests for the new interactive readline and pager components; Added unit tests for interactive readline actions; Added unit tests for interactive readline renderer widgets; Added unit tests for the VersionUpdater component; Added unit tests for the interactive readline input subsystem; Added unit tests for the new completion engine components; Comprehensive test coverage for Psy Shell code cleaner passes.
Dependencies
Introduce vendor-bin tooling and update core dependencies
The project now uses Composer's vendor-bin feature to isolate development tools, adding dedicated \composer.json\ files for PHPUnit (^9.6), PHPStan (^1.8), Phan (^5.4), and Box (^3.16.0). The main library dependencies have been updated to require \nikic/php-parser\ ^5.0 \|\| ^4.0 and \symfony/console\ ^8.0 \|\| ^7.0 \|\| ^6.0 \|\| ^5.0 \|\| ^4.0 \|\| ^3.4, while the minimum supported PHP version is set to 7.4.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 40 → 65 (+25.1)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 100 → 87 (-13.1)
- Architecture 94 → 96 (+1.8)
- Maturity 35 → 50 (+14.8)
- Readiness 30 → 69 (+39.2)
- Security 33 → 83 (+50.0)
Resolved (55)
- Coverage not measured — test suite did not build
- Dimension evaluation failed
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 35 more
New (262)
- AbstractConfigCommand.getOptions (cognitive 18) (src/Command/Config/AbstractConfigCommand.php)
- AbstractConfigCommand.getOptions (cyclomatic 42) (src/Command/Config/AbstractConfigCommand.php)
- BracketPair.doesClosingBracketMatch (cognitive 16) (src/Readline/Interactive/Helper/BracketPair.php)
- BufferAnalysis.hasControlStructureWithoutBody (cognitive 17) (src/CodeAnalysis/BufferAnalysis.php)
- Change coupling clique: ClassConstantEnumerator.php, MethodEnumerator.php, PropertyEnumerator.php (src/Command/ListCommand/ClassConstantEnumerator.php)
- ClassTooLong: Configuration (src/Configuration.php)
- ClassTooLong: ManualFormatter (src/Formatter/ManualFormatter.php)
- ClassTooLong: Shell (src/Shell.php)
- CodeCleaner.resolveClassName (cognitive 24) (src/CodeCleaner.php)
- CodeFormatter.findArrayKeyTokenIndexes (cognitive 30) (src/Formatter/CodeFormatter.php)
- CodeFormatter.findArrayKeyTokenIndexes (cyclomatic 18) (src/Formatter/CodeFormatter.php)
- CodeFormatter.findClassNameTokenIndexes (cognitive 45) (src/Formatter/CodeFormatter.php)
- CodeFormatter.findClassNameTokenIndexes (cyclomatic 23) (src/Formatter/CodeFormatter.php)
- CodeFormatter.splitLines (cognitive 19) (src/Formatter/CodeFormatter.php)
- Command.optionsAsText (cognitive 16) (src/Command/Command.php)
- CommandHighlighter.highlightLines (cognitive 24) (src/Readline/Interactive/Helper/CommandHighlighter.php)
- CommandHighlighter.tokenize (cognitive 25) (src/Readline/Interactive/Helper/CommandHighlighter.php)
- CompletionMenuWidget.render (cognitive 24) (src/Readline/Interactive/Renderer/CompletionMenuWidget.php)
- ComposerAutoloadWarmer.findVendorDir (cognitive 22) (src/TabCompletion/AutoloadWarmer/ComposerAutoloadWarmer.php)
- ComposerAutoloadWarmer.getAutoloadClassMap (cognitive 47) (src/TabCompletion/AutoloadWarmer/ComposerAutoloadWarmer.php)
- …and 242 more
Changes since last survey
- 78 commits — 59 feature/other, 19 fixes
By area
- (repo) — 10 commits
- src/Command — 8 commits
- src/Readline — 7 commits
- src/Shell.php — 6 commits
- .github/workflows — 4 commits
- src/ExecutionLoop — 4 commits
- test/ExecutionClosureTest.php — 4 commits
- test/ExecutionLoop — 4 commits
- src/ExecutionClosure.php — 3 commits
- (root) — 2 commits
- src/CodeCleaner — 2 commits
- src/Input — 2 commits
- src/ManualUpdater — 2 commits
- src/VersionUpdater — 2 commits
- src/functions.php — 2 commits
- test/Fixtures — 2 commits
- test/ShellTest.php — 2 commits
- test/smoketest-pty.sh — 2 commits
- build/composer.lock — 1 commit
- src/Clipboard — 1 commit
Notable commits
- fix: Adapt to Symfony Console backslash escaping fix
- fix: Fix call signature suggestions.
- fix: Fix code style
- fix: Fix context-aware suggestions.
- fix: Fix execution cleanup on error, track per execution
- fix: Fix execution cleanup without breaking existing listeners
- fix: Fix execution test import order
- fix: Fix manual test under Phar
- fix: Fix missing timeit results when code throws
- fix: Fix narrow readline rendering edge cases.
- fix: Fix self-update option help alignment.
- fix: Fix test bootrap interaction with phar
- fix: Fix unit test hang when tty is interactive
- fix: Fix zero-valued grep filters.
- fix: Merge branch 'main' into fix/signal-listener-lifecycle
- fix: Merge pull request #951 from binaryfire/fix/include-lifecycle
- fix: Merge pull request #952 from binaryfire/fix/signal-listener-lifecycle
- fix: Merge pull request #953 from binaryfire/fix/process-forker-run-lifecycle
- fix: Merge pull request #955 from o-kima/fix/generic-docblock-types
- change: Abort the pager on EOF.
- …and 58 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
bobthecow/psysh was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 29a4aa132450141630c709947baf87426d2b51d3 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-a15879f6f801.