This package reports potential web application weaknesses during PHPStan analysis. The PHP rules check direct request input at HTML and SQL sinks. The Blade rule checks raw output tags in templates. The rules do not follow data through variables or functions. Use other security checks and code review with these rules.
Install the package with Composer:
composer require --dev perturbatio/phpstan-cweAdd the configuration file to your phpstan.neon:
includes:
- vendor/perturbatio/phpstan-cwe/extension.neonThe default file enables the two PHP rules and the Blade rule. To use one
rule, include cwe79.neon, cwe79-blade.neon, or cwe89.neon instead of
extension.neon.
The Blade rule scans resources/views and its child directories when the
directory exists. It runs when PHPStan analyzes at least one PHP file.
Set other directories in phpstan.neon if necessary:
parameters:
phpstanCwe:
bladeDirectories:
- resources/views
- packages/shop/resources/viewsRelative paths start at the current working directory. Set the list to
[] to stop the Blade scan.
To ignore one Blade raw echo, put a Blade comment immediately before it:
{{-- @phpstan-ignore phpstanCwe.cwe79 (This value is trusted.) --}}
{!! $trustedHtml !!}An ignore with no matching raw echo gets a report. See the Blade rule document for the exact placement.
The default minimum is 0. Set a value from 0 to 100 in phpstan.neon:
parameters:
phpstanCwe:
minProbability: 80Each rule has a probability score of 80. A minimum of 81 stops all
rules from reporting. This score is an estimate of detection confidence,
not a measured probability of an attack. Severity is separate: each initial
rule reports high severity because the possible harm is high.
Each report gives a CWE number, a reason, a severity, a probability score,
and a link to the MITRE CWE site. Reports are ignorable PHPStan errors.
The stable identifiers are phpstanCwe.cwe79 and phpstanCwe.cwe89.
The same data is in the PHPStan error metadata.
Read CWE-79 and CWE-79 in Blade and CWE-89 for examples and limits.
Tests in tests/Unit check the scanner and report data. Tests in
tests/Integration run rules with PHPStan. Rule fixtures are in
tests/fixtures/CWE-79 and tests/fixtures/CWE-89. The fixture used by
both rules is in tests/fixtures/shared.
vendor/bin/pest
vendor/bin/pest --testsuite Unit
vendor/bin/pest --testsuite Integration