NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #5240 most downloaded on Packagist
A Phan plugin to do security checking
Last release 5 months ago
28 Apr 2026
Release timing varies
gaps range from 3 weeks to 1.1 years
Nearly every release is documented
notes for 35 of 35 stable releases
Nothing withdrawn
no release was ever pulled
9 years old
35 releases · first in 2017
Added support for array_first, array_last, array_find, and array_find_key
array_first, array_last, array_find, and array_find_keyAdded support for PHP 8.5's pipe operator
One column per quarter.
Bumped phan/phan to 6.0.1. This is a new major version for phan.
(MW) Dropped support for legacy hook handler styles (T401532)
mysqli_result functions and methodsHTMLButtonField and its buttonlabel-raw propertyisHTML set to false(MW) Dropped support for unnamespaced Parser and PPFrame.
Parser and PPFrame.$options passed to SelectQueryBuilder::options and ::option$join_conds passed to SelectQueryBuilder::joinCondsHookContainer::register()$options and $join_conds arguments to SELECT DB functionsIReadableDatabase and ISQLPlatform)getQueryInfo() methods, or parser function hook returnsStatus::newGood(), Status::getValue(), and Status::setResult() from analysis using the namespaced FQSEN.### Internal changes * Bumped phan/phan to 5.5.0
Support running in PHP 8.4 (fixed spurious errors seen when analyzing exit)
exit)__toString() method, make the taintedness returned by __toString() propagate to the interface method.\MediaWiki\Message\Message FQSEN when trying to determine if a DoubleEscaped issue involving Message|string is a false positive.Improved accuracy of error reporting ("caused-by lines") by tracking array shapes in more places.
call_user_func and call_user_func_array.(MW) Most of the taintedness values hardcoded in MediaWikiSecurityCheckPlugin::getCustomFuncTaints() have been removed, and annotations have been adde
$rows argument to Database::insert() more accurately, and apply similar rules to InsertQueryBuilder::row() and ::rows().help key in HTMLForm descriptors as an HTML sink.\MediaWiki\Parser\Parser. The non-namespaced version is also still supported.*-taint annotations in an interface method were only inherited by the method implementation in children classes.The raw_param taint flag was removed; error reporting is now sufficiently good that this is no longer needed, and can be treated as normal exec.
SecurityCheckMulti issue type was removed. Now, the plugin emits one issue per taint type.unset( $var['k'] ) on the shape of $var.SecurityCheck-RCE and SecurityCheck-PathTraversal issue types now have critical severity.Global variables and property no longer have EXEC flags if they're later output. Previously, it was supposed to report assigning a tainted value to an
--analyze-twice will catch this kind of issues.--analyze-twice will catch this kind of issues.SecurityCheckInvalidAnnotation, emitted for -taint annotations that cannot be parsed, use unknown or forbidden values (e.g. EXEC bits in return-taint), document non-existing parameters, or have redundant/missing ....Improved caused-by lines for return statements consisting of a function-like call and for inherited methods.
### Internal changes * Bumped phan/phan to 5.1.0
Removed support for standalone install on MediaWiki repos. Generic standalone is still supported, but the script is now called seccheck, not seccheck-
seccheck, not seccheck-generic.raw_param is now a modifier for EXEC taintedness, so it must be specified together with EXEC bits, not normal bits.--analyze-twice will help; this might become officially suggested in the future.match, named arguments, nullsafe method calls and property access, typed properties, constructor property promotion@param-taint and @return-taint annotationsmd5, sha1 and crc32Fixed a crash observed when using the polyfill parser
Added detection for ReDoS vulnerabilities. New issue: SecurityCheck-ReDoS
SecurityCheck-RCE and SecurityCheck-PathTraversalSecurityCheck-ReDoSAllow installing the plugin in PHP 8. Analyzing code with new PHP 8 features is not supported yet (T269263)
Increased the length limit for caused-by lines. The new limit is at 12 entries, rather than fixed at 255 characters (it was roughly doubled)
if conditions,
parameters and return type declarations.'@phan-debug-var-taintedness $varname')$this as hook handlerSecurityCheckPlugin namespace.Added explicit taint info for LinkRenderer::makeBrokenLink
LinkRenderer::makeBrokenLinkshell_exec and friendsGetReturnObjVisitor was deletedRemove reference to AST_LIST (Daimona Eaytoy)
AST_LIST (Daimona Eaytoy)stdClass instances (Daimona Eaytoy)Fix PhanTypeComparisonFromArray edge cases (Daimona Eaytoy)
PhanTypeComparisonFromArray edge cases (Daimona Eaytoy)nodeIs(String|Int) (Daimona Eaytoy)getOriginalScope (Daimona Eaytoy)handleMethodCall always require a FunctionInterface and a function FQSEN (Daimona Eaytoy)try/catch constructs (Daimona Eaytoy)taintToIssueAndSeverity to use a switch (Daimona Eaytoy)build: Upgrade minus-x from 0.3.2 to 1.1.0 (James D. Forrester)
list() assignments (Daimona Eaytoy)Fix phan crash when analyzing MediaWiki core (Daimona Eaytoy)
RAW_PARAM taint type (Daimona Eaytoy)UnusedSuppressionPlugin limited to our warnings (Daimona Eaytoy)ext-ast (Daimona Eaytoy)EXEC_TAINT with ALL_EXEC_TAINT where latter was meant (Brian Wolff)Improve caused-by lines (Daimona Eaytoy)
AST_EMPTY (Daimona Eaytoy)Fix a crash with the literal 'class' (Daimona Eaytoy)
class' (Daimona Eaytoy)TypedElementInterface typehints (Daimona Eaytoy)MW_INSTALL_PATH (Daimona Eaytoy)Fix some issues with CI (Daimona Eaytoy)
MW_INSTALL_PATH (Daimona Eaytoy)IDatabase::buildLike as something that escapes SQL (Brian Wolff)Linker::makeExternalLink (Brian Wolff)EXEC variable from tainting itself (Brian Wolff)Remove wrong EXEC bits from MW functions (Daimona Eaytoy)
EXEC bits from MW functions (Daimona Eaytoy)NO_TAINT for class-string and callable-string (Daimona Eaytoy)ClosureType (Daimona Eaytoy)nodeIsString work again (Daimona Eaytoy)passByReference parameters handling (Daimona Eaytoy)$argc and $argv (Daimona Eaytoy)IDatabase::buildLike as something that escapes SQL (Brian Wolff)Linker::makeExternalLink (Brian Wolff)EXEC variable from tainting itself (Brian Wolff)TaintednessBaseVisitor into a trait (Daimona Eaytoy)Fix fatal when using global keyword with indirect variable (Brian Wolff)
SECURITY_CHECK_EXT_PATH documentation (Kunal Mehta)Avoid false positive related to getQueryInfo() methods. (Brian Wolff)
getQueryInfo() methods. (Brian Wolff)HTMLForm specifier with empty class (Brian Wolff)$conds['field'][] = $tainted (Brian Wolff)htmlform type=info's 'rawrow' option like 'raw' (Brian Wolff)htmlform detection inside AuthenticationRequest (Brian Wolff)HTMLForm $options (Brian Wolff)IDatabase::makeList (Brian Wolff)Make seccheck-mwext and seccheck-fast-mwext work with skins (Brian Wolff)
seccheck-mwext and seccheck-fast-mwext work with skins (Brian Wolff)onlysafefor_html not mark things as exec_escaped. (Brian Wolff)base64_encode as escaping taint. (Brian Wolff)Parser & ParserOutput into inline annotations (Brian Wolff)NO_OVERRIDE flag from being propagated during assignment (Brian Wolff)Ignore tests/ in mwext-fast (Kunal Mehta)
Refactor docblock taint annotation to support docblocks on interfaces (Brian Wolff)
Depend upon phan/phan instead of deprecated etsy/phan (Kunal Mehta)
HTMLForm specifiers (Brian Wolff)\Xml::encodeJsVar and encodeJsCall as double escaping (Brian Wolff)\ in class name list (Brian Wolff)__toString() when object in string context (Brian Wolff)Hooks::runWithoutAbort support (Phantom42)Html escaping functions shouldn't clear non-html taint (Brian Wolff)
SecurityCheckPlugin:: with self:: where possible (Brian Wolff)Update composer.json (Brian Wolff)
list() support (Brian Wolff)SQL_NUMKEY (Brian Wolff)getQueryInfo() return; Process $options & $join_conds (Brian Wolff)IN(...) lists in db select wrapper (Brian Wolff)IDatabase::select style arguments (Brian Wolff)ARRAY_OK flag for functions that are safe with arrays (Brian Wolff)Hooks::run() (Brian Wolff)$wgHooks/$_GLOBALS['wgHooks'] (Brian Wolff)ParserFunctions, and start of work for hooks in general (Brian Wolff)Your coding agent can read these notes before it upgrades. Set up the MCP server →