PHP Static Analysis Tool - discover bugs in your code without running it!
$ npx skills add phpstan/phpstanAlternatives
Compare similar skills by workflow fit, trust score, quality, GitHub adoption, maintenance, and install readiness.
Current skill
Static Value-Flow Analysis Framework for Source Code
PHP Static Analysis Tool - discover bugs in your code without running it!
$ npx skills add phpstan/phpstan🔍 A Hex Editor for Reverse Engineers, Programmers and people who value their retinas when working at 3 AM.
$ npx skills add WerWolv/ImHexA LLVM-based static analysis framework.
$ npx skills add secure-software-engineering/phasarValidate and visualize dependencies. Your rules. JavaScript, TypeScript, CoffeeScript. ES6, CommonJS, AMD.
$ npx skills add sverweij/dependency-cruiserA static code analysis tool for the Elixir language with a focus on code consistency and teaching.
$ npx skills add rrrene/credoSpotBugs is FindBugs' successor. A tool for static analysis to look for bugs in Java code.
$ npx skills add spotbugs/spotbugsAn extensible multilanguage static code analyzer.
$ npx skills add pmd/pmdPHPMD is a spin-off project of PHP Depend and aims to be a PHP equivalent of the well known Java tool PMD. PHPMD can be seen as an user friendly frontend application for the raw metrics stream measured by PHP Depend.
$ npx skills add phpmd/phpmdThe SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects)
$ npx skills add find-sec-bugs/find-sec-bugsstatic analysis of C/C++ code
$ npx skills add cppcheck-opensource/cppcheckCodeCompass is a software comprehension tool for large scale software written in C/C++, C# and Python.
$ npx skills add Ericsson/CodeCompassNext-gen phpDoc parser with support for intersection types and generics
$ npx skills add phpstan/phpdoc-parserSpoon is a metaprogramming library to analyze and transform Java source code. :spoon: is made with :heart:, :beers: and :sparkles:. It parses source files to build a well-designed AST with powerful analysis and transformation API.
$ npx skills add INRIA/spoonAn Intelligent Python Code Quality Analyzer
$ npx skills add ludo-technologies/pyscnStatic analyzer for C/C++ based on the theory of Abstract Interpretation.
$ npx skills add NASA-SW-VnV/ikosSonarSource Static Analyzer for JavaScript and TypeScript
$ npx skills add SonarSource/SonarJSHow to choose
Use an alternative when it has a clearer install path, higher trust score, fresher maintenance, or better platform fit for your current agent stack. Keep SVF if it already passes your workflow test and repository review.
Next step
Open the compare page, test the install commands in a sandbox, and check each repository before using a skill in production.