NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #5117 most downloaded on Packagist
PHPStan rules that help you migrate from PHP-FPM to FrankenPHP classic, then to worker mode. Rules are split by level with demos for every case.
Last release today
07 Oct 2026
Ships fairly regularly
a new release about every 2 weeks
Nearly every release is documented
notes for 12 of 12 stable releases
Nothing withdrawn
no release was ever pulled
2 months old
12 releases · first in 2026
One column per month.
Release v1.2.3 - pcntl_wait/waitpid + Form ResetInterface skips
Release v1.2.3 - pcntl_wait/waitpid + Form ResetInterface skips
NoPcntlForkRule: also flags pcntl_wait / pcntl_waitpid with a dedicated message (blocking wait on a child from the HTTP worker thread).ignoreErrors samples for pcntl/posix hardening identifiers; known gap note for dynamic FuncCall.NoMissingResetInterfaceRule: fewer false positives on Symfony Form helpers — skip name suffixes Form, FormType, TypeExtension, DataTransformer, DataMapper and FQCN fragments /form/, /forms/.flagMissingResetInterface. See UPGRADING.md.Release v1.2.2 - Detect array/nested writes in NoMissingResetInterfaceRule
Release v1.2.2 - Detect array/nested writes in NoMissingResetInterfaceRule
NoMissingResetInterfaceRule: false negative on writes through array elements and nested properties ($this->items[$k] = …, $this->items[] = …, $this->counters[$k]++, $this->items[$k] ??= …, unset($this->items[$k]), $this->obj->prop = …, =&) — only a direct $this->prop = … was detected, so in-memory per-request caches held in arrays were missed.\SIGTERM, …) for native_constant_invocation when CS Fixer runs with pcntl/posix loaded (CI).igor-php/igor-php ^0.9.7 → ^0.10.0 (Dependabot).ruleset-worker-no-kernel-reset.neon / frankenphp.flagMissingResetInterface, re-run PHPStan — expect new findings for array/nested writes. See UPGRADING.md.NoMissingResetInterfaceRule: false negative on writes through array elements and nested properties ($this->items[$k] = …, $this->items[] = …, $this->counters[$k]++, $this->items[$k] ??= …, unset($this->items[$k]), $this->obj->prop = …, =&) — only a direct $this->prop = … was detected, so in-memory per-request caches held in arrays were missed.\SIGTERM, …) for native_constant_invocation when CS Fixer runs with pcntl/posix loaded (CI).igor-php/igor-php ^0.9.7 → ^0.10.0 (Dependabot).ruleset-worker-no-kernel-reset.neon / frankenphp.flagMissingResetInterface, re-run PHPStan — expect new findings for array/nested writes. See UPGRADING.md.REQ-CS-008: igor-php/igor-php (require-dev only), root igor.json , Composer/ Makefile igor target, and release-check wiring for FrankenPHP worker-stat
v1.2.1
igor-php/igor-php (require-dev only), root igor.json, Composer/Makefile igor target, and release-check wiring for FrankenPHP worker-state audit.Release v1.2.0 - Worker kernel-reuse (no FRANKENPHP_RESET_KERNEL) compatibility
Release v1.2.0 - Worker kernel-reuse (no FRANKENPHP_RESET_KERNEL) compatibility
ruleset-worker-no-kernel-reset.neon and parameter frankenphp.flagMissingResetInterface for FrankenPHP worker with FRANKENPHP_RESET_KERNEL unset/false (kernel reused).NoMissingResetInterfaceRule (frankenphp.worker.noMissingResetInterface) — flags $this->… mutations without ResetInterface (heuristic name skips).NoPosixProcessControlRule (frankenphp.hardening.noPosixProcessControl).NoMbEncodingMutationRule: also flags mb_detect_order / mb_substitute_character; allows explicit null argument reads.NoPersistentIniSetRule: sticky keys include mbstring.*, intl.default_locale, default_charset.ruleset-worker-no-kernel-reset.neon for kernel-reuse apps. See UPGRADING.md.nowo-tech/phpstan-frankenphp: ^1.0.See docs/CHANGELOG.md for details.
Release 1.1.3
See docs/CHANGELOG.md for details.
Release v1.1.2: composer audit CI
Release v1.1.1: Symfony 8 demos and Hot Reload 1.4.
Release v1.1.1: Symfony 8 demos and Hot Reload 1.4.
nowo-tech/hot-reload-bundle to ^1.4 with FrankenPHP Mercure/hot_reload (dev/test only).nowo-tech/hot-reload-bundle to ^1.4 with FrankenPHP Mercure/hot_reload (dev/test only).Release v1.1.0 - Worker process-state rules and pcntl signal hardening
Release v1.1.0 - Worker process-state rules and pcntl signal hardening
NoChdirRule (frankenphp.worker.noChdir)NoSetLocaleRule (frankenphp.worker.noSetLocale) — queries via setlocale($category, 0|"0") allowedNoLocaleSetDefaultRule (frankenphp.worker.noLocaleSetDefault) — locale_set_default() / Locale::setDefault()NoDateDefaultTimezoneSetRule (frankenphp.worker.noDateDefaultTimezoneSet)NoMbEncodingMutationRule (frankenphp.worker.noMbEncodingMutation) — mb_internal_encoding / mb_regex_encoding / mb_http_output / mb_language with an argument; no-arg reads allowedNoErrorReportingMutationRule (frankenphp.worker.noErrorReportingMutation)NoUmaskRule (frankenphp.worker.noUmask)NoPcntlSignalRule (frankenphp.hardening.noPcntlSignal) — pcntl_signal, pcntl_async_signals, pcntl_signal_dispatch, pcntl_signal_get_handler, pcntl_sigprocmask, pcntl_sigwaitinfo, pcntl_sigtimedwait, pcntl_alarmRULES.mdROADMAP.md for planned expansions and explicit non-goalsruleset-worker.neon and/or ruleset-hardening.neon: re-run PHPStan and fix or baseline the new identifiers. See UPGRADING.md.nowo-tech/phpstan-frankenphp: ^1.0 (1.1.0 is a compatible minor).Release v1.0.3 - Spec Kit deep baseline and Cursor Agent scaffold
Release v1.0.3 - Spec Kit deep baseline and Cursor Agent scaffold
.specify/ (constitution, templates, workflows).github/copilot-instructions.md for maintainer/agent conventionsspecs/001-baseline/spec.md with semantic FR-* requirements and user scenarios; code-inventory.md maps 20/20 production PHP files under src/ (REQ-SPECKIT-003)actions/stale from v10 to v11ReduceAlwaysFalseIfOrRector so processNode instanceof guards stay for early-return coverage; no public API or reported-error changesnowo-tech/phpstan-frankenphp: ^1.0.Demo Symfony 8: DebugBundle + Twig Inspector; update-bundle ; SYMFONY_DEPRECATIONS_HELPER=max[direct]=0
Release v1.0.2 - FrankenPHP banner, Make demos/smoke, security checklist
docs/images/frankenphp-friendly.png)check-open-prs, demo-smoke; Compose V2→V1 detection (REQ-MAKE-010)DebugBundle + Twig Inspector; update-bundle; SYMFONY_DEPRECATIONS_HELPER=max[direct]=0ignoreErrors: [] in phpstan.neon.dist; release security checklist (12.4.1) in docs/SECURITY.mdDocumentation: remediations remain PHP-FPM compatible.
Release v1.0.1
Documentation: remediations remain PHP-FPM compatible.
First stable release of nowo-tech/phpstan-frankenphp: classic, worker, worker-strict, and hardening PHPStan rulesets, fixture demos, Symfony 8 Franken
Release v1.0.0
First stable release of nowo-tech/phpstan-frankenphp:
classic, worker, worker-strict, and hardening PHPStan rulesets,
fixture demos, Symfony 8 FrankenPHP demo, 100% coverage gate.
First stable release of nowo-tech/phpstan-frankenphp: PHPStan rules to migrate from PHP-FPM to FrankenPHP classic, then worker mode.
type: phpstan-extension) with extension.neon (schema/defaults only; rules are not auto-enabled).ruleset-classic.neon): exit/die, fastcgi_finish_request, putenv, ignore_user_abort, unlimited I/O timeouts.ruleset-worker.neon): mutable statics, static locals, globals, $_ENV/$_SESSION, native session API, persistent ini_set, singletons, register_shutdown_function, set_error_handler / set_exception_handler.ruleset-worker-strict.neon) and parameter frankenphp.flagRequestSuperglobals (default false) to also flag $_GET/$_POST/….ruleset-hardening.neon): set_time_limit(0), memory_limit -1, pcntl_fork, blocking sleep, register_tick_function.rules.neon (classic + worker + hardening).demo/{classic,worker,hardening}/{bad,good} with Composer/Make targets (demo-*, demo-*-good).demo/symfony8) with FRANKENPHP_MODE=worker by default, anti-patterns, and leveled PHPStan configs.specs/001-baseline/).src/, coverage-check / test-coverage-100, CI matrix PHP 8.2–8.5, release-check + release-check-demos.NoSuperglobalAccessRule defaults to $_ENV + $_SESSION only (aligned with FrankenPHP worker reset behaviour); request superglobals are opt-in via worker-strict / flagRequestSuperglobals.readonly static properties.Your coding agent can read these notes before it upgrades. Set up the MCP server →