Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
wordpress avatar

Wp Phpstan

  • 2.5k installs
  • 1.9k repo stars
  • Updated July 27, 2026
  • wordpress/agent-skills

wp-phpstan sets up and fixes PHPStan analysis for WordPress plugins and themes with stubs and baselines.

About

The wp-phpstan skill configures and fixes PHPStan static analysis for WordPress codebases targeting WordPress 6.9 plus with Composer-based PHPStan. Procedure starts with phpstan_inspect.mjs to discover config, baseline, and composer scripts, preferring existing composer run phpstan when present. WordPress core stubs via szepeviktor/phpstan-wordpress or php-stubs/wordpress-stubs are effectively required to avoid unknown function noise. Sane phpstan.neon keeps paths on first-party plugin or theme code, excludes vendor and build artifacts, and documents narrow ignoreErrors entries. Fixes prefer WordPress-specific PHPDoc for REST WP_REST_Request types, hook callback params, query result shapes, and Action Scheduler job args. Third-party plugin classes use real dependency confirmation, plugin stubs like woocommerce-stubs, then targeted ignoreErrors prefixes. Baselines are migration tools not trash bins; do not baseline newly introduced errors. Escalation asks for dependency versions before inventing third-party types. Verification reruns PHPStan after any ignoreErrors pattern changes.

  • Run phpstan_inspect.mjs first to discover config and composer entrypoints.
  • WordPress stubs are required to avoid mass unknown-function errors.
  • Prefer PHPDoc fixes over ignoreErrors for REST and hook callbacks.
  • Third-party classes use stubs then narrow vendor-prefix ignores.
  • Baselines reduce legacy debt; never baseline new errors.

Wp Phpstan by the numbers

  • 2,517 all-time installs (skills.sh)
  • +163 installs in the week ending Jul 28, 2026 (Skillselion tracking)
  • Ranked #328 of 2,184 Testing & QA skills by installs in the Skillselion catalog
  • Security screen: MEDIUM risk (skills.sh audit)
  • Data as of Jul 28, 2026 (Skillselion catalog sync)
At a glance

wp-phpstan capabilities & compatibility

Capabilities
phpstan_inspect.mjs deterministic setup discover · wordpress core stub requirement and config guida · rest, hook, and query phpdoc typing patterns · third party plugin stub and ignoreerrors strateg · baseline migration rules and verification steps
Use cases
testing · code review
From the docs

What wp-phpstan says it does

Without it, expect a high volume of errors about unknown WordPress core functions.
SKILL.md
Prefer correcting types over ignoring errors.
SKILL.md
npx skills add https://github.com/wordpress/agent-skills --skill wp-phpstan

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs2.5k
repo stars1.9k
Security audit3 / 3 scanners passed
Last updatedJuly 27, 2026
Repositorywordpress/agent-skills

How do I run PHPStan on WordPress code without drowning in core function errors?

Configure, run, and fix PHPStan static analysis in WordPress plugins, themes, and sites with stubs and baselines.

Who is it for?

WordPress plugin and theme repos adding or fixing PHPStan with Composer.

Skip if: Skip for non-PHP WordPress work or projects disallowing Composer dev dependencies without approval.

When should I use this skill?

User configures phpstan.neon, fixes PHPStan errors, or handles third-party WP plugin classes.

What you get

Working phpstan.neon, reduced errors via typing, and controlled baseline for legacy code.

  • phpstan.neon configuration
  • phpstan-baseline.neon
  • Fixed static analysis errors

By the numbers

  • Targets WordPress 6.9+ on PHP 7.2.24+
  • Requires Composer-based PHPStan installation

Files

SKILL.mdMarkdownGitHub ↗

WP PHPStan

When to use

Use this skill when working on PHPStan in a WordPress codebase, for example:

  • setting up or updating phpstan.neon / phpstan.neon.dist
  • generating or updating phpstan-baseline.neon
  • fixing PHPStan errors via WordPress-friendly PHPDoc (REST requests, hooks, query results)
  • handling third-party plugin/theme classes safely (stubs/autoload/targeted ignores)

Inputs required

  • wp-project-triage output (run first if you haven't)
  • Whether adding/updating Composer dev dependencies is allowed (stubs).
  • Whether changing the baseline is allowed for this task.

Procedure

0) Discover PHPStan entrypoints (deterministic)

1. Inspect PHPStan setup (config, baseline, scripts):

  • node skills/wp-phpstan/scripts/phpstan_inspect.mjs

Prefer the repo’s existing composer script (e.g. composer run phpstan) when present.

1) Ensure WordPress core stubs are loaded

szepeviktor/phpstan-wordpress or php-stubs/wordpress-stubs are effectively required for most WordPress plugin/theme repos. Without it, expect a high volume of errors about unknown WordPress core functions.

  • Confirm the package is installed (see composer.dependencies in the inspect report).
  • Ensure the PHPStan config references the stubs (see references/third-party-classes.md).

2) Ensure a sane phpstan.neon for WordPress projects

  • Keep paths focused on first-party code (plugin/theme directories).
  • Exclude generated and vendored code (vendor/, node_modules/, build artifacts, tests unless explicitly analyzed).
  • Keep ignoreErrors entries narrow and documented.

See:

  • references/configuration.md

3) Fix errors with WordPress-specific typing (preferred)

Prefer correcting types over ignoring errors. Common WP patterns that need help:

  • REST endpoints: type request parameters using WP_REST_Request<...>
  • Hook callbacks: add accurate @param types for callback args
  • Database results and iterables: use array shapes or object shapes for query results
  • Action Scheduler: type $args array shapes for job callbacks

See:

  • references/wordpress-annotations.md

4) Handle third-party plugin/theme classes (only when needed)

When integrating with plugins/themes not present in the analysis environment:

  • First, confirm the dependency is real (installed/required).
  • Prefer plugin-specific stubs already used in the repo (common examples: php-stubs/woocommerce-stubs, php-stubs/acf-pro-stubs).
  • If PHPStan still cannot resolve classes, add targeted ignoreErrors patterns for the specific vendor prefix.

See:

  • references/third-party-classes.md

5) Baseline management (use as a migration tool, not a trash bin)

  • Generate a baseline once for legacy code, then reduce it over time.
  • Do not “baseline” newly introduced errors.

See:

  • references/configuration.md

Verification

  • Run PHPStan using the discovered command (composer run ... or vendor/bin/phpstan analyse).
  • Confirm the baseline file (if used) is included and didn’t grow unexpectedly.
  • Re-run after changing ignoreErrors to ensure patterns are not masking unrelated issues.

Failure modes / debugging

  • “Class not found”:
  • confirm autoloading/stubs, or add a narrow ignore pattern
  • Huge error counts after enabling PHPStan:
  • reduce paths, add excludePaths, start at a lower level, then ratchet up
  • Inconsistent types around hooks / REST params:
  • add explicit PHPDoc (see references) rather than runtime guards

Escalation

  • If a type depends on a third-party plugin API you can’t confirm, ask for the dependency version or source before inventing types.
  • If fixing requires adding new Composer dependencies (stubs/extensions), confirm it with the user first.

Related skills

How it compares

Use wp-phpstan for WordPress-specific PHPStan setup and fixes; generic PHPStan guides lack WordPress hook, REST, and third-party plugin class patterns.

FAQ

Are WordPress stubs optional?

Effectively required; without stubs expect high volume of unknown WordPress core function errors.

How should third-party plugin classes be handled?

Confirm the dependency, try plugin stubs, then add narrow ignoreErrors for the vendor prefix.

When is a baseline appropriate?

Once for legacy code migration, then shrink over time; never for newly introduced errors.

Is Wp Phpstan safe to install?

skills.sh reports 3 of 3 security scanners passed. Review the Security Audits panel on this page before installing in production.

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.