Conversation
There was a problem hiding this comment.
🟡 Changes recommended
PHPStan 2.x must be isolated or made compatible with the PHP 7.4 Composer jobs.
Get a fresh assessment by requesting another Copilot review.
Pull request overview
Adds PHPStan level 6 analysis with WordPress/WP-CLI stubs, a baseline, CI integration, and documentation. A critical PHP 7.4 Composer compatibility issue remains.
Changes:
- Adds PHPStan dependencies and the
composer analyzescript. - Adds configuration, bootstrap, and WP-CLI stubs.
- Adds CI enforcement and documentation.
- Excludes analysis files from exports.
File summaries
| File | Summary |
|---|---|
tests/phpstan/stubs/wp-cli.php |
Provides WP-CLI class stubs. |
tests/phpstan/stubs/wp-cli-utils.php |
Provides WP-CLI utility stubs. |
tests/phpstan/bootstrap.php |
Defines runtime constants for analysis. |
phpstan.neon.dist |
Configures PHPStan analysis. |
docs/code-linting.md |
Documents PHPStan usage. |
composer.json |
Adds PHPStan dependencies and analysis script; PHPStan 2.x conflicts with PHP 7.4 Composer jobs. |
.github/workflows/phpstan.yml |
Runs PHPStan in CI. |
.gitattributes |
Excludes analysis files from exports. |
Review details
- Files reviewed: 8/9 changed files
- Comments generated: 1
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
pfefferle
force-pushed
the
add/static-analysis
branch
from
September 30, 2026 11:02
9c4d8ac to
10f1c8a
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Proposed changes:
composer analyzeruns it locally.@return void, 15 with their real type, all checked by PHPStan against the return statements. That surfaced three things worth fixing on the way:Screen_Options::initwas hooked withadd_filter( 'init' )instead ofadd_action,Update::handle_update()returned the result of the voidCreate::handle_create(), and the welcome checklist passed two ints toesc_html().add_post_meta expects int, string given, an undefinedGeneric_Object::get_id(), conditions that are always true) to work through file by file. Fixing a listed finding does not fail the run (reportUnmatchedIgnoredErrors: false), andcomposer analyze:baselineregenerates the file. Array value types (array<string, mixed>) are not required; that rule alone accounted for 936 findings WordPress-style docblocks never carry.integration/only (other plugins), and the Stream connector excluded because it extends a class from that plugin. A small WP-CLI stub covers the eight calls the CLI code makes; the official WP-CLI stubs only work with WordPress stubs up to 6.x.docs/code-linting.mdhas a section on it.This is the first step of typing the collection classes; the next PR types
Inboxas the template.Other information:
Testing instructions:
composer install && composer analyzereports no errors.includes/and run it again: it fails.Changelog entry
Skip Changelog, tooling only.
Changelog Entry Details
Significance
Type
Message