larastan/larastan

Larastan - Discover bugs in your code without running it. A phpstan/phpstan extension for Laravel
6,499 69,045,943

calebdw/larastan-livewire

A Larastan / PHPStan extension for Livewire.
61 901,280

tomasvotruba/bladestan

PHPStan rule for static analysis of Blade templates
375 855,490

laraveldaily/filacheck

Static analysis for Filament projects - detect deprecated patterns and code issues
130 149,976

imsuperlative/larastan-filament-macro

PHPStan extension for Filament's Macroable trait — runtime macro method resolution via Larastan.
5 16,257

guanguans/php-cs-fixer-custom-fixers

Use php-cs-fixer to format bats,blade.php,Dockerfile,env,json,md,mdx,sh,sql,tex,text,toml,txt,xml,yaml...files. - 使用 php-cs-fixer 去格式化 bats、blade.php、Dockerfile、env、json、md、mdx、sh、sql、tex、text、toml、txt、xml、yaml...文件。
4 8,380

mfn/phpstan-lost-in-translation

Helps find missing translation strings in Laravel applications
1 5,604

laramint/laravel-security-scanner

Laravel-aware security rules for php-security-scanner. Detects Laravel SQL injection (DB::raw, whereRaw), mass assignment, debug/dd leaks, unsafe validators, CSRF bypass, insecure cookies, env exposure, Blade raw echo, open redirect, Http SSRF, Storage/File path traversal, file-upload validation gaps, Auth/Crypt/Artisan/Process/Config injection, view-name injection, session fixation, and Mail header injection.
3 4,546

adrum/inertia-phpstan

PHPStan extension to validate Inertia.js page existence on disk
8 3,675

odinns/phpstan-pest-this

PHPStan extensions to infer Pest closure $this type from test file mappings.
1 2,235

bnomei/scip-laravel

Laravel-aware SCIP index generation for Laravel applications.
1,813

heyosseus/sloppy

Static analysis for the debt AI coding agents leave behind, on any PHP project: 25 rules, git-diff review, coverage-aware reading order, PHPStan baseline-growth detection, a Rector and Pint fix pass, Pest expectations, CI annotations, agent rulesets and an MCP server. Extra rules and dashboards for Laravel. Deterministic, local, no LLM.
14 931

artflow-studio/laravel-security

Laravel package that scans applications (including Livewire) for security vulnerabilities, reports issues with severity levels, and provides remediation guidance and optional automated fixes.
871

mohamed-ashraf-elsaed/claude-kit

One command sets up Claude Code (and any AI coding agent) on a Laravel project: engineering rules, a quality gate (PHPStan, Pint, Pest), skills, git hooks, and stack-aware frontend tooling.
3 246

prettyyellowdog/lumenstan

Lumenstan - Discover bugs in your code without running it. A phpstan/phpstan wrapper for Lumen based on Larastan
175

seizonio/laravel-php-code-analysis-hook

A GIT pre-commit hook for running php code sniffer, php mess detector and phpunit before a commit can be accepted.
2 74

amarucci/phpstan-laravel-deadcode

Teaches PHPStan's dead code detector to read the wiring Laravel calls and PHP cannot see: Livewire components and their Blade templates, Eloquent enum casts, gate abilities, and package contracts.
41

octane-doctor/octane-doctor

Octane readiness scanner for Laravel: detect long-lived worker risks, explain each finding, and gate CI on new ones.
1 39

goktugcy/worker-safety

Static analysis for PHP applications running on persistent workers. Detect cross-request state risks before they reach production.
7

jakehenshall/pest-plugin-wordpress

The most comprehensive WordPress testing framework built on Pest PHP v4. Includes PHPStan v2.1 for static analysis, SQLite for fast testing, and 150+ helper functions. Test WordPress plugins and themes with Laravel-style syntax. Browser testing, HTTP testing, email mocking, AJAX testing, REST API helpers, test sharding, time travel, and more. Zero configuration required.
1 6

ianrodrigues/pest-plugin-code-quality

Method-level and class-level maintainability limits (complexity, body lines, parameters, methods, properties, inheritance depth) as Pest architecture expectations, with baselines for gradual adoption.
1

msfukui/php-affected

Lists the PHP files that depend on the files you specify. Static analysis with PHP's own tokenizer only - no coverage run, no framework lock-in, no runtime dependencies.
1