Skip to content

PHPStan Rules Extension (Alternative to CLI) ​

In addition to the standalone native CLI (vendor/bin/leakless analyze), the themattosdev/leakless-dev package provides an official PHPStan extension (extension.neon).

This alternative is designed for projects that already run PHPStan in their CI/CD pipeline and prefer consolidating all static analysis into a single invocation (vendor/bin/phpstan analyse), without needing an extra pipeline step.


When to Choose Each Approach? ​

ApproachExecution ModelPerformanceDependenciesBest For
Native CLI (leakless analyze) (Recommended)Pure AST in-memory engineUltra-fast (~milliseconds)Zero heavy dependencies (<20MB RAM)Recommended for most projects; does not require PHPStan.
PHPStan Extension (extension.neon)Integrated into PHPStan pipelineGoverned by PHPStan cacheRequires phpstan/phpstan: ^2.0 in your projectIdeal if your project already uses PHPStan and you want a unified run.

Installing Requirements ​

Because Leakless does not force PHPStan as a hard requirement, add PHPStan to your dev dependencies if you haven't already:

bash
composer require --dev phpstan/phpstan:^2.0

Configuration ​

Include the extension in your phpstan.neon configuration:

yaml
includes:
    - vendor/themattosdev/leakless-dev/extension.neon

parameters:
    level: max
    paths:
        - app
        - src
    ignoreErrors:
        - '#Call to an undefined method Pest\\Expectation.*::(toBeLeakless|toRunCleanly|toResetContainerState|toHaveStatelessInstances)\(\)#'
        - '#Call to an undefined method Illuminate\\Testing\\TestResponse.*::(assertNoDanglingTransactions|assertNoMemoryDrift|assertCleanWorkerState)\(\)#'

If your project utilizes phpstan/extension-installer, extension.neon is automatically discovered and registered without manual inclusion.


Running ​

Run PHPStan normally in your terminal or CI environment:

bash
vendor/bin/phpstan analyse

If any persistent worker rule is breached, PHPStan will report it natively with rule identifiers (e.g. leakless.mutableStaticProperty).


Included Rules ​

Rule ClassIdentifierWhat It Enforces
BanMutableStaticPropertiesRuleleakless.mutableStaticPropertyDisallows mutable static properties on classes unless marked with #[AllowPersistentState] or #[ResetOnRequest].
BanEphemeralInjectionInSingletonsRuleleakless.ephemeralSingletonInjectionPrevents constructor injection of Request / Session in singleton services.
BanSuperglobalsAndTerminatorsRuleleakless.superglobal
leakless.processTerminator
leakless.sessionStart
Blocks direct $_GET, $_POST, $_SESSION, exit(), die(), and session_start().
BanIncompatibleWorkerFunctionsRuleleakless.incompatibleFunction
leakless.globBraceIncompatible
leakless.imapNotThreadSafe
Detects get_browser(), GLOB_BRACE on Alpine musl, ext-imap, and direct procedural headers (setcookie, header).

Static Analysis vs Runtime Registration

Marking a mutable static property with #[ResetOnRequest] informs PHPStan that state cleanup is intended. However, you must also register the class in 'resettables' (in config/leakless.php or via $leakless->registerResetTarget()) so that Leakless actually resets it between requests during runtime execution.

Released under the MIT License.