squizlabs/PHP_CodeSniffer
59.5
Adequate · 26 September 2026
55.6k
lines of production code
PHP
primary language
4
measurements over time
What this system is
This release delivers a comprehensive overhaul of PHP\_CodeSniffer’s internal architecture, introducing dedicated tokenizers for CSS, JavaScript, and PHP, alongside a robust caching system and improved exit code handling. A significant portion of the update focuses on modernizing coding standards, with extensive new sniffs for PSR-12, PEAR, Squiz, and Generic standards, including support for PHP 8.1/8.2 features like enums and attributes. The release also expands cross-language analysis capabilities with new Git-aware filters, external tool integrations, and enhanced Windows batch file support.
Features
Add JSLint and JavaScript Lint debug sniffs
The Squiz standard now includes two new debug sniffs, JSLintSniff and JavaScriptLintSniff, which integrate external JavaScript linting tools (jslint.js and JavaScript Lint) into PHP\_CodeSniffer. These sniffs execute the respective external tools on JavaScript files and report any warnings or errors found, allowing developers to catch JavaScript issues alongside PHP code.
src/Standards/Squiz/Sniffs/Debug · high confidence
Add UnnecessaryStringConcatSniff to detect redundant string concatenation
A new sniff, UnnecessaryStringConcatSniff, has been added to the Generic standard. It identifies cases where two strings are concatenated together when a single string would suffice, suggesting a cleaner alternative. The sniff supports both PHP and JavaScript tokenizers and includes options to control whether errors or warnings are raised, and whether multiline concatenation is allowed.
src/Standards/Generic/Sniffs/Strings · high confidence
Add documentation generators for HTML, Markdown, and Text output formats
The PHP\_CodeSniffer tool now includes built-in generators to produce documentation for coding standards in HTML, Markdown, and plain text formats. This allows users to generate human-readable reference material for sniffs, with the text generator specifically handling line wrapping to ensure proper formatting in terminal outputs.
src/Generators · high confidence
Added FileExtensionSniff to enforce .php/.inc file naming conventions
A new sniff, FileExtensionSniff, has been introduced to the Squiz standard. It enforces that files containing classes, interfaces, traits, or enums use the .php extension, while non-class files should use .inc. The sniff registers for the opening PHP tag, scans for class-like tokens (including enums), and reports errors if the file extension does not match the content type.
src/Standards/Squiz/Sniffs/Files · high confidence
Added PEAR package.xml validation script
A new \ValidatePEARPackageXML\ script has been added to the \scripts/ValidatePEAR\ directory. This tool validates the PHP\_CodeSniffer \package.xml\ file by checking that all files in the \src\ and \tests\ directories are correctly listed in the \\<contents\>\ tag, ensuring no files are missing from the package definition.
scripts/ValidatePEAR · high confidence
Added Zend Code Analyzer integration for PHP\_CodeSniffer
A new \CodeAnalyzerSniff\ has been introduced in the Zend standard to integrate with the external Zend Code Analyzer tool. When the analyzer executable is found on the system, the sniff executes it against each PHP file, parsing the tool's output to report warnings for any issues identified by the external static analysis tool.
src/Standards/Zend/Sniffs/Debug · high confidence
Added and fixed CSS coding standard sniffs
The Squiz CSS coding standard now includes a comprehensive set of new sniffs to enforce CSS formatting and style rules. These include checks for class definition spacing, colon spacing, color definitions, duplicate styles, empty definitions, forbidden styles, indentation, lowercase styles, missing colons, named colors, opacity values, and semicolon spacing. Several sniffs have been updated to fix 'Undefined index' errors and improve fixer behavior, ensuring that automated code corrections work correctly for CSS files.
src/Standards/Squiz/Sniffs/CSS · high confidence
Added new tokenizers for CSS, JavaScript, and PHP code
The codebase now includes dedicated tokenizers for CSS, JavaScript, and PHP, each extending a shared abstract Tokenizer base class. The CSS tokenizer handles CSS-specific syntax by wrapping content in PHP tags and converting specific tokens. The JavaScript tokenizer defines scope openers and closers for JS constructs like if, for, and switch. The PHP tokenizer provides the primary implementation for parsing PHP code, including support for modern PHP features like enums and match expressions. These components work together to provide comprehensive syntax analysis across multiple languages.
src/Tokenizers · high confidence
Enforce PSR-12 rules for trait import statements
The PSR-12 standard now includes a new UseDeclarationSniff that validates trait import statements. This enforces that all trait imports are grouped together, each import is on its own line, and the first import appears immediately after the opening brace (ignoring comments). The sniff also provides automatic fixes for spacing and grouping violations.
src/Standards/PSR12/Sniffs/Traits · high confidence
Enforce PSR-12 spacing rules for return and nullable type declarations
Added new PSR-12 sniffs for return type and nullable type declarations. The ReturnTypeDeclarationSniff ensures there is exactly one space between the colon and the return type, and no space before the colon. The NullableTypeDeclarationSniff ensures there is no space between the question mark and the type in nullable type declarations. Both sniffs provide automatic fixes for spacing issues.
src/Standards/PSR12/Sniffs/Functions · high confidence
Enforce PSR-2 control structure spacing and formatting rules
The PSR-2 standard now includes new sniffs to enforce consistent formatting for control structures. \ControlStructureSpacingSniff\ ensures correct spacing around parentheses in control structures, while \ElseIfDeclarationSniff\ enforces the use of \elseif\ over \else if\. \SwitchDeclarationSniff\ validates switch statement formatting, including case indentation, lowercase keywords, and proper termination of case blocks. These changes improve code style consistency for PHP developers using the PSR-2 standard.
src/Standards/PSR2/Sniffs/ControlStructures · high confidence
Enforce PSR-2 file formatting rules for closing tags and trailing newlines
Added ClosingTagSniff and EndFileNewlineSniff to the PSR-2 standard. The new ClosingTagSniff detects and removes trailing PHP closing tags, while the EndFileNewlineSniff ensures files end with exactly one newline and no excessive blank lines. Both sniffs include automatic fixers to correct violations.
src/Standards/PSR2/Sniffs/Files · high confidence
Enforce blank line after namespace declaration and validate USE statement placement
Added new PSR2 sniffs for namespace and USE declarations. The NamespaceDeclarationSniff ensures there is exactly one blank line after a namespace declaration, while the UseDeclarationSniff enforces that USE statements appear after the namespace declaration and that each USE keyword is followed by a single space. These changes introduce new linting rules and auto-fixes for namespace formatting and USE statement placement.
src/Standards/PSR2/Sniffs/Namespaces · high confidence
Enforce camelCase method naming in PSR1 standard
The PSR1 standard now includes a new \CamelCapsMethodNameSniff\ that validates method names against camelCase formatting. This check applies to all methods within classes, excluding magic methods and closures, and reports errors for any method names that do not conform to the camelCase convention.
src/Standards/PSR1/Sniffs/Methods · high confidence
Enforce short-form type keywords and limit compound namespace depth in PSR-12
The PSR-12 standard now includes two new sniffs. The ShortFormTypeKeywordsSniff requires the use of short-form type keywords (e.g., int, bool) and provides an automatic fix to replace long-form casts. The CompoundNamespaceDepthSniff enforces a maximum depth for compound namespaces, defaulting to a depth of 2, and reports an error if the depth is exceeded.
src/Standards/PSR12/Sniffs/Keywords · high confidence
Enforce spacing around operators in PSR-12
The PSR-12 standard now includes a new \OperatorSpacingSniff\ that verifies operators have at least one space of whitespace before and after them. This enforces consistent spacing around comparison, assignment, boolean, and other operators, with automatic fixing available for missing spaces.
src/Standards/PSR12/Sniffs/Operators · high confidence
Enforce visibility on class constants
A new PSR12 standard rule, ConstantVisibility, has been added to require explicit visibility declarations on all class constants. This change ensures that every class constant includes a visibility modifier (such as public, protected, or private), addressing a gap in the previous behavior where non-class constants might have triggered false positives.
src/Standards/PSR12/Sniffs/Properties · high confidence
Introduce Squiz array formatting rules
Added new Squiz standard sniffs for array formatting: ArrayBracketSpacing enforces spacing around square brackets, and ArrayDeclaration enforces style, indentation, and fixer rules for array declarations. This brings the Squiz standard's array handling in line with the rest of the codebase by using the new namespace-based structure.
src/Standards/Squiz/Sniffs/Arrays · high confidence
Introduce Zend/ValidVariableName sniff for PHP variable naming conventions
The PHP\_CodeSniffer tool now includes a new \ValidVariableNameSniff\ within the Zend coding standard. This addition enforces camelCase naming for all variables, member variables, and variables embedded in strings, while also applying specific rules for public versus private/protected member variables regarding leading underscores. Users will now receive errors or warnings when variable names violate these camelCase or underscore conventions.
src/Standards/Zend/Sniffs/NamingConventions · high confidence
New CyclomaticComplexity and NestingLevel sniffs in the Generic standard
The Generic standard now includes two new metric sniffs: CyclomaticComplexitySniff and NestingLevelSniff. The complexity sniff counts decision points (including ternary, null coalescence, and null-safe operators) to warn or error when a function's cyclomatic complexity exceeds configurable thresholds. The nesting level sniff calculates the deepest nesting depth within functions, warning or erroring when the nesting level exceeds configurable limits. Both sniffs allow users to configure the warning and error thresholds via the standard's configuration.
src/Standards/Generic/Sniffs/Metrics · high confidence
New Git merge conflict and Subversion property sniffs
Added new sniffs for the Generic standard: GitMergeConflictSniff detects Git merge conflict markers (e.g., \<\<\<\<\<\<\<, =======, \>\>\>\>\>\>\>) in PHP, JavaScript, and CSS files, while SubversionPropertiesSniff validates Subversion properties (svn:keywords, svn:eol-style) on files under version control.
src/Standards/Generic/Sniffs/VersionControl · high confidence
New Git-aware file filters for targeted linting
Added new \GitModified\ and \GitStaged\ filters that allow PHP\_CodeSniffer to lint only files that have been modified or staged in a Git repository. This enables developers to run linting on a subset of files, such as during pre-commit hooks or CI checks, rather than scanning the entire codebase. The implementation includes a base \ExactMatch\ filter class and specific subclasses that query Git to determine which files to include.
src/Filters · high confidence
New MySource code standards and sniffs for PHP, CSS, and JavaScript
The MySource standard now includes a comprehensive set of new sniffs that enforce coding practices across PHP, CSS, and JavaScript. For PHP, the standard checks that superglobals are accessed via a helper method, that eval() is not used to instantiate objects, that Ajax requests are not compared to NULL, and that function results are not returned directly. For JavaScript, it ensures that console is not used for variable or function names, that 'this' is only assigned to 'self', that widgets are not manually created, and that widget type callbacks are properly structured. For CSS, it prevents the use of browser-specific styles. Additionally, the standard enforces that systems are included before use and that included systems are actually used.
src/Standards/MySource/Sniffs · high confidence
New PEAR coding standard sniffs for control structures and formatting
The PEAR standard now includes new sniffs to enforce coding style rules. ControlSignatureSniff verifies that control statements (including the new match expression) follow the standard pattern. MultiLineConditionSniff ensures multi-line IF conditions are correctly indented and formatted. MultiLineAssignmentSniff enforces that multi-line assignments have the equal sign on the second line and are properly indented.
src/Standards/PEAR/Sniffs/ControlStructures · high confidence
New PEAR whitespace sniffs for object operators, scope closing braces, and scope indentation
The PEAR standard now includes three new whitespace sniffs: ObjectOperatorIndentSniff, which checks that chained object operators are indented correctly (including support for PHP 8.0's nullsafe operator); ScopeClosingBraceSniff, which ensures closing braces are aligned and on their own lines; and ScopeIndentSniff, which enforces correct indentation for control structures. These changes improve code formatting consistency for PHP developers using the PEAR standard.
src/Standards/PEAR/Sniffs/WhiteSpace · high confidence
New PHP 8.1 enum support and duplicate class name detection
The Generic coding standard now includes new sniffs for detecting duplicate class, interface, and trait names across files, and enforces opening brace placement for classes, interfaces, traits, and PHP 8.1 enums. Users will see warnings for duplicate type names and fixable errors for brace placement and spacing, with the new DuplicateClassNameSniff tracking namespaces to identify conflicts.
src/Standards/Generic/Sniffs/Classes · high confidence
New PHP code sniffs for syntax, types, and constants
The Generic standard introduces several new sniffs to enforce PHP coding standards: SyntaxSniff validates PHP syntax; BacktickOperatorSniff forbids the backtick execution operator; CharacterBeforePHPOpeningTagSniff ensures the opening PHP tag is the first content; ClosingPHPTagSniff checks for paired PHP tags; DisallowAlternativePHPTagsSniff and DisallowShortOpenTagSniff enforce standard PHP tags; DiscourageGotoSniff warns against using goto; DeprecatedFunctionsSniff flags deprecated functions; DisallowRequestSuperglobalSniff discourages $\_REQUEST; ForbiddenFunctionsSniff blocks specified functions; LowerCaseConstantSniff and UpperCaseConstantSniff enforce case for TRUE, FALSE, NULL; LowerCaseKeywordSniff enforces lowercase keywords; LowerCaseTypeSniff enforces lowercase type declarations; NoSilencedErrorsSniff warns about error suppression; RequireStrictTypesSniff mandates strict\_types declaration; SAPIUsageSniff prefers PHP\_SAPI constant; and the existing ForbiddenFunctionsSniff is extended to support nullsafe operators and class names in attributes.
src/Standards/Generic/Sniffs/PHP · high confidence
New PSR-12 class formatting and instantiation checks
The PSR-12 standard now includes four new sniffs to enforce class formatting and instantiation rules: \AnonClassDeclarationSniff\ validates anonymous class formatting; \ClassInstantiationSniff\ ensures classes are instantiated with parentheses; \ClosingBraceSniff\ prevents comments or statements on the same line as closing braces; and \OpeningBraceSpaceSniff\ prohibits blank lines after opening braces. These changes improve code consistency and catch style violations in class declarations and instantiations.
src/Standards/PSR12/Sniffs/Classes · high confidence
New PSR12 sniffs for control structure spacing and boolean operator placement
Two new sniffs have been added to the PSR12 standard: \ControlStructureSpacing\ enforces correct spacing and indentation inside multi-line control structure parentheses, while \BooleanOperatorPlacement\ ensures boolean operators between conditions are consistently placed at the beginning or end of the line. The \BooleanOperatorPlacement\ sniff also supports an \allowOnly\ configuration option to restrict operators to either the first or last position, and both sniffs handle PHP 8 \match\ expressions.
src/Standards/PSR12/Sniffs/ControlStructures · high confidence
New PSR12 sniffs for file headers, import statements, declare statements, and open tags
The PSR12 standard now includes new sniffs to enforce formatting rules for PHP files. FileHeaderSniff ensures the file header is the first content in the file, allowing for hashbang lines. ImportStatementSniff enforces that import statements do not begin with a leading backslash and provides auto-fixing. DeclareStatementSniff checks the formatting of declare statements, including spacing and case. OpenTagSniff ensures the opening PHP tag is on a line by itself for PHP-only files.
src/Standards/PSR12/Sniffs/Files · high confidence
New PSR2 method and function call signature checks
Three new sniffs have been added to the PSR2 standard to enforce stricter formatting for method declarations, function call signatures, and function closing braces. The MethodDeclarationSniff now validates the order of method modifiers (static, abstract, final, visibility) and warns against underscore-prefixed method names. The FunctionCallSignatureSniff introduces checks for multi-line function calls, while the FunctionClosingBraceSniff ensures closing braces are placed correctly after function bodies. These changes improve code consistency and provide automatic fixes for common formatting errors.
src/Standards/PSR2/Sniffs/Methods · high confidence
New Squiz PHP sniffs for code style and safety
Added new Squiz standard sniffs to enforce coding conventions and improve code quality: CommentedOutCode (warns about commented-out code), DisallowBooleanStatement (prevents boolean operators outside control structures), DisallowComparisonAssignment (prevents assigning comparison results to variables), DisallowInlineIf (bans inline IF statements), DisallowMultipleAssignments (enforces single assignments per line), DisallowSizeFunctionsInLoops (bans size functions in loop conditions), DiscouragedFunctions (flags debug functions like print\_r), EmbeddedPhp (enforces indentation of embedded PHP), Eval (discourages eval), GlobalKeyword (forbids the global keyword), Heredoc (bans heredoc/nowdoc syntax), InnerFunctions (forbids nested functions), LowercasePHPFunctions (enforces lowercase for built-in functions), and NonExecutableCode (warns about unreachable code).
src/Standards/Squiz/Sniffs/PHP · high confidence
New Squiz code standards for object syntax and instantiation
Three new PHP\_CodeSniffer sniffs have been added to the Squiz standard to enforce stricter object usage. ObjectMemberCommaSniff now flags trailing commas in object literals, ObjectInstantiationSniff requires that new objects be assigned to variables (with updated logic to handle PHP 8.0+ match expressions), and DisallowObjectStringIndexSniff enforces dot notation for object indexing in JavaScript. These changes improve code consistency and catch potential errors in object handling.
src/Standards/Squiz/Sniffs/Objects · high confidence
New Squiz string-related code sniffs
Added three new PHP\_CodeSniffer sniffs for the Squiz standard: ConcatenationSpacingSniff enforces spacing around the string concatenation operator; DoubleQuoteUsageSniff flags unnecessary double-quoted strings and disallows variables within them; EchoedStringsSniff prevents wrapping echoed strings in parentheses. These changes improve static analysis of string formatting and style.
src/Standards/Squiz/Sniffs/Strings · high confidence
New Zend standard rule to remove trailing PHP closing tags
A new sniff, ClosingTagSniff, has been added to the Zend standard to enforce that PHP files do not end with a closing tag. The rule detects a closing tag at the end of a file and, if fixable, removes it. The fixer logic also ensures a semicolon is added before the closing tag if the preceding token is not already a semicolon, closing tag, or curly bracket.
src/Standards/Zend/Sniffs/Files · high confidence
New and improved function declaration sniffs in the Squiz standard
The Squiz standard now includes dedicated sniffs for function declarations, including spacing, duplicate arguments, global function warnings, lowercase keywords, and multi-line formatting. These changes enforce consistent function declaration styles, such as requiring lowercase for keywords like \function\, \closure\, and \fn\, and ensure proper spacing around parentheses, reference operators, and variadic operators. Users will see new linting rules and auto-fixes for function-related code style issues.
src/Standards/Squiz/Sniffs/Functions · high confidence
New and updated Squiz class-related sniffs
The Squiz standard now includes new sniffs for class declarations, file naming, duplicate properties, lowercase keywords, self references, and valid class names. ClassDeclarationSniff enforces single-class-per-file and brace spacing; ClassFileNameSniff validates names for classes, interfaces, traits, and enums; DuplicatePropertySniff detects duplicate JS object properties; LowercaseClassKeywordsSniff enforces lowercase for class keywords including readonly; SelfMemberReferenceSniff ensures correct self:: usage and spacing; ValidClassNameSniff enforces PascalCase for class, interface, trait, and enum names.
src/Standards/Squiz/Sniffs/Classes · high confidence
New and updated Squiz control structure sniffs
The Squiz standard now includes new sniffs for control structures: ControlSignature enforces spacing after keywords and closing parentheses, and allows configuring spaces before the colon in alternative syntax; ForLoopDeclaration and ForEachLoopDeclaration enforce spacing around brackets and the 'as' keyword; InlineIfDeclaration checks spacing for shorthand IF statements; LowercaseDeclaration ensures control keywords are lowercase; and SwitchDeclaration enforces indentation and spacing for case/default statements. These changes provide automated enforcement of consistent control structure formatting.
src/Standards/Squiz/Sniffs/ControlStructures · high confidence
New and updated formatting sniffs for PHP CodeSniffer
The Generic standard now includes new sniffs to enforce spacing around cast operators and the NOT operator, alongside updates to existing alignment checks. A new \SpaceBeforeCast\ sniff ensures a single space precedes cast tokens, while \SpaceAfterCast\ and \SpaceAfterNot\ enforce configurable spacing after cast and NOT operators respectively. The \NoSpaceAfterCast\ sniff is now deprecated in favor of the new \SpaceAfterCast\ with a spacing of 0. Additionally, \MultipleStatementAlignment\ and \DisallowMultipleStatements\ have been updated to handle edge cases involving closures, anonymous classes, and FOR loops, preventing false positives and fatal errors in these scenarios.
src/Standards/Generic/Sniffs/Formatting, src/Standards/Generic/Sniffs/WhiteSpace · high confidence
New and updated report generators for PHP\_CodeSniffer
The \src/Reports\ directory now includes implementations for CBF, Checkstyle, Code, CSV, Diff, Emacs, Full, Gitblame, Hgblame, Info, JSON, JUnit, and Notifysend reports. These changes introduce or update the output formats available to users, enabling integration with various CI/CD pipelines (Jenkins, JUnit), IDEs (Emacs), and other tools (Checkstyle, CSV, JSON). The CBF report specifically handles the auto-fixing features of the PHPCBF script, while other reports like Full and Code provide detailed error and warning information in different formats.
src/Reports · high confidence
New array syntax and indentation rules for PHP CodeSniffer
Added three new sniffs to the Generic standard: ArrayIndentSniff enforces consistent indentation for multi-line arrays, DisallowLongArraySyntaxSniff bans the long array syntax (array()) in favor of short syntax (\[\]), and DisallowShortArraySyntaxSniff bans the short array syntax in favor of the long syntax (array()). These changes allow users to enforce specific array formatting and syntax preferences in their codebases.
src/Standards/Generic/Sniffs/Arrays · high confidence
New build and validation scripts for PHAR packaging and PEAR package verification
Added scripts/build-phar.php to automate the creation of the phpcs and phpcbf PHAR files, implementing a custom whitespace and comment stripping function for cross-version PHP compatibility. Also added scripts/validate-pear-package.php to validate the PEAR package.xml file, ensuring the package meets required standards before release.
scripts · high confidence
New code analysis sniffs for PHP\_CodeSniffer Generic standard
The Generic standard introduces several new code analysis sniffs to detect common code smells and potential issues. These include \AssignmentInCondition\ to flag variable assignments in conditions, \EmptyPHPStatement\ to detect empty PHP statements and superfluous semicolons, \EmptyStatement\ to find empty control structure bodies, \ForLoopShouldBeWhileLoop\ to suggest simplifying for-loops, \ForLoopWithTestFunctionCall\ to warn about function calls in loop tests, \JumbledIncrementer\ to detect confusing loop incrementers, \UnconditionalIfStatement\ to flag always-true/false conditions, \UnnecessaryFinalModifier\ to remove redundant final modifiers, and \UselessOverridingMethod\ to identify methods that merely call the parent. These additions help developers identify and clean up problematic or redundant code patterns.
src/Standards/Generic/Sniffs/CodeAnalysis · high confidence
New comment-related sniffs for TODO, FIXME, and DocComment
The Generic standard now includes new sniffs for detecting TODO and FIXME comments, as well as enforcing basic formatting for doc blocks. The \TodoSniff\ and \FixmeSniff\ classes have been added to warn about these specific comment types, while \DocCommentSniff\ enforces structure and capitalization rules for PHPDoc blocks. These changes improve code quality checks by identifying pending tasks and ensuring consistent documentation formatting.
src/Standards/Generic/Sniffs/Commenting · high confidence
New debug sniffs for external linting tools
Added four new debug sniffs that integrate external JavaScript and CSS linting tools into the code analysis workflow. The new \CSSLintSniff\ runs \csslint\ on CSS files, while \ClosureLinterSniff\, \ESLintSniff\, and \JSHintSniff\ execute \gjslint\, \eslint\, and \jshint\ respectively on JavaScript files. Each sniff parses the output of the respective tool and reports warnings or errors on the corresponding lines in the source file.
src/Standards/Generic/Sniffs/Debug · high confidence
New file-level code quality checks and stricter line-length rules
The Generic standard now includes several new sniffs to enforce file structure and formatting: ByteOrderMarkSniff detects BOM headers, EndFileNewlineSniff and EndFileNoNewlineSniff enforce trailing newlines, LineEndingsSniff validates EOL characters, ExecutableFileSniff prevents PHP files from being executable, InlineHTMLSniff ensures files contain only PHP code, and LowercasedFilenameSniff enforces lowercase filenames. Additionally, the LineLengthSniff now supports an ignoreComments property to exclude comment-only lines from length checks, and OneObjectStructurePerFileSniff enforces a single class, interface, trait, or enum per file.
src/Standards/Generic/Sniffs/Files · high confidence
New function-related code sniffs for PHP\_CodeSniffer
The Generic standard now includes three new sniffs to enforce coding style for function calls and braces: CallTimePassByReferenceSniff prohibits passing variables by reference in function calls; FunctionCallArgumentSpacingSniff enforces consistent spacing around commas in function arguments; and OpeningFunctionBraceBsdAllmanSniff and OpeningFunctionBraceKernighanRitchieSniff enforce whether the opening brace for functions and closures should be on the same line or the next line, with automatic fixing capabilities.
src/Standards/Generic/Sniffs/Functions · high confidence
New operator usage sniffs for PHP and JavaScript
Added three new sniffs in the Squiz standard to enforce better operator usage: ComparisonOperatorUsage enforces identical comparison operators (===) over equal (==); IncrementDecrementUsage encourages using ++/-- over += 1 or -= 1; and ValidLogicalOperators prohibits the use of 'and'/'or' in favor of &&/\|\|. These changes provide automated code style enforcement for common operator anti-patterns.
src/Standards/Squiz/Sniffs/Operators · high confidence
New scope validation sniffs for methods, member variables, and static $this usage
The Squiz standard introduces three new sniffs to enforce stricter scope and usage rules: MethodScopeSniff now requires explicit visibility modifiers on all class methods; MemberVarScopeSniff requires explicit scope modifiers on class member variables; and StaticThisUsageSniff detects the use of $this within static methods, which causes runtime errors. These changes add new linting errors for previously unvalidated code patterns.
src/Standards/Squiz/Sniffs/Scope · high confidence
New sniffs for Yoda conditions and inline control structures
Added new PHP\_CodeSniffer sniffs to enforce coding standards: DisallowYodaConditionsSniff flags Yoda-style conditions (e.g., \if (null === $var)\), and InlineControlStructureSniff detects and auto-fixes inline control structures (e.g., \if ($x) echo $y;\) by adding braces. These changes help standardize code style by preventing unsafe comparisons and encouraging explicit block syntax.
src/Standards/Generic/Sniffs/ControlStructures · high confidence
New utility classes for caching, token definitions, and standards management
The src/Util directory now includes new utility classes: Cache.php for managing run caching with improved file hashing and configuration tracking; Common.php with helper functions like isReadable and realpath; Standards.php for discovering and listing installed coding standards; Timing.php for run time and memory reporting; and Tokens.php which defines a comprehensive set of token constants for PHP 8.1 features (including T\_READONLY, T\_ENUM, T\_ENUM\_CASE, T\_TYPE\_INTERSECTION) alongside backported tokens for older PHP versions.
src/Util · high confidence
PEAR naming convention sniffs added for classes, functions, and variables
The PEAR standard now includes new sniffs to enforce naming conventions for class names, function/method names, and member variables. The ValidClassNameSniff ensures class and interface names start with a capital letter and use underscores as separators. The ValidFunctionNameSniff validates method and function names, including checks for magic methods, private method prefixes, and camelCase formatting. The ValidVariableNameSniff enforces underscore prefixes for private member variables and prevents them on public ones. These changes provide automated style checking for PEAR-compliant code.
src/Standards/PEAR/Sniffs/NamingConventions · high confidence
PEAR standard function sniffs added
The PEAR standard now includes new sniffs for function declarations, function call signatures, and default values. The FunctionDeclarationSniff enforces spacing around the FUNCTION keyword, parentheses, and the USE keyword for closures. The FunctionCallSignatureSniff validates spacing around function calls and handles single and multi-line call formatting. The ValidDefaultValueSniff ensures that function parameters with default values are placed at the end of the argument list.
src/Standards/PEAR/Sniffs/Functions · high confidence
PEAR standard: new ClassDeclaration and IncludingFile sniffs
The PEAR coding standard now includes dedicated sniffs for class declarations and file inclusions. The new ClassDeclarationSniff enforces that opening braces for classes, interfaces, traits, and enums are placed on the line following the declaration, with no extra blank lines, and that the brace is alone on its line. The new IncludingFileSniff enforces the use of include/require\_once in conditional contexts and require/require\_once in unconditional contexts, while also preventing unnecessary parentheses around included files.
src/Standards/PEAR/Sniffs/Classes · high confidence
PSR-1 class declaration sniff added
A new ClassDeclarationSniff has been introduced to enforce PSR-1 standards, ensuring that each class, interface, trait, or enum is defined in its own file and resides within a namespace.
src/Standards/PSR1/Sniffs/Classes · high confidence
Refactored sniffs into a shared abstract base class hierarchy
The PHP\_CodeSniffer library has been refactored to use a new set of abstract base classes (AbstractArraySniff, AbstractPatternSniff, AbstractScopeSniff, AbstractVariableSniff) that provide common functionality for specific types of code analysis. This change introduces a more structured and reusable foundation for implementing new sniffs, allowing developers to extend these abstract classes to handle array, pattern, scope, and variable checks with less boilerplate code.
src/Sniffs · high confidence
Behavioural changes
Centralized exception handling for code analysis
The codebase now uses dedicated exception classes in the PHP\_CodeSniffer\\Exceptions namespace to manage control flow and errors. DeepExitException replaces direct exit() calls to allow the runner to handle exit codes cleanly, while RuntimeException and TokenizerException provide specific error handling for unrecoverable and tokenizer-related issues respectively.
src/Exceptions · high confidence
Enforce modifier keyword ordering and spacing in class and property declarations
The PSR2 coding standard now enforces that the \static\ and \readonly\ modifiers must appear after the visibility declaration on class and property declarations. Additionally, the standard now requires exactly one space between inheritance modifiers (like \abstract\, \final\, \readonly\) and the \class\/\interface\ keyword, and enforces a single space after property type declarations. These changes ensure that code adheres to the PSR-12 and PSR-13 specifications regarding modifier ordering and spacing.
src/Standards/PSR2/Sniffs/Classes · high confidence
Improved support for anonymous classes in core and specific sniffs
The core tokenizer and several sniffs have been updated to properly recognize and handle anonymous classes, ensuring consistent linting and auto-fixing for this PHP feature.
(repo-wide) · high confidence
Introduced new file handling classes for improved caching and STDIN support
The \src/Files\ directory now includes \DummyFile\, \File\, \FileList\, and \LocalFile\ classes. \DummyFile\ handles content without a filesystem path (e.g., STDIN), while \LocalFile\ manages standard files with support for content reloading and caching. \FileList\ manages the iteration of files to be checked. These changes enable more robust handling of STDIN input, better caching of file analysis results, and improved filtering of file lists.
src/Files · high confidence
Major internal refactoring and bug fixes in PHP\_CodeSniffer
The core components of PHP\_CodeSniffer (Config, Fixer, Reporter, Ruleset, Runner) have been significantly refactored to improve stability, performance, and usability. Key changes include: fixing exit codes for PHPCS/PHPCBF to better distinguish between fixable and non-fixable errors; improving the autoloader to correctly handle relative paths and custom namespaces; enhancing the caching system for better performance and accuracy; fixing numerous bugs related to STDIN processing, parallel execution, and report generation; and adding new features like the ability to set array values via CLI, support for custom report classes via FQN, and improved error handling. These changes result in more reliable code analysis and fixing, better performance on large codebases, and more accurate error reporting.
src · high confidence
New and updated naming convention checks for functions and variables
The Squiz standard now includes a new ValidFunctionNameSniff to enforce camel caps for function names, and the existing ValidVariableNameSniff has been updated to validate variable naming in more contexts, including member variables, strings, and object properties. The variable sniff also now correctly handles nullsafe object operators and PHP reserved variables.
src/Standards/Squiz/Sniffs/NamingConventions · high confidence
New naming convention sniffs for abstract classes, interfaces, and traits
The Generic standard now includes new sniffs to enforce naming conventions for abstract classes (AbstractClassNamePrefix), interfaces (InterfaceNameSuffix), and traits (TraitNameSuffix). Additionally, the CamelCapsFunctionName, ConstructorName, and UpperCaseConstantName sniffs have been restructured and expanded: magic methods now include serialize/unserialize, the constructor name sniff better handles nested anonymous classes and PHP 8.1 deprecation notices, and the constant name sniff now supports the PHP 8.0 nullsafe object operator and ignores PHPCS annotation tokens.
src/Standards/Generic/Sniffs/NamingConventions · high confidence
PEAR comment sniffs migrated to new namespace and support modern PHP features
The PEAR comment sniffs (ClassComment, FileComment, FunctionComment, and InlineComment) have been moved into the new \PHP\_CodeSniffer n n nStandards n n nPEAR n n nSniffs n n nCommenting\ namespace. This migration includes support for PHP 8.1 enums and PHP 8.2 readonly classes in the class comment sniff, and adds handling for PHP attributes in function and class comment checks to prevent false positives. The inline comment sniff remains unchanged in behavior but is now part of the restructured directory layout.
src/Standards/PEAR/Sniffs/Commenting · high confidence
PSR1/SideEffects sniff updated to support modern PHP features and disable comments
The PSR1/SideEffects sniff now recognizes PHP 8.1 enums and PHP 8.0 nullsafe object operators as valid symbol declarations, preventing false positives for these constructs. Additionally, the sniff now respects \@phpcs:disable\ annotations, allowing users to selectively disable the check on specific lines or blocks of code.
src/Standards/PSR1/Sniffs/Files · high confidence
Restored Windows batch files for PHP\_CodeSniffer and PHP Code Beautifier
The Windows batch files (phpcs.bat and phpcbf.bat) have been re-added to the bin directory, ensuring that users on Windows can continue to invoke the PHP\_CodeSniffer and PHP Code Beautifier tools via the .bat wrappers. The underlying PHP scripts (phpcs and phpcbf) have been updated to return exit codes from the Runner's runPHPCS() and runPHPCBF() methods, allowing the batch files to correctly propagate the tool's exit status.
bin · high confidence
Squiz comment sniffs support PHP 8.1/8.2+ features and fix fixer conflicts
The Squiz comment sniffs have been updated to support modern PHP syntax, including enums, readonly classes/properties, and match expressions. The \BlockCommentSniff\ now correctly ignores enums and attributes, while \ClosingDeclarationCommentSniff\ and \LongConditionClosingCommentSniff\ recognize enums and match statements respectively. Additionally, several sniffs (\FunctionComment\, \InlineComment\, \PostStatementComment\) have been fixed to prevent false positives with attributes, handle nullable type hints, and resolve fixer conflicts where comments were incorrectly modified or left unfixable.
src/Standards/Squiz/Sniffs/Commenting · high confidence
Squiz whitespace sniffs migrated to PHP\_CodeSniffer 3.x
The Squiz standard's whitespace-related sniffs (including CastSpacing, ControlStructureSpacing, FunctionClosingBraceSpace, FunctionOpeningBraceSpace, FunctionSpacing, LanguageConstructSpacing, LogicalOperatorSpacing, MemberVarSpacing, ObjectOperatorSpacing, OperatorSpacing, PropertyLabelSpacing, and ScopeClosingBrace) have been rewritten for PHP\_CodeSniffer 3.x. This update ensures these sniffs correctly enforce spacing rules for PHP and JavaScript code, with improved handling of fixer conflicts, support for newer language features (such as PHP 8.0/8.1 constructs), and more robust error reporting and auto-fixing capabilities.
src/Standards/Squiz/Sniffs/WhiteSpace · high confidence
Squiz/OperatorBracket: fix false positives and regressions
The Squiz/OperatorBracket sniff has been updated to correctly handle various edge cases that previously caused false positives or failed to fix code properly. Specific improvements include: no longer throwing errors for PHP 7.1 multi-catch exceptions; correctly fixing statements containing strings, short array syntax, and pipe-separated flags; making an exception for match expressions; allowing the nullsafe object operator; and fixing incorrect autofixes for the null coalescing operator and static statements. The sniff now also correctly ignores reference operators and handles unary minus in assignments and comparisons.
src/Standards/Squiz/Sniffs/Formatting · high confidence
Test coverage
Added core unit tests for error suppression and naming conventions; Added integration tests for the Ruleset class; Added test cases for PSR2 ClosingTag and EndFileNewline sniffs; Added test coverage for the Filter::accept method; Added tests for Config reportWidth setting; Added tests for PSR-12 FileHeader, ImportStatement, DeclareStatement, and OpenTag sniffs; Added tests for PSR12 ConstantVisibility sniff; Added tests for PSR12 OperatorSpacing rule; Added tests for Zend/ValidVariableName sniff; Added tests for the AbstractArraySniff class; Added tests for the PSR12 UseDeclaration sniff; Added tests for the autoloader's class name detection; Added tokenizer tests for PHP 8.1 enums, attributes, and explicit octal notation; Added unit tests for ArrayBracketSpacing and ArrayDeclaration sniffs; Added unit tests for CSSLint, ClosureLinter, ESLint, and JSHint; Added unit tests for CyclomaticComplexity and NestingLevel sniffs; Added unit tests for DisallowYodaConditions and InlineControlStructure sniffs; Added unit tests for Generic file sniffs; Added unit tests for Generic naming convention sniffs; Added unit tests for Generic whitespace sniffs; Added unit tests for Generic/DuplicateClassName and Generic/OpeningBraceSameLine sniffs; Added unit tests for Git merge conflict detection; Added unit tests for JSLint and JavaScriptLint sniffs; Added unit tests for PEAR ClassDeclaration sniff; Added unit tests for PEAR ControlSignature and MultiLineCondition sniffs; Added unit tests for PEAR function standards; Added unit tests for PEAR naming conventions; Added unit tests for PHP code standard sniffs; Added unit tests for PSR-12 ControlStructures sniffs; Added unit tests for PSR-12 class formatting sniffs; Added unit tests for PSR-12 function sniffs; Added unit tests for PSR-12 standards; Added unit tests for PSR1 CamelCapsMethodName sniff; Added unit tests for PSR2 ClassDeclaration and PropertyDeclaration sniffs; Added unit tests for PSR2 Method, FunctionCallSignature, and FunctionClosingBrace sniffs; Added unit tests for Squiz PHP standards; Added unit tests for Squiz class-related sniffs; Added unit tests for Squiz comment sniffs; Added unit tests for Squiz control structure sniffs; Added unit tests for Squiz function sniffs; Added unit tests for Squiz object-related sniffs; Added unit tests for Squiz operator sniffs; Added unit tests for Squiz string-related sniffs; Added unit tests for core File class methods; Added unit tests for multiple Generic code analysis sniffs; Added unit tests for multiple Squiz CSS sniffs; Added unit tests for the PEAR IncludingFile sniff; Added unit tests for the Squiz FileExtension sniff; Added unit tests for the Squiz OperatorBracket sniff; Added unit tests for the UnnecessaryStringConcat sniff; Added unit tests for the Zend ClosingTag sniff; Added unit tests for the Zend CodeAnalyzer sniff; Expanded test coverage for PSR1 SideEffects sniff; Expanded test coverage for PSR2 namespace and use declaration rules; New test infrastructure for PHP\_CodeSniffer; Refactored sniff unit test runner to support all installed standards.
Dependencies
Add Composer support for PHP\_CodeSniffer
A new composer.json file has been added to the project, enabling installation via Composer. The package is defined as 'squizlabs/php\_codesniffer' and specifies PHP 5.4.0+ as a requirement, along with the 'ext-tokenizer', 'ext-xmlwriter', and 'ext-simplexml' extensions. It also includes 'phpunit/phpunit' as a dev dependency for testing, and exposes the 'phpcs' and 'phpcbf' scripts as binaries.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 37 → 59 (+22.3)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 56 → 64 (+8.2)
- Architecture 96 → 96 (+0.6)
- Maturity 61 → 50 (-10.6)
- Readiness 14 → 64 (+50.2)
- Security 52 → 71 (+19.6)
Resolved (179)
- Config.__construct (cognitive 28) (Config)
- Config.__construct (cyclomatic 18) (Config)
- Config.__set (cognitive 26) (Config)
- Config.processLongArgument (cognitive 1064) (Config)
- Config.processLongArgument (cyclomatic 114) (Config)
- Config.processShortArgument (cyclomatic 21) (Config)
- Config.restoreDefaults (cognitive 19) (Config)
- Config.restoreDefaults (cyclomatic 17) (Config)
- Config.setCommandLineValues (cognitive 25) (Config)
- Config.setConfigData (cognitive 25) (Config)
- Config.setConfigData (cyclomatic 16) (Config)
- Coverage not measured — test suite did not build
- Dimension evaluation failed
- Duplicated block (10 lines × 2) (src/Ruleset.php)
- Duplicated block (10 lines × 2) (src/Ruleset.php)
- Duplicated block (10 lines × 2) (src/Standards/Generic/Sniffs/ControlStructures/InlineControlStructureSniff.php)
- Duplicated block (10 lines × 2) (src/Standards/Generic/Sniffs/WhiteSpace/ScopeIndentSniff.php)
- Duplicated block (10 lines × 2) (src/Standards/PEAR/Sniffs/Commenting/FunctionCommentSniff.php)
- Duplicated block (10 lines × 2) (src/Standards/PEAR/Sniffs/Commenting/FunctionCommentSniff.php)
- Duplicated block (10 lines × 2) (src/Standards/PEAR/Sniffs/Functions/FunctionDeclarationSniff.php)
- …and 159 more
New (802)
- AbstractPatternSniff.parse (cognitive 40) (src/Sniffs/AbstractPatternSniff.php)
- AbstractPatternSniff.process (cognitive 16) (src/Sniffs/AbstractPatternSniff.php)
- AbstractPatternSniff.processPattern (cognitive 368) (src/Sniffs/AbstractPatternSniff.php)
- AbstractPatternSniff.processPattern (cyclomatic 88) (src/Sniffs/AbstractPatternSniff.php)
- AbstractVariableSniff.processTokenWithinScope (cognitive 28) (src/Sniffs/AbstractVariableSniff.php)
- AbstractVariableSniff.processTokenWithinScope (cyclomatic 17) (src/Sniffs/AbstractVariableSniff.php)
- AjaxNullComparisonSniff.process (cognitive 16) (src/Standards/MySource/Sniffs/PHP/AjaxNullComparisonSniff.php)
- AnonClassDeclarationSniff.process (cognitive 25) (src/Standards/PSR12/Sniffs/Classes/AnonClassDeclarationSniff.php)
- AnonClassDeclarationSniff.processSingleLineArgumentList (cognitive 40) (src/Standards/PSR12/Sniffs/Classes/AnonClassDeclarationSniff.php)
- AnonClassDeclarationSniff.processSingleLineArgumentList (cyclomatic 17) (src/Standards/PSR12/Sniffs/Classes/AnonClassDeclarationSniff.php)
- ArbitraryParenthesesSpacingSniff.process (cognitive 109) (src/Standards/Generic/Sniffs/WhiteSpace/ArbitraryParenthesesSpacingSniff.php)
- ArbitraryParenthesesSpacingSniff.process (cyclomatic 38) (src/Standards/Generic/Sniffs/WhiteSpace/ArbitraryParenthesesSpacingSniff.php)
- ArrayDeclarationSniff.process (cognitive 41) (src/Standards/Squiz/Sniffs/Arrays/ArrayDeclarationSniff.php)
- ArrayDeclarationSniff.processMultiLineArray (cognitive 332) (src/Standards/Squiz/Sniffs/Arrays/ArrayDeclarationSniff.php)
- ArrayDeclarationSniff.processMultiLineArray (cyclomatic 112) (src/Standards/Squiz/Sniffs/Arrays/ArrayDeclarationSniff.php)
- ArrayDeclarationSniff.processSingleLineArray (cognitive 80) (src/Standards/Squiz/Sniffs/Arrays/ArrayDeclarationSniff.php)
- ArrayDeclarationSniff.processSingleLineArray (cyclomatic 28) (src/Standards/Squiz/Sniffs/Arrays/ArrayDeclarationSniff.php)
- ArrayIndentSniff.processMultiLineArray (cognitive 27) (src/Standards/Generic/Sniffs/Arrays/ArrayIndentSniff.php)
- AssignmentInConditionSniff.process (cognitive 39) (src/Standards/Generic/Sniffs/CodeAnalysis/AssignmentInConditionSniff.php)
- AssignmentInConditionSniff.process (cyclomatic 18) (src/Standards/Generic/Sniffs/CodeAnalysis/AssignmentInConditionSniff.php)
- …and 782 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
squizlabs/PHP_CodeSniffer was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit c6c65ca0dc8608ba87631523b97b2f8d5351a854 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-a15879f6f801.