wp-phpstan

PHPStan-Konfiguration, Fehlerbehebung und Baseline-Verwaltung für WordPress-Projekte. Behandelt WordPress-spezifische Typisierungsmuster: REST-Endpunkte mit WP_REST_Request, Hook-Callbacks mit präzisen @param-Typen, Datenbankergebnisse und Action-Scheduler-Job-Argumente. Verwaltet die Auflösung von Drittanbieter-Plugin/Theme-Klassen über Stubs (php-stubs/woocommerce-stubs, php-stubs/acf-pro-stubs) und gezielte Ignorier-Muster. Bietet deterministische PHPStan-Erkennung, Konfigurationsvalidierung, Baseline...

npx skills add https://github.com/wordpress/agent-skills --skill wp-phpstan

WP PHPStan

When to use

Use this skill when working on PHPStan in a WordPress codebase, for example:

  • setting up or updating phpstan.neon / phpstan.neon.dist
  • generating or updating phpstan-baseline.neon
  • fixing PHPStan errors via WordPress-friendly PHPDoc (REST requests, hooks, query results)
  • handling third-party plugin/theme classes safely (stubs/autoload/targeted ignores)

Inputs required

  • wp-project-triage output (run first if you haven't)
  • Whether adding/updating Composer dev dependencies is allowed (stubs).
  • Whether changing the baseline is allowed for this task.

Procedure

0) Discover PHPStan entrypoints (deterministic)

  1. Inspect PHPStan setup (config, baseline, scripts):
    • node skills/wp-phpstan/scripts/phpstan_inspect.mjs

Prefer the repo’s existing composer script (e.g. composer run phpstan) when present.

1) Ensure WordPress core stubs are loaded

szepeviktor/phpstan-wordpress or php-stubs/wordpress-stubs are effectively required for most WordPress plugin/theme repos. Without it, expect a high volume of errors about unknown WordPress core functions.

  • Confirm the package is installed (see composer.dependencies in the inspect report).
  • Ensure the PHPStan config references the stubs (see references/third-party-classes.md).

2) Ensure a sane phpstan.neon for WordPress projects

  • Keep paths focused on first-party code (plugin/theme directories).
  • Exclude generated and vendored code (vendor/, node_modules/, build artifacts, tests unless explicitly analyzed).
  • Keep ignoreErrors entries narrow and documented.

See:

  • references/configuration.md

3) Fix errors with WordPress-specific typing (preferred)

Prefer correcting types over ignoring errors. Common WP patterns that need help:

  • REST endpoints: type request parameters using WP_REST_Request<...>
  • Hook callbacks: add accurate @param types for callback args
  • Database results and iterables: use array shapes or object shapes for query results
  • Action Scheduler: type $args array shapes for job callbacks

See:

  • references/wordpress-annotations.md

4) Handle third-party plugin/theme classes (only when needed)

When integrating with plugins/themes not present in the analysis environment:

  • First, confirm the dependency is real (installed/required).
  • Prefer plugin-specific stubs already used in the repo (common examples: php-stubs/woocommerce-stubs, php-stubs/acf-pro-stubs).
  • If PHPStan still cannot resolve classes, add targeted ignoreErrors patterns for the specific vendor prefix.

See:

  • references/third-party-classes.md

5) Baseline management (use as a migration tool, not a trash bin)

  • Generate a baseline once for legacy code, then reduce it over time.
  • Do not “baseline” newly introduced errors.

See:

  • references/configuration.md

Verification

  • Run PHPStan using the discovered command (composer run ... or vendor/bin/phpstan analyse).
  • Confirm the baseline file (if used) is included and didn’t grow unexpectedly.
  • Re-run after changing ignoreErrors to ensure patterns are not masking unrelated issues.

Failure modes / debugging

  • “Class not found”:
    • confirm autoloading/stubs, or add a narrow ignore pattern
  • Huge error counts after enabling PHPStan:
    • reduce paths, add excludePaths, start at a lower level, then ratchet up
  • Inconsistent types around hooks / REST params:
    • add explicit PHPDoc (see references) rather than runtime guards

Escalation

  • If a type depends on a third-party plugin API you can’t confirm, ask for the dependency version or source before inventing types.
  • If fixing requires adding new Composer dependencies (stubs/extensions), confirm it with the user first.

Mehr Skills von wordpress

blueprint
wordpress
Verwenden beim Erstellen, Bearbeiten oder Überprüfen von WordPress Playground Blueprint JSON-Dateien. Wird bei Erwähnungen von Blueprints, Playground-Konfiguration oder Anfragen ausgelöst…
official
wordpress-router
wordpress
Klassifiziere WordPress-Codebasen und leite an den korrekten Workflow für Plugins, Themes, Blöcke und Core-Checkouts weiter. Führt automatisiertes Projekt-Triage durch, um den Repo-Typ (Plugin, Theme, Block-Theme, Gutenberg-Blöcke, WP-Core) und verfügbare Werkzeuge zu identifizieren. Gibt Klassifikationsergebnisse und Entscheidungsbaum-Routing an domänenspezifische Skills basierend auf Benutzerabsicht und Projektart aus. Erfordert Repo-Root-Zugriff sowie Bash/Node-Dateisystemoperationen; einige Workflows benötigen WP-CLI. Zielgruppe: WordPress 6.9+ mit PHP 7.2.24+;...
official
wp-abilities-api
wordpress
WordPress-Abilities-API-Registrierung, REST-Bereitstellung und clientseitige Nutzung für WordPress 6.9+. Registrieren Sie Abilities und Kategorien in PHP mit wp_register_ability() und wp_register_ability_category() mit stabilen IDs, Labels und Metadaten. Stellen Sie Abilities Clients über die /wp-json/wp-abilities/v1/ REST-Endpunkte zur Verfügung, indem Sie meta.show_in_rest: true setzen. Nutzen Sie Abilities in JavaScript mit dem @wordpress/abilities-Paket für clientseitigen Zugriff und Berechtigungsprüfungen. Erfordert WordPress 6.9+...
official
wp-abilities-audit
wordpress
Audit a WordPress plugin's REST surface and produce a standardized audit document proposing Abilities API registrations. Produces a markdown doc with a YAML…
official
wp-abilities-verify
wordpress
Überprüfe die Abilities-API-Registrierungen eines WordPress-Plugins: Fähigkeiten auflisten, prüfen, ob das Callback-Verhalten mit der Behauptung jeder Annotation übereinstimmt (die adversariale…
official
wp-block-development
wordpress
WordPress-Block-Entwicklung für Gutenberg: Metadaten, Registrierung, Rendering und Build-Workflows. Behandelt Block-Erstellung, block.json-Konfiguration, statisches vs. dynamisches Rendering und serverseitige PHP-Registrierung mit register_block_type_from_metadata(). Erzwingt apiVersion: 3 für WordPress 6.9+-Kompatibilität, einschließlich iframe-Editor-Unterstützung und Stilisolierung. Behandelt Attributserialisierung, Deprecations/Migrationen zur Vermeidung von "Invalid block"-Fehlern und die Zusammensetzung innerer Blöcke. Enthält...
official
wp-block-themes
wordpress
WordPress-Block-Theme-Entwicklung: theme.json, Vorlagen, Patterns und Fehlerbehebung im Site-Editor. Behandelt theme.json-Bearbeitung (Voreinstellungen, Einstellungen, blockbezogene Stile), Vorlagen und Vorlagenteile, Patterns sowie Stilvarianten ab WordPress 6.9+. Enthält Triage-Skripte zur Erkennung von Theme-Wurzeln und Block-Theme-Strukturen sowie geführte Verfahren zur Erstellung neuer Themes oder zur Umwandlung klassischer Themes. Bietet Debugging-Workflows für Probleme mit der Stilhierarchie, Überschreibungen durch Benutzeranpassungen und den Site...
official
wp-interactivity-api
wordpress
Verwenden beim Erstellen oder Debuggen von WordPress Interactivity API-Funktionen (data-wp-*-Direktiven, @wordpress/interactivity store/state/actions, block viewScriptModule…
official