NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #4546 most downloaded on Packagist
Code-Sniffer, Auto-Fixer and Tokenizer for PSR2-R
Last release 2 months ago
06 Aug 2026
Release timing varies
gaps range from 2 weeks to 4 months
Rarely documented
notes for 10 of 45 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
46 releases · first in 2016
Security: raise the squizlabs/php_codesniffer floor to ^4.0.2 . CVE-2026-67434 , an OS command injection advisory published 2026-08-05, covers >=4.0.0…
Security: raise the squizlabs/php_codesniffer floor to ^4.0.2. CVE-2026-67434, an OS command injection advisory published 2026-08-05, covers >=4.0.0,<4.0.2. The previous constraint allowed an affected version.
Generic.PHP.DeprecatedFunctions was effectively disabled (#45). The ruleset set the sniff's forbiddenFunctions property, which replaces the list the sniff builds in its constructor from the Reflection API rather than adding to it. The standard reported fewer deprecations than plain Generic did - utf8_encode() among them. Removed functions such as create_function() and each() moved to Generic.PHP.ForbiddenFunctions, where a property override is safe.
Both are fully covered by rules the standard already enables, so nothing stops being reported. Only the error codes change, which is why this is a minor rather than a patch - adjust any baseline or phpcs:ignore that names them.
PSR2R.PHP.DuplicateSemicolon (#47), superseded by SlevomatCodingStandard.PHP.UselessSemicolon, which reports everything it did and also catches a stray ; after a block.
PSR2R.WhiteSpace.UnaryOperatorSpacing, superseded by PhpCollective.WhiteSpace.ImplicitCastSpacing together with Generic.WhiteSpace.IncrementDecrementSpacing, both already enabled here. The reference operator was the last construct only the PSR2R sniff handled; php-collective/code-sniffer 0.6.7 covers it, and the floor moves to ^0.6.7 accordingly. The replacement also catches ! $b, which the PSR2R sniff missed.
Most PSR2R rules come from php-collective/code-sniffer. Its 0.6.5 to 0.6.7 releases land here with this bump and carry several fixes to sniffs PSR2R enables, including ConsistentIndent on PHP 8.4 property hooks, attribute names being rewritten as function calls, and DocBlockTagGrouping reporting a fix it never applied.
Full Changelog: 2.8.1...2.9.0
One column per quarter.
Changed PSR2R.PHP.PreferStaticOverSelf to skip self:: usages inside final classes.
PSR2R.PHP.PreferStaticOverSelf to skip self:: usages inside final classes.Universal.CodeAnalysis.StaticInFinalClass, which correctly prefers self:: where late static binding cannot apply.Full Changelog: 2.8.0...2.8.1
PSR2R.Commenting.DocBlock : skip fully-typed methods. Methods whose parameters and return type are all natively typed no longer require a docblock, re
PSR2R.Commenting.DocBlock: skip fully-typed methods. Methods whose parameters and return type are all natively typed no longer require a docblock, reducing noise on modern PHP 8.1+ codebases.PSR2R.WhiteSpace.DocBlockAlignment: avoid a PHPCBF max-loop conflict with PSR2R.WhiteSpace.TabIndent when fixing over-indented docblocks. The fixer now keeps structural docblock indentation tab-based instead of alternating between spaces and tabs. #43php-collective/code-sniffer to ^0.6.0, picking up its upstream fixes (including the DocBlockParamAllowDefaultValue positional-mismatch fix and additional type-safety improvements across sniffs).php-collective/code-sniffer 0.6:
AnonClassKeywordSpacing, FirstClassCallableSpacing, Operators.TypeSeparatorSpacing, Attributes.BracketSpacing, Attributes.DisallowAttributeParentheses, Attributes.TrailingComma, ControlStructures.DisallowAlternativeSyntax, CodeAnalysis.NoEchoSprintf, CodeAnalysis.ConstructorDestructorReturn, CodeAnalysis.ForeachUniqueAssignment, CodeAnalysis.StaticInFinalClassArrays.ArrayAccess, Attributes.AttributeAndTargetSpacing, Attributes.RequireAttributeAfterDocComment, Classes.BackedEnumTypeSpacing, Classes.EnumCaseSpacing, Classes.ClassMemberSpacing, Functions.NamedArgumentSpacing, ControlStructures.LanguageConstructWithParentheses, PHP.ForbiddenClassesPHP.DisallowSizeFunctionsInLoops, WhiteSpace.FunctionOpeningBraceSpaceFull Changelog: 2.7.1...2.8.0
Allow @link and @see as inline doc comment markers
@link and @see as inline doc comment markersFull Changelog: 2.7.0...2.7.1
Fix up new code-sniffer dependency v0.5 compatibility. Adds 1 sniff, removed 1.
Notable change: Attributes are now handled like classes, so no FQCN inside, but normal use statements.
Full Changelog: 2.6.1...2.7.0
Fixed up TabAndSpaceSniff issues
Added PSR2R.WhiteSpace.ArrayDeclarationSpacing sniff
Full Changelog: 2.5.0...2.6.0
Added Squiz.ControlStructures.ForLoopDeclaration sniff
Full Changelog: 2.4.3...2.5.0
Fixes Fixed up UnneededElse sniff
Fixes Added missing if/else sniffs.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →