Skip to content
Back to skills

Php Conventions

ASecurity

PHP code conventions covering PHP 8.2+ strict types, PSR-12 formatting, PHPStan/Psalm static analysis, PHPUnit, Composer dependency management, PSR-4 autoloading, and security. Load when writing or reviewing PHP code.

  • 146 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 5, 2026
ai-agentsphptestingsecurity

Security analysis

A100/100

Scanned October 5, 2026

npx -y skills add Goldziher/ai-rulez --skill php-conventions --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Php Conventions?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Php Conventions
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/goldziher-php-conventions/badge)](https://www.skillsdirectory.com/skills/goldziher-php-conventions)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: php-conventions
description: PHP code conventions covering PHP 8.2+ strict types, PSR-12 formatting, PHPStan/Psalm static analysis, PHPUnit, Composer dependency management, PSR-4 autoloading, and security. Load when writing or reviewing PHP code.
---

- PHP 8.2+, `declare(strict_types=1)`, typed properties, union types, enums, readonly classes.
- Formatting: PSR-12 via a fixer (e.g., PHP_CodeSniffer/phpcbf or php-cs-fixer). Static analysis: a strict analyzer (e.g., PHPStan at max level or Psalm).
- Testing: PHPUnit with `@dataProvider`, 80%+ coverage.
- Error handling: specific exceptions extending `RuntimeException`, constructor promotion for value objects.
- First-class callable syntax (`$fn = strlen(...)`) for callbacks. Arrow functions (`fn() =>`) for simple closures.
- Dependencies: Composer with `composer.lock` committed, `^` version constraints. `composer audit` in CI.
- Security: require `roave/security-advisories` as dev dependency to block vulnerable packages.
- PSR-4 autoloading exclusively — no `require`/`include` for classes.
- Intersection types for strict parameter contracts. Named arguments for readability.
- Anti-patterns: `@` suppression, `eval()`, dynamic property access, `extract()`.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…