Skip to content

Update PHPStan to 2.x and exclude includes/ from analysis - #972

Merged
georgestephanis merged 2 commits into
masterfrom
phpstan-update
Sep 9, 2026
Merged

georgestephanis merged 2 commits into
masterfrom
phpstan-update

Conversation

@masteradhoc

@masteradhoc masteradhoc commented Sep 7, 2026 •

Copy link
Copy Markdown
Collaborator

Why

CI was emitting an upgrade warning on every lint:phpstan run:

You're running an old version of PHPStan. The last release in the 1.12.x series with new features and bugfixes was released on July 17th 2025 [...] Upgrade today to PHPStan 2.2 or newer.

The run also failed with a single error in includes/function.login-footer.php (if.alwaysFalse).

What

  • Bump to PHPStan 2.x — szepeviktor/phpstan-wordpress goes from ^1.3 to ^2.0, which pulls in phpstan/phpstan 2.2.13 (was 1.12.34) and php-stubs/wordpress-stubs 7.1.0 (was 6.9.4). PHPStan itself stays a transitive dependency of the extension.
  • Drop includes/ from the analysed paths — those files are taken over from WordPress core and are already checked upstream. This also resolves the if.alwaysFalse failure without touching code that is intentionally kept close to core.
  • Set treatPhpDocTypesAsCertain: false — PHPStan 2 infers types more aggressively and started reporting alreadyNarrowedType on defensive runtime checks. Runtime values in WordPress are not guaranteed to match the documented PHPDoc types, so the defensive checks stay and the check is relaxed instead.
  • Remove a redundant guard in the settings screen — class_exists( 'Two_Factor_Core' ) && method_exists( 'Two_Factor_Core', 'get_providers' ) is statically always true (the class is loaded unconditionally by two-factor.php). This was the one error not covered by treatPhpDocTypesAsCertain. The is_array() fallback on the return value is kept.

No baseline entries, @phpstan-ignore comments, or type casts were added.

Testing

  • composer lint-phpstan — no errors
  • composer lint (PHPCS) — 22/22 clean
Open WordPress Playground Preview

Bumps szepeviktor/phpstan-wordpress to ^2.0, which pulls in PHPStan 2.2
and the updated WordPress stubs. CI was warning that the 1.12.x series
had been unmaintained for over a year.

The includes/ directory is dropped from the analysed paths: those files
are taken over from WordPress core and are already checked upstream.

PHPStan 2 infers types more aggressively, which surfaced a handful of
alreadyNarrowedType errors. treatPhpDocTypesAsCertain is disabled since
runtime values in WordPress are not guaranteed to match documented
types, and the redundant class_exists()/method_exists() guard around
Two_Factor_Core::get_providers() is removed.
@github-actions

github-actions Bot commented Sep 8, 2026

Copy link
Copy Markdown

The following accounts have interacted with this PR and/or linked issues. I will continue to update these lists as activity occurs. You can also manually ask me to refresh this list by adding the props-bot label.

If you're merging code through a pull request on GitHub, copy and paste the following into the bottom of the merge commit message.

Co-authored-by: masteradhoc <masteradhoc@git.wordpress.org>

To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook.

@masteradhoc masteradhoc self-assigned this Sep 8, 2026
@masteradhoc masteradhoc added this to the 0.17.0 milestone Sep 8, 2026
@masteradhoc

Copy link
Copy Markdown
Collaborator Author

after merging the PR #974 of @georgestephanis this is green now. ready for a review!

@georgestephanis
georgestephanis merged commit 90d24f0 into master Sep 9, 2026
24 checks passed
@georgestephanis
georgestephanis deleted the phpstan-update branch September 9, 2026 16:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants