wp-phpstan
wordpress/agent-skills
Configure and fix PHPStan static analysis in WordPress projects with proper typing and baseline management.
What is wp-phpstan?
PHPStan static analysis skill for WordPress plugins, themes, and sites. Use this when setting up phpstan.neon, generating baselines, fixing type errors with WordPress-specific annotations, and handling third-party plugin classes safely.
- Inspect and discover PHPStan configuration, baseline, and entrypoints in WordPress projects
- Ensure WordPress core stubs (szepeviktor/phpstan-wordpress or php-stubs/wordpress-stubs) are loaded and configured
- Set up focused phpstan.neon with proper paths, excludes, and documented ignoreErrors entries
- Fix PHPStan errors using WordPress-specific typing: REST requests, hook callbacks, database results, and Action Scheduler patterns
- Generate and manage phpstan-baseline.neon as a migration tool to reduce legacy errors over time
- Handle third-party plugin/theme classes with targeted stubs or narrow ignore patterns
How to install wp-phpstan
npx skills add https://github.com/wordpress/agent-skills --skill wp-phpstan- WordPress 7.0+ with PHP 7.4.0+
- Composer-based PHPStan setup in the project
- wp-project-triage output (run first to understand project structure)
- Permission to add/update Composer dev dependencies (for stubs) and modify baselines
How to use wp-phpstan
- 1.Run the PHPStan inspection script: node skills/wp-phpstan/scripts/phpstan_inspect.mjs
- 2.Verify WordPress core stubs are installed (szepeviktor/phpstan-wordpress or php-stubs/wordpress-stubs)
- 3.Review and update phpstan.neon: focus paths on first-party code, exclude vendor/node_modules/tests
- 4.Fix errors by adding WordPress-specific PHPDoc annotations (REST types, hook params, database shapes)
- 5.Add targeted ignoreErrors patterns only for confirmed third-party dependencies
- 6.Generate baseline if needed: vendor/bin/phpstan analyse --generate-baseline
- 7.Run PHPStan to verify: composer run phpstan or vendor/bin/phpstan analyse
Use cases
- Setting up PHPStan for the first time in a WordPress plugin or theme repository
- Fixing type errors in hook callbacks and REST endpoint handlers
- Integrating third-party plugin dependencies (WooCommerce, ACF Pro) with proper stubs
- Migrating legacy WordPress code to strict typing by generating and gradually reducing baselines
- Debugging high error counts by reducing analysis scope and adding proper excludePaths
- WordPress plugin developers
- WordPress theme developers
- Site builders using Composer-based WordPress projects
- Teams adopting static analysis in existing WordPress codebases
wp-phpstan FAQ
Confirm the dependency is installed and autoloaded, or check if a stub package (php-stubs/woocommerce-stubs, php-stubs/acf-pro-stubs) exists. Add a narrow ignore pattern only as a last resort.
No. Generate a baseline only for legacy code as a migration tool, then reduce it over time. Do not baseline newly introduced errors.
Use WP_REST_Request<...> with proper type annotations, and add explicit @param PHPDoc to callback functions.
Reduce the analysis scope by narrowing paths, adding excludePaths for generated/test code, and starting at a lower level before ratcheting up.
Yes, but confirm with the user first. Common stubs include szepeviktor/phpstan-wordpress, php-stubs/woocommerce-stubs, and php-stubs/acf-pro-stubs.
Full instructions (SKILL.md)
Source of truth, from wordpress/agent-skills.
name: wp-phpstan description: "Use when configuring, running, or fixing PHPStan static analysis in WordPress projects (plugins/themes/sites): phpstan.neon setup, baselines, WordPress-specific typing, and handling third-party plugin classes." compatibility: "Targets WordPress 7.0+ (PHP 7.4.0+). Requires Composer-based PHPStan."
WP PHPStan
When to use
Use this skill when working on PHPStan in a WordPress codebase, for example:
- setting up or updating
phpstan.neon/phpstan.neon.dist - generating or updating
phpstan-baseline.neon - fixing PHPStan errors via WordPress-friendly PHPDoc (REST requests, hooks, query results)
- handling third-party plugin/theme classes safely (stubs/autoload/targeted ignores)
Inputs required
wp-project-triageoutput (run first if you haven't)- Whether adding/updating Composer dev dependencies is allowed (stubs).
- Whether changing the baseline is allowed for this task.
Procedure
0) Discover PHPStan entrypoints (deterministic)
- Inspect PHPStan setup (config, baseline, scripts):
node skills/wp-phpstan/scripts/phpstan_inspect.mjs
Prefer the repo’s existing composer script (e.g. composer run phpstan) when present.
1) Ensure WordPress core stubs are loaded
szepeviktor/phpstan-wordpress or php-stubs/wordpress-stubs are effectively required for most WordPress plugin/theme repos. Without it, expect a high volume of errors about unknown WordPress core functions.
- Confirm the package is installed (see
composer.dependenciesin the inspect report). - Ensure the PHPStan config references the stubs (see
references/third-party-classes.md).
2) Ensure a sane phpstan.neon for WordPress projects
- Keep
pathsfocused on first-party code (plugin/theme directories). - Exclude generated and vendored code (
vendor/,node_modules/, build artifacts, tests unless explicitly analyzed). - Keep
ignoreErrorsentries narrow and documented.
See:
references/configuration.md
3) Fix errors with WordPress-specific typing (preferred)
Prefer correcting types over ignoring errors. Common WP patterns that need help:
- REST endpoints: type request parameters using
WP_REST_Request<...> - Hook callbacks: add accurate
@paramtypes for callback args - Database results and iterables: use array shapes or object shapes for query results
- Action Scheduler: type
$argsarray shapes for job callbacks
See:
references/wordpress-annotations.md
4) Handle third-party plugin/theme classes (only when needed)
When integrating with plugins/themes not present in the analysis environment:
- First, confirm the dependency is real (installed/required).
- Prefer plugin-specific stubs already used in the repo (common examples:
php-stubs/woocommerce-stubs,php-stubs/acf-pro-stubs). - If PHPStan still cannot resolve classes, add targeted
ignoreErrorspatterns for the specific vendor prefix.
See:
references/third-party-classes.md
5) Baseline management (use as a migration tool, not a trash bin)
- Generate a baseline once for legacy code, then reduce it over time.
- Do not “baseline” newly introduced errors.
See:
references/configuration.md
Verification
- Run PHPStan using the discovered command (
composer run ...orvendor/bin/phpstan analyse). - Confirm the baseline file (if used) is included and didn’t grow unexpectedly.
- Re-run after changing
ignoreErrorsto ensure patterns are not masking unrelated issues.
Failure modes / debugging
- “Class not found”:
- confirm autoloading/stubs, or add a narrow ignore pattern
- Huge error counts after enabling PHPStan:
- reduce
paths, addexcludePaths, start at a lower level, then ratchet up
- reduce
- Inconsistent types around hooks / REST params:
- add explicit PHPDoc (see references) rather than runtime guards
Escalation
- If a type depends on a third-party plugin API you can’t confirm, ask for the dependency version or source before inventing types.
- If fixing requires adding new Composer dependencies (stubs/extensions), confirm it with the user first.
Related skills
More from wordpress/agent-skills and the wider catalog.

wp-playground
Route WordPress Playground tasks to the right workflow: CLI, browser, debugging, or Blueprint authoring.

wp-plugin-development
Develop WordPress plugins with proper architecture, hooks, security, and lifecycle management.

wp-plugin-directory-guidelines
Reference the 18 WordPress.org Plugin Directory guidelines for GPL compliance, licensing, naming, and submission requirements.

wp-project-triage
Deterministic WordPress repository inspection with structured JSON output for workflow guidance.

wp-rest-api
Build, extend, and debug WordPress REST API endpoints with schema validation, authentication, and custom fields.

wp-wpcli-and-ops
WordPress operations via WP-CLI: safe search-replace, database management, plugin/theme control, and automation.