Skip to content
CAI
Software that uses CAICheck a score

squizlabs/PHP_CodeSniffer

59.5

Adequate · 26 September 2026

55.6k

lines of production code

PHP

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This release delivers a comprehensive overhaul of PHP\_CodeSniffer’s internal architecture, introducing dedicated tokenizers for CSS, JavaScript, and PHP, alongside a robust caching system and improved exit code handling. A significant portion of the update focuses on modernizing coding standards, with extensive new sniffs for PSR-12, PEAR, Squiz, and Generic standards, including support for PHP 8.1/8.2 features like enums and attributes. The release also expands cross-language analysis capabilities with new Git-aware filters, external tool integrations, and enhanced Windows batch file support.

Features

Add JSLint and JavaScript Lint debug sniffs

The Squiz standard now includes two new debug sniffs, JSLintSniff and JavaScriptLintSniff, which integrate external JavaScript linting tools (jslint.js and JavaScript Lint) into PHP\_CodeSniffer. These sniffs execute the respective external tools on JavaScript files and report any warnings or errors found, allowing developers to catch JavaScript issues alongside PHP code.

src/Standards/Squiz/Sniffs/Debug · high confidence

Add UnnecessaryStringConcatSniff to detect redundant string concatenation

A new sniff, UnnecessaryStringConcatSniff, has been added to the Generic standard. It identifies cases where two strings are concatenated together when a single string would suffice, suggesting a cleaner alternative. The sniff supports both PHP and JavaScript tokenizers and includes options to control whether errors or warnings are raised, and whether multiline concatenation is allowed.

src/Standards/Generic/Sniffs/Strings · high confidence

Add documentation generators for HTML, Markdown, and Text output formats

The PHP\_CodeSniffer tool now includes built-in generators to produce documentation for coding standards in HTML, Markdown, and plain text formats. This allows users to generate human-readable reference material for sniffs, with the text generator specifically handling line wrapping to ensure proper formatting in terminal outputs.

src/Generators · high confidence

Added FileExtensionSniff to enforce .php/.inc file naming conventions

A new sniff, FileExtensionSniff, has been introduced to the Squiz standard. It enforces that files containing classes, interfaces, traits, or enums use the .php extension, while non-class files should use .inc. The sniff registers for the opening PHP tag, scans for class-like tokens (including enums), and reports errors if the file extension does not match the content type.

src/Standards/Squiz/Sniffs/Files · high confidence

Added PEAR package.xml validation script

A new \ValidatePEARPackageXML\ script has been added to the \scripts/ValidatePEAR\ directory. This tool validates the PHP\_CodeSniffer \package.xml\ file by checking that all files in the \src\ and \tests\ directories are correctly listed in the \\<contents\>\ tag, ensuring no files are missing from the package definition.

scripts/ValidatePEAR · high confidence

Added Zend Code Analyzer integration for PHP\_CodeSniffer

A new \CodeAnalyzerSniff\ has been introduced in the Zend standard to integrate with the external Zend Code Analyzer tool. When the analyzer executable is found on the system, the sniff executes it against each PHP file, parsing the tool's output to report warnings for any issues identified by the external static analysis tool.

src/Standards/Zend/Sniffs/Debug · high confidence

Added and fixed CSS coding standard sniffs

The Squiz CSS coding standard now includes a comprehensive set of new sniffs to enforce CSS formatting and style rules. These include checks for class definition spacing, colon spacing, color definitions, duplicate styles, empty definitions, forbidden styles, indentation, lowercase styles, missing colons, named colors, opacity values, and semicolon spacing. Several sniffs have been updated to fix 'Undefined index' errors and improve fixer behavior, ensuring that automated code corrections work correctly for CSS files.

src/Standards/Squiz/Sniffs/CSS · high confidence

Added new tokenizers for CSS, JavaScript, and PHP code

The codebase now includes dedicated tokenizers for CSS, JavaScript, and PHP, each extending a shared abstract Tokenizer base class. The CSS tokenizer handles CSS-specific syntax by wrapping content in PHP tags and converting specific tokens. The JavaScript tokenizer defines scope openers and closers for JS constructs like if, for, and switch. The PHP tokenizer provides the primary implementation for parsing PHP code, including support for modern PHP features like enums and match expressions. These components work together to provide comprehensive syntax analysis across multiple languages.

src/Tokenizers · high confidence

Enforce PSR-12 rules for trait import statements

The PSR-12 standard now includes a new UseDeclarationSniff that validates trait import statements. This enforces that all trait imports are grouped together, each import is on its own line, and the first import appears immediately after the opening brace (ignoring comments). The sniff also provides automatic fixes for spacing and grouping violations.

src/Standards/PSR12/Sniffs/Traits · high confidence

Enforce PSR-12 spacing rules for return and nullable type declarations

Added new PSR-12 sniffs for return type and nullable type declarations. The ReturnTypeDeclarationSniff ensures there is exactly one space between the colon and the return type, and no space before the colon. The NullableTypeDeclarationSniff ensures there is no space between the question mark and the type in nullable type declarations. Both sniffs provide automatic fixes for spacing issues.

src/Standards/PSR12/Sniffs/Functions · high confidence

Enforce PSR-2 control structure spacing and formatting rules

The PSR-2 standard now includes new sniffs to enforce consistent formatting for control structures. \ControlStructureSpacingSniff\ ensures correct spacing around parentheses in control structures, while \ElseIfDeclarationSniff\ enforces the use of \elseif\ over \else if\. \SwitchDeclarationSniff\ validates switch statement formatting, including case indentation, lowercase keywords, and proper termination of case blocks. These changes improve code style consistency for PHP developers using the PSR-2 standard.

src/Standards/PSR2/Sniffs/ControlStructures · high confidence

Enforce PSR-2 file formatting rules for closing tags and trailing newlines

Added ClosingTagSniff and EndFileNewlineSniff to the PSR-2 standard. The new ClosingTagSniff detects and removes trailing PHP closing tags, while the EndFileNewlineSniff ensures files end with exactly one newline and no excessive blank lines. Both sniffs include automatic fixers to correct violations.

src/Standards/PSR2/Sniffs/Files · high confidence

Enforce blank line after namespace declaration and validate USE statement placement

Added new PSR2 sniffs for namespace and USE declarations. The NamespaceDeclarationSniff ensures there is exactly one blank line after a namespace declaration, while the UseDeclarationSniff enforces that USE statements appear after the namespace declaration and that each USE keyword is followed by a single space. These changes introduce new linting rules and auto-fixes for namespace formatting and USE statement placement.

src/Standards/PSR2/Sniffs/Namespaces · high confidence

Enforce camelCase method naming in PSR1 standard

The PSR1 standard now includes a new \CamelCapsMethodNameSniff\ that validates method names against camelCase formatting. This check applies to all methods within classes, excluding magic methods and closures, and reports errors for any method names that do not conform to the camelCase convention.

src/Standards/PSR1/Sniffs/Methods · high confidence

Enforce short-form type keywords and limit compound namespace depth in PSR-12

The PSR-12 standard now includes two new sniffs. The ShortFormTypeKeywordsSniff requires the use of short-form type keywords (e.g., int, bool) and provides an automatic fix to replace long-form casts. The CompoundNamespaceDepthSniff enforces a maximum depth for compound namespaces, defaulting to a depth of 2, and reports an error if the depth is exceeded.

src/Standards/PSR12/Sniffs/Keywords · high confidence

Enforce spacing around operators in PSR-12

The PSR-12 standard now includes a new \OperatorSpacingSniff\ that verifies operators have at least one space of whitespace before and after them. This enforces consistent spacing around comparison, assignment, boolean, and other operators, with automatic fixing available for missing spaces.

src/Standards/PSR12/Sniffs/Operators · high confidence

Enforce visibility on class constants

A new PSR12 standard rule, ConstantVisibility, has been added to require explicit visibility declarations on all class constants. This change ensures that every class constant includes a visibility modifier (such as public, protected, or private), addressing a gap in the previous behavior where non-class constants might have triggered false positives.

src/Standards/PSR12/Sniffs/Properties · high confidence

Introduce Squiz array formatting rules

Added new Squiz standard sniffs for array formatting: ArrayBracketSpacing enforces spacing around square brackets, and ArrayDeclaration enforces style, indentation, and fixer rules for array declarations. This brings the Squiz standard's array handling in line with the rest of the codebase by using the new namespace-based structure.

src/Standards/Squiz/Sniffs/Arrays · high confidence

Introduce Zend/ValidVariableName sniff for PHP variable naming conventions

The PHP\_CodeSniffer tool now includes a new \ValidVariableNameSniff\ within the Zend coding standard. This addition enforces camelCase naming for all variables, member variables, and variables embedded in strings, while also applying specific rules for public versus private/protected member variables regarding leading underscores. Users will now receive errors or warnings when variable names violate these camelCase or underscore conventions.

src/Standards/Zend/Sniffs/NamingConventions · high confidence

New CyclomaticComplexity and NestingLevel sniffs in the Generic standard

The Generic standard now includes two new metric sniffs: CyclomaticComplexitySniff and NestingLevelSniff. The complexity sniff counts decision points (including ternary, null coalescence, and null-safe operators) to warn or error when a function's cyclomatic complexity exceeds configurable thresholds. The nesting level sniff calculates the deepest nesting depth within functions, warning or erroring when the nesting level exceeds configurable limits. Both sniffs allow users to configure the warning and error thresholds via the standard's configuration.

src/Standards/Generic/Sniffs/Metrics · high confidence

New Git merge conflict and Subversion property sniffs

Added new sniffs for the Generic standard: GitMergeConflictSniff detects Git merge conflict markers (e.g., \<\<\<\<\<\<\<, =======, \>\>\>\>\>\>\>) in PHP, JavaScript, and CSS files, while SubversionPropertiesSniff validates Subversion properties (svn:keywords, svn:eol-style) on files under version control.

src/Standards/Generic/Sniffs/VersionControl · high confidence

New Git-aware file filters for targeted linting

Added new \GitModified\ and \GitStaged\ filters that allow PHP\_CodeSniffer to lint only files that have been modified or staged in a Git repository. This enables developers to run linting on a subset of files, such as during pre-commit hooks or CI checks, rather than scanning the entire codebase. The implementation includes a base \ExactMatch\ filter class and specific subclasses that query Git to determine which files to include.

src/Filters · high confidence

New MySource code standards and sniffs for PHP, CSS, and JavaScript

The MySource standard now includes a comprehensive set of new sniffs that enforce coding practices across PHP, CSS, and JavaScript. For PHP, the standard checks that superglobals are accessed via a helper method, that eval() is not used to instantiate objects, that Ajax requests are not compared to NULL, and that function results are not returned directly. For JavaScript, it ensures that console is not used for variable or function names, that 'this' is only assigned to 'self', that widgets are not manually created, and that widget type callbacks are properly structured. For CSS, it prevents the use of browser-specific styles. Additionally, the standard enforces that systems are included before use and that included systems are actually used.

src/Standards/MySource/Sniffs · high confidence

New PEAR coding standard sniffs for control structures and formatting

The PEAR standard now includes new sniffs to enforce coding style rules. ControlSignatureSniff verifies that control statements (including the new match expression) follow the standard pattern. MultiLineConditionSniff ensures multi-line IF conditions are correctly indented and formatted. MultiLineAssignmentSniff enforces that multi-line assignments have the equal sign on the second line and are properly indented.

src/Standards/PEAR/Sniffs/ControlStructures · high confidence

New PEAR whitespace sniffs for object operators, scope closing braces, and scope indentation

The PEAR standard now includes three new whitespace sniffs: ObjectOperatorIndentSniff, which checks that chained object operators are indented correctly (including support for PHP 8.0's nullsafe operator); ScopeClosingBraceSniff, which ensures closing braces are aligned and on their own lines; and ScopeIndentSniff, which enforces correct indentation for control structures. These changes improve code formatting consistency for PHP developers using the PEAR standard.

src/Standards/PEAR/Sniffs/WhiteSpace · high confidence

New PHP 8.1 enum support and duplicate class name detection

The Generic coding standard now includes new sniffs for detecting duplicate class, interface, and trait names across files, and enforces opening brace placement for classes, interfaces, traits, and PHP 8.1 enums. Users will see warnings for duplicate type names and fixable errors for brace placement and spacing, with the new DuplicateClassNameSniff tracking namespaces to identify conflicts.

src/Standards/Generic/Sniffs/Classes · high confidence

New PHP code sniffs for syntax, types, and constants

The Generic standard introduces several new sniffs to enforce PHP coding standards: SyntaxSniff validates PHP syntax; BacktickOperatorSniff forbids the backtick execution operator; CharacterBeforePHPOpeningTagSniff ensures the opening PHP tag is the first content; ClosingPHPTagSniff checks for paired PHP tags; DisallowAlternativePHPTagsSniff and DisallowShortOpenTagSniff enforce standard PHP tags; DiscourageGotoSniff warns against using goto; DeprecatedFunctionsSniff flags deprecated functions; DisallowRequestSuperglobalSniff discourages $\_REQUEST; ForbiddenFunctionsSniff blocks specified functions; LowerCaseConstantSniff and UpperCaseConstantSniff enforce case for TRUE, FALSE, NULL; LowerCaseKeywordSniff enforces lowercase keywords; LowerCaseTypeSniff enforces lowercase type declarations; NoSilencedErrorsSniff warns about error suppression; RequireStrictTypesSniff mandates strict\_types declaration; SAPIUsageSniff prefers PHP\_SAPI constant; and the existing ForbiddenFunctionsSniff is extended to support nullsafe operators and class names in attributes.

src/Standards/Generic/Sniffs/PHP · high confidence

New PSR-12 class formatting and instantiation checks

The PSR-12 standard now includes four new sniffs to enforce class formatting and instantiation rules: \AnonClassDeclarationSniff\ validates anonymous class formatting; \ClassInstantiationSniff\ ensures classes are instantiated with parentheses; \ClosingBraceSniff\ prevents comments or statements on the same line as closing braces; and \OpeningBraceSpaceSniff\ prohibits blank lines after opening braces. These changes improve code consistency and catch style violations in class declarations and instantiations.

src/Standards/PSR12/Sniffs/Classes · high confidence

New PSR12 sniffs for control structure spacing and boolean operator placement

Two new sniffs have been added to the PSR12 standard: \ControlStructureSpacing\ enforces correct spacing and indentation inside multi-line control structure parentheses, while \BooleanOperatorPlacement\ ensures boolean operators between conditions are consistently placed at the beginning or end of the line. The \BooleanOperatorPlacement\ sniff also supports an \allowOnly\ configuration option to restrict operators to either the first or last position, and both sniffs handle PHP 8 \match\ expressions.

src/Standards/PSR12/Sniffs/ControlStructures · high confidence

New PSR12 sniffs for file headers, import statements, declare statements, and open tags

The PSR12 standard now includes new sniffs to enforce formatting rules for PHP files. FileHeaderSniff ensures the file header is the first content in the file, allowing for hashbang lines. ImportStatementSniff enforces that import statements do not begin with a leading backslash and provides auto-fixing. DeclareStatementSniff checks the formatting of declare statements, including spacing and case. OpenTagSniff ensures the opening PHP tag is on a line by itself for PHP-only files.

src/Standards/PSR12/Sniffs/Files · high confidence

New PSR2 method and function call signature checks

Three new sniffs have been added to the PSR2 standard to enforce stricter formatting for method declarations, function call signatures, and function closing braces. The MethodDeclarationSniff now validates the order of method modifiers (static, abstract, final, visibility) and warns against underscore-prefixed method names. The FunctionCallSignatureSniff introduces checks for multi-line function calls, while the FunctionClosingBraceSniff ensures closing braces are placed correctly after function bodies. These changes improve code consistency and provide automatic fixes for common formatting errors.

src/Standards/PSR2/Sniffs/Methods · high confidence

New Squiz PHP sniffs for code style and safety

Added new Squiz standard sniffs to enforce coding conventions and improve code quality: CommentedOutCode (warns about commented-out code), DisallowBooleanStatement (prevents boolean operators outside control structures), DisallowComparisonAssignment (prevents assigning comparison results to variables), DisallowInlineIf (bans inline IF statements), DisallowMultipleAssignments (enforces single assignments per line), DisallowSizeFunctionsInLoops (bans size functions in loop conditions), DiscouragedFunctions (flags debug functions like print\_r), EmbeddedPhp (enforces indentation of embedded PHP), Eval (discourages eval), GlobalKeyword (forbids the global keyword), Heredoc (bans heredoc/nowdoc syntax), InnerFunctions (forbids nested functions), LowercasePHPFunctions (enforces lowercase for built-in functions), and NonExecutableCode (warns about unreachable code).

src/Standards/Squiz/Sniffs/PHP · high confidence

New Squiz code standards for object syntax and instantiation

Three new PHP\_CodeSniffer sniffs have been added to the Squiz standard to enforce stricter object usage. ObjectMemberCommaSniff now flags trailing commas in object literals, ObjectInstantiationSniff requires that new objects be assigned to variables (with updated logic to handle PHP 8.0+ match expressions), and DisallowObjectStringIndexSniff enforces dot notation for object indexing in JavaScript. These changes improve code consistency and catch potential errors in object handling.

src/Standards/Squiz/Sniffs/Objects · high confidence

Added three new PHP\_CodeSniffer sniffs for the Squiz standard: ConcatenationSpacingSniff enforces spacing around the string concatenation operator; DoubleQuoteUsageSniff flags unnecessary double-quoted strings and disallows variables within them; EchoedStringsSniff prevents wrapping echoed strings in parentheses. These changes improve static analysis of string formatting and style.

src/Standards/Squiz/Sniffs/Strings · high confidence

New Zend standard rule to remove trailing PHP closing tags

A new sniff, ClosingTagSniff, has been added to the Zend standard to enforce that PHP files do not end with a closing tag. The rule detects a closing tag at the end of a file and, if fixable, removes it. The fixer logic also ensures a semicolon is added before the closing tag if the preceding token is not already a semicolon, closing tag, or curly bracket.

src/Standards/Zend/Sniffs/Files · high confidence

New and improved function declaration sniffs in the Squiz standard

The Squiz standard now includes dedicated sniffs for function declarations, including spacing, duplicate arguments, global function warnings, lowercase keywords, and multi-line formatting. These changes enforce consistent function declaration styles, such as requiring lowercase for keywords like \function\, \closure\, and \fn\, and ensure proper spacing around parentheses, reference operators, and variadic operators. Users will see new linting rules and auto-fixes for function-related code style issues.

src/Standards/Squiz/Sniffs/Functions · high confidence

The Squiz standard now includes new sniffs for class declarations, file naming, duplicate properties, lowercase keywords, self references, and valid class names. ClassDeclarationSniff enforces single-class-per-file and brace spacing; ClassFileNameSniff validates names for classes, interfaces, traits, and enums; DuplicatePropertySniff detects duplicate JS object properties; LowercaseClassKeywordsSniff enforces lowercase for class keywords including readonly; SelfMemberReferenceSniff ensures correct self:: usage and spacing; ValidClassNameSniff enforces PascalCase for class, interface, trait, and enum names.

src/Standards/Squiz/Sniffs/Classes · high confidence

New and updated Squiz control structure sniffs

The Squiz standard now includes new sniffs for control structures: ControlSignature enforces spacing after keywords and closing parentheses, and allows configuring spaces before the colon in alternative syntax; ForLoopDeclaration and ForEachLoopDeclaration enforce spacing around brackets and the 'as' keyword; InlineIfDeclaration checks spacing for shorthand IF statements; LowercaseDeclaration ensures control keywords are lowercase; and SwitchDeclaration enforces indentation and spacing for case/default statements. These changes provide automated enforcement of consistent control structure formatting.

src/Standards/Squiz/Sniffs/ControlStructures · high confidence

New and updated formatting sniffs for PHP CodeSniffer

The Generic standard now includes new sniffs to enforce spacing around cast operators and the NOT operator, alongside updates to existing alignment checks. A new \SpaceBeforeCast\ sniff ensures a single space precedes cast tokens, while \SpaceAfterCast\ and \SpaceAfterNot\ enforce configurable spacing after cast and NOT operators respectively. The \NoSpaceAfterCast\ sniff is now deprecated in favor of the new \SpaceAfterCast\ with a spacing of 0. Additionally, \MultipleStatementAlignment\ and \DisallowMultipleStatements\ have been updated to handle edge cases involving closures, anonymous classes, and FOR loops, preventing false positives and fatal errors in these scenarios.

src/Standards/Generic/Sniffs/Formatting, src/Standards/Generic/Sniffs/WhiteSpace · high confidence

New and updated report generators for PHP\_CodeSniffer

The \src/Reports\ directory now includes implementations for CBF, Checkstyle, Code, CSV, Diff, Emacs, Full, Gitblame, Hgblame, Info, JSON, JUnit, and Notifysend reports. These changes introduce or update the output formats available to users, enabling integration with various CI/CD pipelines (Jenkins, JUnit), IDEs (Emacs), and other tools (Checkstyle, CSV, JSON). The CBF report specifically handles the auto-fixing features of the PHPCBF script, while other reports like Full and Code provide detailed error and warning information in different formats.

src/Reports · high confidence

New array syntax and indentation rules for PHP CodeSniffer

Added three new sniffs to the Generic standard: ArrayIndentSniff enforces consistent indentation for multi-line arrays, DisallowLongArraySyntaxSniff bans the long array syntax (array()) in favor of short syntax (\[\]), and DisallowShortArraySyntaxSniff bans the short array syntax in favor of the long syntax (array()). These changes allow users to enforce specific array formatting and syntax preferences in their codebases.

src/Standards/Generic/Sniffs/Arrays · high confidence

New build and validation scripts for PHAR packaging and PEAR package verification

Added scripts/build-phar.php to automate the creation of the phpcs and phpcbf PHAR files, implementing a custom whitespace and comment stripping function for cross-version PHP compatibility. Also added scripts/validate-pear-package.php to validate the PEAR package.xml file, ensuring the package meets required standards before release.

scripts · high confidence

New code analysis sniffs for PHP\_CodeSniffer Generic standard

The Generic standard introduces several new code analysis sniffs to detect common code smells and potential issues. These include \AssignmentInCondition\ to flag variable assignments in conditions, \EmptyPHPStatement\ to detect empty PHP statements and superfluous semicolons, \EmptyStatement\ to find empty control structure bodies, \ForLoopShouldBeWhileLoop\ to suggest simplifying for-loops, \ForLoopWithTestFunctionCall\ to warn about function calls in loop tests, \JumbledIncrementer\ to detect confusing loop incrementers, \UnconditionalIfStatement\ to flag always-true/false conditions, \UnnecessaryFinalModifier\ to remove redundant final modifiers, and \UselessOverridingMethod\ to identify methods that merely call the parent. These additions help developers identify and clean up problematic or redundant code patterns.

src/Standards/Generic/Sniffs/CodeAnalysis · high confidence

The Generic standard now includes new sniffs for detecting TODO and FIXME comments, as well as enforcing basic formatting for doc blocks. The \TodoSniff\ and \FixmeSniff\ classes have been added to warn about these specific comment types, while \DocCommentSniff\ enforces structure and capitalization rules for PHPDoc blocks. These changes improve code quality checks by identifying pending tasks and ensuring consistent documentation formatting.

src/Standards/Generic/Sniffs/Commenting · high confidence

New debug sniffs for external linting tools

Added four new debug sniffs that integrate external JavaScript and CSS linting tools into the code analysis workflow. The new \CSSLintSniff\ runs \csslint\ on CSS files, while \ClosureLinterSniff\, \ESLintSniff\, and \JSHintSniff\ execute \gjslint\, \eslint\, and \jshint\ respectively on JavaScript files. Each sniff parses the output of the respective tool and reports warnings or errors on the corresponding lines in the source file.

src/Standards/Generic/Sniffs/Debug · high confidence

New file-level code quality checks and stricter line-length rules

The Generic standard now includes several new sniffs to enforce file structure and formatting: ByteOrderMarkSniff detects BOM headers, EndFileNewlineSniff and EndFileNoNewlineSniff enforce trailing newlines, LineEndingsSniff validates EOL characters, ExecutableFileSniff prevents PHP files from being executable, InlineHTMLSniff ensures files contain only PHP code, and LowercasedFilenameSniff enforces lowercase filenames. Additionally, the LineLengthSniff now supports an ignoreComments property to exclude comment-only lines from length checks, and OneObjectStructurePerFileSniff enforces a single class, interface, trait, or enum per file.

src/Standards/Generic/Sniffs/Files · high confidence

The Generic standard now includes three new sniffs to enforce coding style for function calls and braces: CallTimePassByReferenceSniff prohibits passing variables by reference in function calls; FunctionCallArgumentSpacingSniff enforces consistent spacing around commas in function arguments; and OpeningFunctionBraceBsdAllmanSniff and OpeningFunctionBraceKernighanRitchieSniff enforce whether the opening brace for functions and closures should be on the same line or the next line, with automatic fixing capabilities.

src/Standards/Generic/Sniffs/Functions · high confidence

New operator usage sniffs for PHP and JavaScript

Added three new sniffs in the Squiz standard to enforce better operator usage: ComparisonOperatorUsage enforces identical comparison operators (===) over equal (==); IncrementDecrementUsage encourages using ++/-- over += 1 or -= 1; and ValidLogicalOperators prohibits the use of 'and'/'or' in favor of &&/\|\|. These changes provide automated code style enforcement for common operator anti-patterns.

src/Standards/Squiz/Sniffs/Operators · high confidence

New scope validation sniffs for methods, member variables, and static $this usage

The Squiz standard introduces three new sniffs to enforce stricter scope and usage rules: MethodScopeSniff now requires explicit visibility modifiers on all class methods; MemberVarScopeSniff requires explicit scope modifiers on class member variables; and StaticThisUsageSniff detects the use of $this within static methods, which causes runtime errors. These changes add new linting errors for previously unvalidated code patterns.

src/Standards/Squiz/Sniffs/Scope · high confidence

New sniffs for Yoda conditions and inline control structures

Added new PHP\_CodeSniffer sniffs to enforce coding standards: DisallowYodaConditionsSniff flags Yoda-style conditions (e.g., \if (null === $var)\), and InlineControlStructureSniff detects and auto-fixes inline control structures (e.g., \if ($x) echo $y;\) by adding braces. These changes help standardize code style by preventing unsafe comparisons and encouraging explicit block syntax.

src/Standards/Generic/Sniffs/ControlStructures · high confidence

New utility classes for caching, token definitions, and standards management

The src/Util directory now includes new utility classes: Cache.php for managing run caching with improved file hashing and configuration tracking; Common.php with helper functions like isReadable and realpath; Standards.php for discovering and listing installed coding standards; Timing.php for run time and memory reporting; and Tokens.php which defines a comprehensive set of token constants for PHP 8.1 features (including T\_READONLY, T\_ENUM, T\_ENUM\_CASE, T\_TYPE\_INTERSECTION) alongside backported tokens for older PHP versions.

src/Util · high confidence

PEAR naming convention sniffs added for classes, functions, and variables

The PEAR standard now includes new sniffs to enforce naming conventions for class names, function/method names, and member variables. The ValidClassNameSniff ensures class and interface names start with a capital letter and use underscores as separators. The ValidFunctionNameSniff validates method and function names, including checks for magic methods, private method prefixes, and camelCase formatting. The ValidVariableNameSniff enforces underscore prefixes for private member variables and prevents them on public ones. These changes provide automated style checking for PEAR-compliant code.

src/Standards/PEAR/Sniffs/NamingConventions · high confidence

PEAR standard function sniffs added

The PEAR standard now includes new sniffs for function declarations, function call signatures, and default values. The FunctionDeclarationSniff enforces spacing around the FUNCTION keyword, parentheses, and the USE keyword for closures. The FunctionCallSignatureSniff validates spacing around function calls and handles single and multi-line call formatting. The ValidDefaultValueSniff ensures that function parameters with default values are placed at the end of the argument list.

src/Standards/PEAR/Sniffs/Functions · high confidence

PEAR standard: new ClassDeclaration and IncludingFile sniffs

The PEAR coding standard now includes dedicated sniffs for class declarations and file inclusions. The new ClassDeclarationSniff enforces that opening braces for classes, interfaces, traits, and enums are placed on the line following the declaration, with no extra blank lines, and that the brace is alone on its line. The new IncludingFileSniff enforces the use of include/require\_once in conditional contexts and require/require\_once in unconditional contexts, while also preventing unnecessary parentheses around included files.

src/Standards/PEAR/Sniffs/Classes · high confidence

PSR-1 class declaration sniff added

A new ClassDeclarationSniff has been introduced to enforce PSR-1 standards, ensuring that each class, interface, trait, or enum is defined in its own file and resides within a namespace.

src/Standards/PSR1/Sniffs/Classes · high confidence

Refactored sniffs into a shared abstract base class hierarchy

The PHP\_CodeSniffer library has been refactored to use a new set of abstract base classes (AbstractArraySniff, AbstractPatternSniff, AbstractScopeSniff, AbstractVariableSniff) that provide common functionality for specific types of code analysis. This change introduces a more structured and reusable foundation for implementing new sniffs, allowing developers to extend these abstract classes to handle array, pattern, scope, and variable checks with less boilerplate code.

src/Sniffs · high confidence

Behavioural changes

Centralized exception handling for code analysis

The codebase now uses dedicated exception classes in the PHP\_CodeSniffer\\Exceptions namespace to manage control flow and errors. DeepExitException replaces direct exit() calls to allow the runner to handle exit codes cleanly, while RuntimeException and TokenizerException provide specific error handling for unrecoverable and tokenizer-related issues respectively.

src/Exceptions · high confidence

Enforce modifier keyword ordering and spacing in class and property declarations

The PSR2 coding standard now enforces that the \static\ and \readonly\ modifiers must appear after the visibility declaration on class and property declarations. Additionally, the standard now requires exactly one space between inheritance modifiers (like \abstract\, \final\, \readonly\) and the \class\/\interface\ keyword, and enforces a single space after property type declarations. These changes ensure that code adheres to the PSR-12 and PSR-13 specifications regarding modifier ordering and spacing.

src/Standards/PSR2/Sniffs/Classes · high confidence

Improved support for anonymous classes in core and specific sniffs

The core tokenizer and several sniffs have been updated to properly recognize and handle anonymous classes, ensuring consistent linting and auto-fixing for this PHP feature.

(repo-wide) · high confidence

Introduced new file handling classes for improved caching and STDIN support

The \src/Files\ directory now includes \DummyFile\, \File\, \FileList\, and \LocalFile\ classes. \DummyFile\ handles content without a filesystem path (e.g., STDIN), while \LocalFile\ manages standard files with support for content reloading and caching. \FileList\ manages the iteration of files to be checked. These changes enable more robust handling of STDIN input, better caching of file analysis results, and improved filtering of file lists.

src/Files · high confidence

Major internal refactoring and bug fixes in PHP\_CodeSniffer

The core components of PHP\_CodeSniffer (Config, Fixer, Reporter, Ruleset, Runner) have been significantly refactored to improve stability, performance, and usability. Key changes include: fixing exit codes for PHPCS/PHPCBF to better distinguish between fixable and non-fixable errors; improving the autoloader to correctly handle relative paths and custom namespaces; enhancing the caching system for better performance and accuracy; fixing numerous bugs related to STDIN processing, parallel execution, and report generation; and adding new features like the ability to set array values via CLI, support for custom report classes via FQN, and improved error handling. These changes result in more reliable code analysis and fixing, better performance on large codebases, and more accurate error reporting.

src · high confidence

New and updated naming convention checks for functions and variables

The Squiz standard now includes a new ValidFunctionNameSniff to enforce camel caps for function names, and the existing ValidVariableNameSniff has been updated to validate variable naming in more contexts, including member variables, strings, and object properties. The variable sniff also now correctly handles nullsafe object operators and PHP reserved variables.

src/Standards/Squiz/Sniffs/NamingConventions · high confidence

New naming convention sniffs for abstract classes, interfaces, and traits

The Generic standard now includes new sniffs to enforce naming conventions for abstract classes (AbstractClassNamePrefix), interfaces (InterfaceNameSuffix), and traits (TraitNameSuffix). Additionally, the CamelCapsFunctionName, ConstructorName, and UpperCaseConstantName sniffs have been restructured and expanded: magic methods now include serialize/unserialize, the constructor name sniff better handles nested anonymous classes and PHP 8.1 deprecation notices, and the constant name sniff now supports the PHP 8.0 nullsafe object operator and ignores PHPCS annotation tokens.

src/Standards/Generic/Sniffs/NamingConventions · high confidence

PEAR comment sniffs migrated to new namespace and support modern PHP features

The PEAR comment sniffs (ClassComment, FileComment, FunctionComment, and InlineComment) have been moved into the new \PHP\_CodeSniffer n n nStandards n n nPEAR n n nSniffs n n nCommenting\ namespace. This migration includes support for PHP 8.1 enums and PHP 8.2 readonly classes in the class comment sniff, and adds handling for PHP attributes in function and class comment checks to prevent false positives. The inline comment sniff remains unchanged in behavior but is now part of the restructured directory layout.

src/Standards/PEAR/Sniffs/Commenting · high confidence

PSR1/SideEffects sniff updated to support modern PHP features and disable comments

The PSR1/SideEffects sniff now recognizes PHP 8.1 enums and PHP 8.0 nullsafe object operators as valid symbol declarations, preventing false positives for these constructs. Additionally, the sniff now respects \@phpcs:disable\ annotations, allowing users to selectively disable the check on specific lines or blocks of code.

src/Standards/PSR1/Sniffs/Files · high confidence

Restored Windows batch files for PHP\_CodeSniffer and PHP Code Beautifier

The Windows batch files (phpcs.bat and phpcbf.bat) have been re-added to the bin directory, ensuring that users on Windows can continue to invoke the PHP\_CodeSniffer and PHP Code Beautifier tools via the .bat wrappers. The underlying PHP scripts (phpcs and phpcbf) have been updated to return exit codes from the Runner's runPHPCS() and runPHPCBF() methods, allowing the batch files to correctly propagate the tool's exit status.

bin · high confidence

Squiz comment sniffs support PHP 8.1/8.2+ features and fix fixer conflicts

The Squiz comment sniffs have been updated to support modern PHP syntax, including enums, readonly classes/properties, and match expressions. The \BlockCommentSniff\ now correctly ignores enums and attributes, while \ClosingDeclarationCommentSniff\ and \LongConditionClosingCommentSniff\ recognize enums and match statements respectively. Additionally, several sniffs (\FunctionComment\, \InlineComment\, \PostStatementComment\) have been fixed to prevent false positives with attributes, handle nullable type hints, and resolve fixer conflicts where comments were incorrectly modified or left unfixable.

src/Standards/Squiz/Sniffs/Commenting · high confidence

Squiz whitespace sniffs migrated to PHP\_CodeSniffer 3.x

The Squiz standard's whitespace-related sniffs (including CastSpacing, ControlStructureSpacing, FunctionClosingBraceSpace, FunctionOpeningBraceSpace, FunctionSpacing, LanguageConstructSpacing, LogicalOperatorSpacing, MemberVarSpacing, ObjectOperatorSpacing, OperatorSpacing, PropertyLabelSpacing, and ScopeClosingBrace) have been rewritten for PHP\_CodeSniffer 3.x. This update ensures these sniffs correctly enforce spacing rules for PHP and JavaScript code, with improved handling of fixer conflicts, support for newer language features (such as PHP 8.0/8.1 constructs), and more robust error reporting and auto-fixing capabilities.

src/Standards/Squiz/Sniffs/WhiteSpace · high confidence

Squiz/OperatorBracket: fix false positives and regressions

The Squiz/OperatorBracket sniff has been updated to correctly handle various edge cases that previously caused false positives or failed to fix code properly. Specific improvements include: no longer throwing errors for PHP 7.1 multi-catch exceptions; correctly fixing statements containing strings, short array syntax, and pipe-separated flags; making an exception for match expressions; allowing the nullsafe object operator; and fixing incorrect autofixes for the null coalescing operator and static statements. The sniff now also correctly ignores reference operators and handles unary minus in assignments and comparisons.

src/Standards/Squiz/Sniffs/Formatting · high confidence

Test coverage

Added core unit tests for error suppression and naming conventions; Added integration tests for the Ruleset class; Added test cases for PSR2 ClosingTag and EndFileNewline sniffs; Added test coverage for the Filter::accept method; Added tests for Config reportWidth setting; Added tests for PSR-12 FileHeader, ImportStatement, DeclareStatement, and OpenTag sniffs; Added tests for PSR12 ConstantVisibility sniff; Added tests for PSR12 OperatorSpacing rule; Added tests for Zend/ValidVariableName sniff; Added tests for the AbstractArraySniff class; Added tests for the PSR12 UseDeclaration sniff; Added tests for the autoloader's class name detection; Added tokenizer tests for PHP 8.1 enums, attributes, and explicit octal notation; Added unit tests for ArrayBracketSpacing and ArrayDeclaration sniffs; Added unit tests for CSSLint, ClosureLinter, ESLint, and JSHint; Added unit tests for CyclomaticComplexity and NestingLevel sniffs; Added unit tests for DisallowYodaConditions and InlineControlStructure sniffs; Added unit tests for Generic file sniffs; Added unit tests for Generic naming convention sniffs; Added unit tests for Generic whitespace sniffs; Added unit tests for Generic/DuplicateClassName and Generic/OpeningBraceSameLine sniffs; Added unit tests for Git merge conflict detection; Added unit tests for JSLint and JavaScriptLint sniffs; Added unit tests for PEAR ClassDeclaration sniff; Added unit tests for PEAR ControlSignature and MultiLineCondition sniffs; Added unit tests for PEAR function standards; Added unit tests for PEAR naming conventions; Added unit tests for PHP code standard sniffs; Added unit tests for PSR-12 ControlStructures sniffs; Added unit tests for PSR-12 class formatting sniffs; Added unit tests for PSR-12 function sniffs; Added unit tests for PSR-12 standards; Added unit tests for PSR1 CamelCapsMethodName sniff; Added unit tests for PSR2 ClassDeclaration and PropertyDeclaration sniffs; Added unit tests for PSR2 Method, FunctionCallSignature, and FunctionClosingBrace sniffs; Added unit tests for Squiz PHP standards; Added unit tests for Squiz class-related sniffs; Added unit tests for Squiz comment sniffs; Added unit tests for Squiz control structure sniffs; Added unit tests for Squiz function sniffs; Added unit tests for Squiz object-related sniffs; Added unit tests for Squiz operator sniffs; Added unit tests for Squiz string-related sniffs; Added unit tests for core File class methods; Added unit tests for multiple Generic code analysis sniffs; Added unit tests for multiple Squiz CSS sniffs; Added unit tests for the PEAR IncludingFile sniff; Added unit tests for the Squiz FileExtension sniff; Added unit tests for the Squiz OperatorBracket sniff; Added unit tests for the UnnecessaryStringConcat sniff; Added unit tests for the Zend ClosingTag sniff; Added unit tests for the Zend CodeAnalyzer sniff; Expanded test coverage for PSR1 SideEffects sniff; Expanded test coverage for PSR2 namespace and use declaration rules; New test infrastructure for PHP\_CodeSniffer; Refactored sniff unit test runner to support all installed standards.

Dependencies

Add Composer support for PHP\_CodeSniffer

A new composer.json file has been added to the project, enabling installation via Composer. The package is defined as 'squizlabs/php\_codesniffer' and specifies PHP 5.4.0+ as a requirement, along with the 'ext-tokenizer', 'ext-xmlwriter', and 'ext-simplexml' extensions. It also includes 'phpunit/phpunit' as a dev dependency for testing, and exposes the 'phpcs' and 'phpcbf' scripts as binaries.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 37 → 59 (+22.3)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 56 → 64 (+8.2)
  • Architecture 96 → 96 (+0.6)
  • Maturity 61 → 50 (-10.6)
  • Readiness 14 → 64 (+50.2)
  • Security 52 → 71 (+19.6)

Resolved (179)

  • Config.__construct (cognitive 28) (Config)
  • Config.__construct (cyclomatic 18) (Config)
  • Config.__set (cognitive 26) (Config)
  • Config.processLongArgument (cognitive 1064) (Config)
  • Config.processLongArgument (cyclomatic 114) (Config)
  • Config.processShortArgument (cyclomatic 21) (Config)
  • Config.restoreDefaults (cognitive 19) (Config)
  • Config.restoreDefaults (cyclomatic 17) (Config)
  • Config.setCommandLineValues (cognitive 25) (Config)
  • Config.setConfigData (cognitive 25) (Config)
  • Config.setConfigData (cyclomatic 16) (Config)
  • Coverage not measured — test suite did not build
  • Dimension evaluation failed
  • Duplicated block (10 lines × 2) (src/Ruleset.php)
  • Duplicated block (10 lines × 2) (src/Ruleset.php)
  • Duplicated block (10 lines × 2) (src/Standards/Generic/Sniffs/ControlStructures/InlineControlStructureSniff.php)
  • Duplicated block (10 lines × 2) (src/Standards/Generic/Sniffs/WhiteSpace/ScopeIndentSniff.php)
  • Duplicated block (10 lines × 2) (src/Standards/PEAR/Sniffs/Commenting/FunctionCommentSniff.php)
  • Duplicated block (10 lines × 2) (src/Standards/PEAR/Sniffs/Commenting/FunctionCommentSniff.php)
  • Duplicated block (10 lines × 2) (src/Standards/PEAR/Sniffs/Functions/FunctionDeclarationSniff.php)
  • …and 159 more

New (802)

  • AbstractPatternSniff.parse (cognitive 40) (src/Sniffs/AbstractPatternSniff.php)
  • AbstractPatternSniff.process (cognitive 16) (src/Sniffs/AbstractPatternSniff.php)
  • AbstractPatternSniff.processPattern (cognitive 368) (src/Sniffs/AbstractPatternSniff.php)
  • AbstractPatternSniff.processPattern (cyclomatic 88) (src/Sniffs/AbstractPatternSniff.php)
  • AbstractVariableSniff.processTokenWithinScope (cognitive 28) (src/Sniffs/AbstractVariableSniff.php)
  • AbstractVariableSniff.processTokenWithinScope (cyclomatic 17) (src/Sniffs/AbstractVariableSniff.php)
  • AjaxNullComparisonSniff.process (cognitive 16) (src/Standards/MySource/Sniffs/PHP/AjaxNullComparisonSniff.php)
  • AnonClassDeclarationSniff.process (cognitive 25) (src/Standards/PSR12/Sniffs/Classes/AnonClassDeclarationSniff.php)
  • AnonClassDeclarationSniff.processSingleLineArgumentList (cognitive 40) (src/Standards/PSR12/Sniffs/Classes/AnonClassDeclarationSniff.php)
  • AnonClassDeclarationSniff.processSingleLineArgumentList (cyclomatic 17) (src/Standards/PSR12/Sniffs/Classes/AnonClassDeclarationSniff.php)
  • ArbitraryParenthesesSpacingSniff.process (cognitive 109) (src/Standards/Generic/Sniffs/WhiteSpace/ArbitraryParenthesesSpacingSniff.php)
  • ArbitraryParenthesesSpacingSniff.process (cyclomatic 38) (src/Standards/Generic/Sniffs/WhiteSpace/ArbitraryParenthesesSpacingSniff.php)
  • ArrayDeclarationSniff.process (cognitive 41) (src/Standards/Squiz/Sniffs/Arrays/ArrayDeclarationSniff.php)
  • ArrayDeclarationSniff.processMultiLineArray (cognitive 332) (src/Standards/Squiz/Sniffs/Arrays/ArrayDeclarationSniff.php)
  • ArrayDeclarationSniff.processMultiLineArray (cyclomatic 112) (src/Standards/Squiz/Sniffs/Arrays/ArrayDeclarationSniff.php)
  • ArrayDeclarationSniff.processSingleLineArray (cognitive 80) (src/Standards/Squiz/Sniffs/Arrays/ArrayDeclarationSniff.php)
  • ArrayDeclarationSniff.processSingleLineArray (cyclomatic 28) (src/Standards/Squiz/Sniffs/Arrays/ArrayDeclarationSniff.php)
  • ArrayIndentSniff.processMultiLineArray (cognitive 27) (src/Standards/Generic/Sniffs/Arrays/ArrayIndentSniff.php)
  • AssignmentInConditionSniff.process (cognitive 39) (src/Standards/Generic/Sniffs/CodeAnalysis/AssignmentInConditionSniff.php)
  • AssignmentInConditionSniff.process (cyclomatic 18) (src/Standards/Generic/Sniffs/CodeAnalysis/AssignmentInConditionSniff.php)
  • …and 782 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

squizlabs/PHP_CodeSniffer was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit c6c65ca0dc8608ba87631523b97b2f8d5351a854 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-a15879f6f801.