NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #180 most downloaded on Packagist
PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards.
Last release 2 months ago
06 Aug 2026
Ships unpredictably
gaps range from 8 days to 9 months
Rarely documented
notes for 9 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
14 years old
109 releases · first in 2012
The 4.0.2 release, the 4.0.3 and the 4.0.4 release are 100% the same (aside from the version number), there was just a slight snafu in the release pub
The 4.0.2 release, the 4.0.3 and the 4.0.4 release are 100% the same (aside from the version number), there was just a slight snafu in the release publication on GitHub (missing PHAR assets). Sorry for the confusion.
This is a security release and all users are advised to update their install(s) as soon as possible. The security issue only affects users of the Gitb…
This is a security release and all users are advised to update their install(s) as soon as possible.
The security issue only affects users of the Gitblame, Hgblame or Svnblame report(s).
(void) cast. #1325T_VOID_CAST token has been added to the Tokens::CAST_TOKENS array.suggest section to the composer.json file to inform users about the recommended iconv and pcntl PHP extensions. #1388
libxml is a required PHP extension. #1409$this in static closures. #1377WrongOpener*) has been made more informative. #1358. Fixes #1322.
PEAR.Functions.FunctionDeclaration #1445
CloseBracketLine error message now exposes 1 data value (previously 0).EmptyLine error message now exposes 1 data value (previously 0).Indent error message now exposes 3 data values (previously 2).PSR12.Classes.AnonClassDeclaration and Squiz.Functions.MultiLineFunctionDeclaration sniffs.PSR2.Classes.ClassDeclaration #1446
ExtendsLine and ImplementsLine error messages now expose 3 data values (previously 1).SpaceBeforeExtends and SpaceBeforeImplements error messages now expose 2 data values (previously 1).PSR12.Classes.AnonClassDeclaration and Squiz.Classes.ClassDeclaration sniffs.PSR2.ControlStructures.SwitchDeclaration #1447
defaultNotLower and caseNotLower error messages now expose 3 data values (previously 2).SpaceBeforeColonDEFAULT and SpaceBeforeColonCASE error messages now expose 1 data value (previously 0).BodyOnNextLineDEFAULT and BodyOnNextLineCASE error messages now expose 1 data value (previously 0).WrongOpenerdefault and WrongOpenercase error messages now expose 1 data value (previously 0).Squiz.ControlStructures.SwitchDeclaration #1449
CaseNotLower and DefaultNotLower error messages now expose 3 data values (previously 2).CaseIndent and DefaultIndent error messages now expose 2 data values (previously 0).SpaceBeforeColonCase and SpaceBeforeColonDefault error messages now expose 1 data value (previously 0).BreakIndent error message now exposes 1 data value (previously 0).SpacingAfterCase and SpacingAfterDefault error messages now expose 1 data value (previously 0).Squiz.Functions.FunctionDeclarationArgumentSpacing #1452
SpaceBeforeEquals error message now exposes 3 data values (previously 2).SpaceAfterEquals error message now exposes 3 data values (previously 2).Squiz.Functions.MultiLineFunctionDeclaration #1453
FirstParamSpacing and UseFirstParamSpacing error messages now expose 1 data value (previously 0).OneParamPerLine and UseOneParamPerLine error messages now expose 1 data value (previously 0).PSR12.Classes.AnonClassDeclaration sniff.Gitblame, Hgblame or Svnblame report(s) would process a file whose name contains shell metacharacters. #1473
Full report, or any of the other non-*blame reports, are not affected.$this in non-static closures nested in OO methods.phpcbf.
Squiz.Functions.MultiLineFunctionDeclaration sniff.The PHP_CodeSniffer project is happy to welcome the following new contributors:
@bigdevlarry, @Faze-up, @jrchamp, @lazerg, @morozov, @ntdiary, @SAY-5
Closed: 10 issues
Merged: 33 pull requests
Follow @phpcs on Mastodon or @PHP_CodeSniffer on X to stay informed.
Please consider funding the PHP_CodeSniffer project. If you already do so: thank you!
One column per quarter.
Runtime support for PHP 8.5. All known PHP 8.5 deprecation notices have been fixed.
This release includes all improvements and bugfixes from PHP_CodeSniffer 3.13.5.
phpcs:ignore comma-separated rule reference lists.
phpcs:disable/phpcs:enable ignore annotations.switch.
case/default and "case breaking" statements.switch case condition or after a default keyword, was not regarded as a "scope_opener" for the case/default body.WrongOpener error is now also auto-fixable if the wrong opener is a PHP close tag.The PHP_CodeSniffer project is happy to welcome the following new contributors:
@andrewnicols, @Soh1121
Closed: 2 issues
Merged: 8 pull requests
Follow @phpcs on Mastodon or @PHP_CodeSniffer on X to stay informed.
Please consider funding the PHP_CodeSniffer project. If you already do so: thank you!
This release contains breaking changes.
This release contains breaking changes.
Upgrade guides for both ruleset maintainers/end-users, as well as for sniff developers and integrators, have been published to the Wiki.
You are strongly encouraged to read the upgrade guide applicable to your situation before upgrading.
This release includes all improvements and bugfixes from PHP_CodeSniffer 4.0.0-beta1, 4.0.0-RC1, 3.13.3 and 3.13.4.
exit/die/true/false/null will be tokenized as the keyword token and the token 'content' will include the leading backslash. #1201^8.4.0 || ^9.3.4 || ^10.5.32 || 11.3.3 - 11.5.28 || ^11.5.31. #1247
phpcbf on code provided via STDIN.
// phpcs:set for inline array properties did not handle a single item array with the value true, false or null correctly.phpcbf in parallel mode.master branch has been renamed to 3.x and the default branch has changed to the 4.x branch.
Closed: 5 issues
Merged: 35 pull requests
Follow @phpcs on Mastodon or @PHP_CodeSniffer on X to stay informed.
Please consider funding the PHP_CodeSniffer project. If you already do so: thank you!
Nothing published for this version
This is a security release and all users are advised to update their install(s) as soon as possible.
This is a security release and all users are advised to update their install(s) as soon as possible.
Gitblame, Hgblame or Svnblame report(s) would process a file whose name contains shell metacharacters. #1473
Full report, or any of the other non-*blame reports, are not affected.Closed: 0 issues
Merged: 46 pull requests
Follow @phpcs on Mastodon or @PHP_CodeSniffer on X to stay informed.
Please consider funding the PHP_CodeSniffer project. If you already do so: thank you!
Runtime support for PHP 8.5. All known PHP 8.5 deprecation notices have been fixed.
master branch has been renamed to 3.x and the default branch has changed to the 4.x branch.
The PHP_CodeSniffer project is happy to welcome the following new contributors:
@andrewnicols
Closed: 2 issues
Merged: 36 pull requests
Follow @phpcs on Mastodon or @PHP_CodeSniffer on X to stay informed.
Please consider funding the PHP_CodeSniffer project. If you already do so: thank you!
Fixed bug #1215 : PHP 8.5 "Using null as an array offset" deprecation notices.
Closed: 0 issues
Merged: 3 pull requests
If you like to stay informed about releases and more, follow @phpcs on Mastodon or @PHP_CodeSniffer on X.
Please consider funding the PHP_CodeSniffer project. If you already do so: thank you!
Tokenizer support for PHP 8.4 dereferencing of new expressions without wrapping parentheses. #1160
abstract properties. #1183
File::getMemberProperties() method now also supports abstract properties through a new is_abstract array index in the return value. #1184abstract properties:
exit/die is used as a fully qualified "function call", it will now be tokenized as T_NS_SEPARATOR + T_EXIT.true/false/null will now be tokenized as T_NS_SEPARATOR + T_TRUE/T_FALSE/T_NULL. #1201
T_NS_SEPARATOR + T_STRING.WrongOpener* error code is now auto-fixable if the identified "wrong opener" is a semi-colon. #1161
AbstractAfterVisibility error code.--parallel option fails if PHP_CodeSniffer is invoked via bash and the invokation creates a non-PHPCS-managed process.
--parallel scanning was enabled.The PHP_CodeSniffer project is happy to welcome the following new contributors:
@benno5020, @NanoSector
Closed: 11 issues
Merged: 40 pull requests
Follow @phpcs on Mastodon or @PHP_CodeSniffer on X to stay informed.
Please consider funding the PHP_CodeSniffer project. If you already do so: thank you!
The documentation for the following sniffs has been improved:
SpacingAfterSetVis[i]bility.
Closed: 0 issues
Merged: 6 pull requests
Follow @phpcs on Mastodon or @PHP_CodeSniffer on X to stay informed.
Please consider funding the PHP_CodeSniffer project. If you already do so: thank you!
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →