Skip to content
Back to skills

Write Safe Idiomatic Php

ASecurity

Write solid PHP avoiding type juggling traps, array quirks, and common security pitfalls.

  • 19 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 19, 2026
ai-agentsgophpsqldebuggingsecurity

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned September 19, 2026

npx -y skills add rondoflow/rondoflow --skill write-safe-idiomatic-php --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Write Safe Idiomatic Php?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Write Safe Idiomatic Php
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/rondoflow-write-safe-idiomatic-php/badge)](https://www.skillsdirectory.com/skills/rondoflow-write-safe-idiomatic-php)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: write-safe-idiomatic-php
description: "Write solid PHP avoiding type juggling traps, array quirks, and common security pitfalls."
category: "Content & Writing"
author: community
version: "1.0.1"
icon: pencil
---

## Quick Reference

| Topic | File |
|-------|------|
| Loose typing, ==, ===, type juggling, strict_types | `types.md` |
| Associative arrays, iteration, array functions | `arrays.md` |
| Traits, interfaces, visibility, late static binding | `oop.md` |
| Encoding, interpolation, heredoc, regex | `strings.md` |
| Exceptions, error handling, @ operator | `errors.md` |
| SQL injection, XSS, CSRF, input validation | `security.md` |
| PHP 8+ features, attributes, named args, match | `modern.md` |

## Critical Rules

- `==` coerces types: `"0" == false` is true — always use `===` for strict comparison
- `in_array($val, $arr)` uses loose comparison — pass `true` as third param for strict
- `strpos()` returns 0 for match at start — use `=== false` not `!strpos()`
- Never concatenate SQL — use prepared statements with PDO
- `htmlspecialchars($s, ENT_QUOTES)` all output — prevents XSS
- `isset()` returns false for null — use `array_key_exists()` to check key exists
- `foreach ($arr as &$val)` — unset `$val` after loop or last ref persists
- `static::` late binding vs `self::` early binding — `static` respects overrides
- `@` suppresses errors — avoid, makes debugging impossible
- Catch `Throwable` for both `Error` and `Exception` — PHP 7+
- `declare(strict_types=1)` per file — enables strict type checking
- `strlen()` counts bytes — use `mb_strlen()` for UTF-8 character count
- Objects pass by reference-like handle — clone explicitly with `clone $obj`
- `array_merge()` reindexes numeric keys — use `+` operator to preserve keys

Files in this skill

  • SKILL.md1.8 KB
  • manifest.json306 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…