PluginBench
Skill
Official
Review
Audit score 70

wp-phpstan

wordpress/agent-skills

Configure and fix PHPStan static analysis in WordPress projects with proper typing and baseline management.

What is wp-phpstan?

PHPStan static analysis skill for WordPress plugins, themes, and sites. Use this when setting up phpstan.neon, generating baselines, fixing type errors with WordPress-specific annotations, and handling third-party plugin classes safely.

  • Inspect and discover PHPStan configuration, baseline, and entrypoints in WordPress projects
  • Ensure WordPress core stubs (szepeviktor/phpstan-wordpress or php-stubs/wordpress-stubs) are loaded and configured
  • Set up focused phpstan.neon with proper paths, excludes, and documented ignoreErrors entries
  • Fix PHPStan errors using WordPress-specific typing: REST requests, hook callbacks, database results, and Action Scheduler patterns
  • Generate and manage phpstan-baseline.neon as a migration tool to reduce legacy errors over time
  • Handle third-party plugin/theme classes with targeted stubs or narrow ignore patterns

How to install wp-phpstan

npx skills add https://github.com/wordpress/agent-skills --skill wp-phpstan
Prerequisites
  • WordPress 7.0+ with PHP 7.4.0+
  • Composer-based PHPStan setup in the project
  • wp-project-triage output (run first to understand project structure)
  • Permission to add/update Composer dev dependencies (for stubs) and modify baselines
Claude Code
Cursor
Windsurf
Cline

How to use wp-phpstan

  1. 1.Run the PHPStan inspection script: node skills/wp-phpstan/scripts/phpstan_inspect.mjs
  2. 2.Verify WordPress core stubs are installed (szepeviktor/phpstan-wordpress or php-stubs/wordpress-stubs)
  3. 3.Review and update phpstan.neon: focus paths on first-party code, exclude vendor/node_modules/tests
  4. 4.Fix errors by adding WordPress-specific PHPDoc annotations (REST types, hook params, database shapes)
  5. 5.Add targeted ignoreErrors patterns only for confirmed third-party dependencies
  6. 6.Generate baseline if needed: vendor/bin/phpstan analyse --generate-baseline
  7. 7.Run PHPStan to verify: composer run phpstan or vendor/bin/phpstan analyse

Use cases

Good for
  • Setting up PHPStan for the first time in a WordPress plugin or theme repository
  • Fixing type errors in hook callbacks and REST endpoint handlers
  • Integrating third-party plugin dependencies (WooCommerce, ACF Pro) with proper stubs
  • Migrating legacy WordPress code to strict typing by generating and gradually reducing baselines
  • Debugging high error counts by reducing analysis scope and adding proper excludePaths
Who it's for
  • WordPress plugin developers
  • WordPress theme developers
  • Site builders using Composer-based WordPress projects
  • Teams adopting static analysis in existing WordPress codebases

wp-phpstan FAQ

What if I see 'Class not found' errors?

Confirm the dependency is installed and autoloaded, or check if a stub package (php-stubs/woocommerce-stubs, php-stubs/acf-pro-stubs) exists. Add a narrow ignore pattern only as a last resort.

Should I baseline all errors to get started?

No. Generate a baseline only for legacy code as a migration tool, then reduce it over time. Do not baseline newly introduced errors.

How do I type REST endpoint parameters?

Use WP_REST_Request<...> with proper type annotations, and add explicit @param PHPDoc to callback functions.

What if PHPStan reports too many errors?

Reduce the analysis scope by narrowing paths, adding excludePaths for generated/test code, and starting at a lower level before ratcheting up.

Can I add new Composer dependencies for stubs?

Yes, but confirm with the user first. Common stubs include szepeviktor/phpstan-wordpress, php-stubs/woocommerce-stubs, and php-stubs/acf-pro-stubs.

Full instructions (SKILL.md)

Source of truth, from wordpress/agent-skills.


name: wp-phpstan description: "Use when configuring, running, or fixing PHPStan static analysis in WordPress projects (plugins/themes/sites): phpstan.neon setup, baselines, WordPress-specific typing, and handling third-party plugin classes." compatibility: "Targets WordPress 7.0+ (PHP 7.4.0+). Requires Composer-based PHPStan."

WP PHPStan

When to use

Use this skill when working on PHPStan in a WordPress codebase, for example:

  • setting up or updating phpstan.neon / phpstan.neon.dist
  • generating or updating phpstan-baseline.neon
  • fixing PHPStan errors via WordPress-friendly PHPDoc (REST requests, hooks, query results)
  • handling third-party plugin/theme classes safely (stubs/autoload/targeted ignores)

Inputs required

  • wp-project-triage output (run first if you haven't)
  • Whether adding/updating Composer dev dependencies is allowed (stubs).
  • Whether changing the baseline is allowed for this task.

Procedure

0) Discover PHPStan entrypoints (deterministic)

  1. Inspect PHPStan setup (config, baseline, scripts):
    • node skills/wp-phpstan/scripts/phpstan_inspect.mjs

Prefer the repo’s existing composer script (e.g. composer run phpstan) when present.

1) Ensure WordPress core stubs are loaded

szepeviktor/phpstan-wordpress or php-stubs/wordpress-stubs are effectively required for most WordPress plugin/theme repos. Without it, expect a high volume of errors about unknown WordPress core functions.

  • Confirm the package is installed (see composer.dependencies in the inspect report).
  • Ensure the PHPStan config references the stubs (see references/third-party-classes.md).

2) Ensure a sane phpstan.neon for WordPress projects

  • Keep paths focused on first-party code (plugin/theme directories).
  • Exclude generated and vendored code (vendor/, node_modules/, build artifacts, tests unless explicitly analyzed).
  • Keep ignoreErrors entries narrow and documented.

See:

  • references/configuration.md

3) Fix errors with WordPress-specific typing (preferred)

Prefer correcting types over ignoring errors. Common WP patterns that need help:

  • REST endpoints: type request parameters using WP_REST_Request<...>
  • Hook callbacks: add accurate @param types for callback args
  • Database results and iterables: use array shapes or object shapes for query results
  • Action Scheduler: type $args array shapes for job callbacks

See:

  • references/wordpress-annotations.md

4) Handle third-party plugin/theme classes (only when needed)

When integrating with plugins/themes not present in the analysis environment:

  • First, confirm the dependency is real (installed/required).
  • Prefer plugin-specific stubs already used in the repo (common examples: php-stubs/woocommerce-stubs, php-stubs/acf-pro-stubs).
  • If PHPStan still cannot resolve classes, add targeted ignoreErrors patterns for the specific vendor prefix.

See:

  • references/third-party-classes.md

5) Baseline management (use as a migration tool, not a trash bin)

  • Generate a baseline once for legacy code, then reduce it over time.
  • Do not “baseline” newly introduced errors.

See:

  • references/configuration.md

Verification

  • Run PHPStan using the discovered command (composer run ... or vendor/bin/phpstan analyse).
  • Confirm the baseline file (if used) is included and didn’t grow unexpectedly.
  • Re-run after changing ignoreErrors to ensure patterns are not masking unrelated issues.

Failure modes / debugging

  • “Class not found”:
    • confirm autoloading/stubs, or add a narrow ignore pattern
  • Huge error counts after enabling PHPStan:
    • reduce paths, add excludePaths, start at a lower level, then ratchet up
  • Inconsistent types around hooks / REST params:
    • add explicit PHPDoc (see references) rather than runtime guards

Escalation

  • If a type depends on a third-party plugin API you can’t confirm, ask for the dependency version or source before inventing types.
  • If fixing requires adding new Composer dependencies (stubs/extensions), confirm it with the user first.