{"id":13826466,"url":"https://github.com/wordpress/wordpress-coding-standards","last_synced_at":"2026-04-06T03:36:49.737Z","repository":{"id":37696642,"uuid":"1691187","full_name":"WordPress/WordPress-Coding-Standards","owner":"WordPress","description":"PHP_CodeSniffer rules (sniffs) to enforce WordPress coding conventions","archived":false,"fork":false,"pushed_at":"2024-10-05T00:46:27.000Z","size":6191,"stargazers_count":2553,"open_issues_count":222,"forks_count":485,"subscribers_count":84,"default_branch":"develop","last_synced_at":"2024-10-29T14:14:31.685Z","etag":null,"topics":["coding-conventions","php-codesniffer","phpcs","ruleset","wordpress-development","wordpress-standards"],"latest_commit_sha":null,"homepage":"","language":"PHP","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/WordPress.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":".github/CONTRIBUTING.md","funding":".github/FUNDING.yml","license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null},"funding":{"custom":"https://opencollective.com/php_codesniffer"}},"created_at":"2011-05-02T12:49:18.000Z","updated_at":"2024-10-28T20:23:25.000Z","dependencies_parsed_at":"2024-01-07T22:49:42.901Z","dependency_job_id":"d2ad500f-109f-4f88-8272-483c534f2a14","html_url":"https://github.com/WordPress/WordPress-Coding-Standards","commit_stats":{"total_commits":2564,"total_committers":104,"mean_commits":"24.653846153846153","dds":0.4656786271450858,"last_synced_commit":"7f766304b0654cee7c1dfa8e548f65fce197e05c"},"previous_names":[],"tags_count":32,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/WordPress%2FWordPress-Coding-Standards","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/WordPress%2FWordPress-Coding-Standards/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/WordPress%2FWordPress-Coding-Standards/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/WordPress%2FWordPress-Coding-Standards/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/WordPress","download_url":"https://codeload.github.com/WordPress/WordPress-Coding-Standards/tar.gz/refs/heads/develop","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":250513383,"owners_count":21443201,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["coding-conventions","php-codesniffer","phpcs","ruleset","wordpress-development","wordpress-standards"],"created_at":"2024-08-04T09:01:38.180Z","updated_at":"2025-12-17T13:36:41.755Z","avatar_url":"https://github.com/WordPress.png","language":"PHP","readme":"\u003cdiv aria-hidden=\"true\"\u003e\n\n[![Latest Stable Version](https://img.shields.io/packagist/v/wp-coding-standards/wpcs?label=stable)](https://packagist.org/packages/wp-coding-standards/wpcs)\n[![Release Date of the Latest Version](https://img.shields.io/github/release-date/WordPress/WordPress-Coding-Standards.svg?maxAge=1800)](https://github.com/WordPress/WordPress-Coding-Standards/releases)\n:construction:\n[![Latest Unstable Version](https://img.shields.io/badge/unstable-dev--develop-e68718.svg?maxAge=2419200)](https://packagist.org/packages/wp-coding-standards/wpcs#dev-develop)\n\n[![Basic QA checks](https://github.com/WordPress/WordPress-Coding-Standards/actions/workflows/basic-qa.yml/badge.svg)](https://github.com/WordPress/WordPress-Coding-Standards/actions/workflows/basic-qa.yml)\n[![Unit Tests](https://github.com/WordPress/WordPress-Coding-Standards/actions/workflows/unit-tests.yml/badge.svg)](https://github.com/WordPress/WordPress-Coding-Standards/actions/workflows/unit-tests.yml)\n[![codecov.io](https://codecov.io/gh/WordPress/WordPress-Coding-Standards/graph/badge.svg?token=UzFYn0RzVG\u0026branch=develop)](https://codecov.io/gh/WordPress/WordPress-Coding-Standards?branch=develop)\n\n[![Minimum PHP Version](https://img.shields.io/packagist/php-v/wp-coding-standards/wpcs.svg?maxAge=3600)](https://packagist.org/packages/wp-coding-standards/wpcs)\n[![Tested on PHP 7.2 to 8.5](https://img.shields.io/badge/tested%20on-PHP%207.2%20|%207.3%20|%207.4%20|%208.0%20|%208.1%20|%208.2%20|%208.3%20|%208.4%20|%208.5-green.svg?maxAge=2419200)](https://github.com/WordPress/WordPress-Coding-Standards/actions/workflows/unit-tests.yml)\n\n[![License: MIT](https://img.shields.io/github/license/WordPress/WordPress-Coding-Standards)](https://github.com/WordPress/WordPress-Coding-Standards/blob/develop/LICENSE)\n[![Total Downloads](https://img.shields.io/packagist/dt/wp-coding-standards/wpcs\n)](https://packagist.org/packages/wp-coding-standards/wpcs/stats)\n\n\u003c/div\u003e\n\n\n# WordPress Coding Standards for PHP_CodeSniffer\n\n* [Introduction](#introduction)\n* [Minimum Requirements](#minimum-requirements)\n* [Installation](#installation)\n    + [Composer Project-based Installation](#composer-project-based-installation)\n    + [Composer Global Installation](#composer-global-installation)\n    + [Updating your WordPressCS install to a newer version](#updating-your-wordpresscs-install-to-a-newer-version)\n    + [Using your WordPressCS install](#using-your-wordpresscs-install)\n* [Rulesets](#rulesets)\n    + [Standards subsets](#standards-subsets)\n    + [Using a custom ruleset](#using-a-custom-ruleset)\n    + [Customizing sniff behavior](#customizing-sniff-behavior)\n    + [Recommended additional rulesets](#recommended-additional-rulesets)\n* [How to use](#how-to-use)\n    + [Command line](#command-line)\n    + [Using PHPCS and WordPressCS from within your IDE](#using-phpcs-and-wordpresscs-from-within-your-ide)\n* [Running your code through WordPressCS automatically using Continuous Integration tools](#running-your-code-through-wordpresscs-automatically-using-continuous-integration-tools)\n* [Fixing errors or ignoring them](#fixing-errors-or-ignoring-them)\n    + [Tools shipped with WordPressCS](#tools-shipped-with-wordpresscs)\n* [Contributing](#contributing)\n* [Funding](#funding)\n* [License](#license)\n\n---\n\n## Introduction\n\nThis project is a collection of [PHP_CodeSniffer](https://github.com/PHPCSStandards/PHP_CodeSniffer) rules (sniffs) to validate code developed for WordPress. It ensures code quality and adherence to coding conventions, especially the official [WordPress Coding Standards](https://make.wordpress.org/core/handbook/best-practices/coding-standards/).\n\n**This project needs funding. [Find out how you can help](#funding).**\n\n## Minimum Requirements\n\nThe WordPress Coding Standards package requires:\n* PHP 7.2 or higher with the following extensions enabled:\n    - [Filter](https://www.php.net/book.filter)\n    - [libxml](https://www.php.net/book.libxml)\n    - [Tokenizer](https://www.php.net/book.tokenizer)\n    - [XMLReader](https://www.php.net/book.xmlreader)\n* [Composer](https://getcomposer.org/)\n\nFor the best results, it is recommended to also ensure the following additional PHP extensions are enabled:\n- [iconv](https://www.php.net/book.iconv)\n- [Multibyte String](https://www.php.net/book.mbstring)\n\n## Installation\n\nAs of [WordPressCS 3.0.0](https://make.wordpress.org/core/2023/08/21/wordpresscs-3-0-0-is-now-available/), installation via Composer using the below instructions is the only supported type of installation.\n\n[Composer](https://getcomposer.org/) will automatically install the project dependencies and register the rulesets from WordPressCS and other external standards with PHP_CodeSniffer using the [Composer PHPCS plugin](https://github.com/PHPCSStandards/composer-installer).\n\n\u003e If you are upgrading from an older WordPressCS version to version 3.0.0, please read the [Upgrade guide for ruleset maintainers and end-users](https://github.com/WordPress/WordPress-Coding-Standards/wiki/Upgrade-Guide-to-WordPressCS-3.0.0-for-ruleset-maintainers) first!\n\n### Composer Project-based Installation\n\nRun the following from the root of your project:\n```bash\ncomposer config allow-plugins.dealerdirect/phpcodesniffer-composer-installer true\ncomposer require --dev wp-coding-standards/wpcs:\"^3.0\"\n```\n\n### Composer Global Installation\n\nAlternatively, you may want to install this standard globally:\n```bash\ncomposer global config allow-plugins.dealerdirect/phpcodesniffer-composer-installer true\ncomposer global require --dev wp-coding-standards/wpcs:\"^3.0\"\n```\n\n### Updating your WordPressCS install to a newer version\n\nIf you installed WordPressCS using either of the above commands, you can upgrade to a newer version as follows:\n```bash\n# Project local install\ncomposer update wp-coding-standards/wpcs --with-dependencies\n\n# Global install\ncomposer global update wp-coding-standards/wpcs --with-dependencies\n```\n\n### Using your WordPressCS install\n\nOnce you have installed WordPressCS using either of the above commands, use it as follows:\n```bash\n# Project local install\nvendor/bin/phpcs -ps . --standard=WordPress\n\n# Global install\n%USER_DIRECTORY%/Composer/vendor/bin/phpcs -ps . --standard=WordPress\n```\n\n\u003e **Pro-tip**: For the convenience of using `phpcs` as a global command, use the _Global install_ method and add the path to the `%USER_DIRECTORY%/Composer/vendor/bin` directory to the `PATH` environment variable for your operating system.\n\n\n##  Rulesets\n\n### Standards subsets\n\nThe project encompasses a super-set of the sniffs that the WordPress community may need. If you use the `WordPress` standard you will get all the checks.\n\nYou can use the following as standard names when invoking `phpcs` to select sniffs, fitting your needs:\n\n* `WordPress` - complete set with all of the sniffs in the project\n  - `WordPress-Core` - main ruleset for [WordPress core coding standards](https://developer.wordpress.org/coding-standards/wordpress-coding-standards/php/)\n  - `WordPress-Docs` - additional ruleset for [WordPress inline documentation standards](https://developer.wordpress.org/coding-standards/inline-documentation-standards/php/)\n  - `WordPress-Extra` - extended ruleset with recommended best practices, not sufficiently covered in the WordPress core coding standards\n    - includes `WordPress-Core`\n\n### Using a custom ruleset\n\nIf you need to further customize the selection of sniffs for your project - you can create a custom ruleset file.\n\nWhen you name this file either `.phpcs.xml`, `phpcs.xml`, `.phpcs.xml.dist` or `phpcs.xml.dist`, PHP_CodeSniffer will automatically locate it as long as it is placed in the directory from which you run the CodeSniffer or in a directory above it. If you follow these naming conventions you don't have to supply a `--standard` CLI argument.\n\nFor more info, read about [using a default configuration file](https://github.com/PHPCSStandards/PHP_CodeSniffer/wiki/Advanced-Usage#using-a-default-configuration-file). See also the provided WordPressCS [`phpcs.xml.dist.sample`](phpcs.xml.dist.sample) file and the [fully annotated example ruleset](https://github.com/PHPCSStandards/PHP_CodeSniffer/wiki/Annotated-ruleset.xml) in the PHP_CodeSniffer documentation.\n\n### Customizing sniff behavior\n\nThe WordPress Coding Standard contains a number of sniffs which are configurable. This means that you can turn parts of the sniff on or off, or change the behavior by setting a property for the sniff in your custom `[.]phpcs.xml[.dist]` file.\n\nYou can find a complete list of all the properties you can change for the WordPressCS sniffs in the [wiki](https://github.com/WordPress/WordPress-Coding-Standards/wiki/Customizable-sniff-properties).\n\nWordPressCS also uses sniffs from PHPCSExtra and from PHP_CodeSniffer itself.\nThe [README for PHPCSExtra](https://github.com/PHPCSStandards/PHPCSExtra) contains information on the properties which can be set for the sniff from PHPCSExtra.\nInformation on custom properties which can be set for sniffs from PHP_CodeSniffer can be found in the [PHP_CodeSniffer wiki](https://github.com/PHPCSStandards/PHP_CodeSniffer/wiki/Customisable-Sniff-Properties).\n\n\n### Recommended additional rulesets\n\n#### PHPCompatibility\n\nThe [PHPCompatibility](https://github.com/PHPCompatibility/PHPCompatibility) ruleset and its subset [PHPCompatibilityWP](https://github.com/PHPCompatibility/PHPCompatibilityWP) come highly recommended.\nThe [PHPCompatibility](https://github.com/PHPCompatibility/PHPCompatibility) sniffs are designed to analyze your code for cross-version PHP compatibility.\n\nThe [PHPCompatibilityWP](https://github.com/PHPCompatibility/PHPCompatibilityWP) ruleset is based on PHPCompatibility, but specifically crafted to prevent false positives for projects which expect to run within the context of WordPress, i.e. core, plugins and themes.\n\nInstall either as a separate ruleset and run it separately against your code or add it to your custom ruleset, like so:\n```xml\n\u003cconfig name=\"testVersion\" value=\"7.2-\"/\u003e\n\u003crule ref=\"PHPCompatibilityWP\"\u003e\n    \u003cinclude-pattern\u003e*\\.php$\u003c/include-pattern\u003e\n\u003c/rule\u003e\n```\n\nWhichever way you run it, do make sure you set the `testVersion` to run the sniffs against. The `testVersion` determines for which PHP versions you will receive compatibility information. The recommended setting for this at this moment is  `7.2-` to support the same PHP versions as WordPress Core supports.\n\nFor more information about setting the `testVersion`, see:\n* [PHPCompatibility: Sniffing your code for compatibility with specific PHP version(s)](https://github.com/PHPCompatibility/PHPCompatibility#sniffing-your-code-for-compatibility-with-specific-php-versions)\n* [PHPCompatibility: Using a custom ruleset](https://github.com/PHPCompatibility/PHPCompatibility#using-a-custom-ruleset)\n\n#### VariableAnalysis\n\nFor some additional checks around (undefined/unused) variables, the [`VariableAnalysis`](https://github.com/sirbrillig/phpcs-variable-analysis/) standard is a handy addition.\n\n#### VIP Coding Standards\n\nFor those projects which deploy to the WordPress VIP platform, it is recommended to also use the [official WordPress VIP coding standards](https://github.com/Automattic/VIP-Coding-Standards) ruleset.\n\n\n## How to use\n\n### Command line\n\nRun the `phpcs` command line tool on a given file or directory, for example:\n```bash\nvendor/bin/phpcs --standard=WordPress wp-load.php\n```\n\nWill result in following output:\n```\n--------------------------------------------------------------------------------\nFOUND 6 ERRORS AND 4 WARNINGS AFFECTING 5 LINES\n--------------------------------------------------------------------------------\n  36 | WARNING | error_reporting() can lead to full path disclosure.\n  36 | WARNING | error_reporting() found. Changing configuration values at\n     |         | runtime is strongly discouraged.\n  52 | WARNING | Silencing errors is strongly discouraged. Use proper error\n     |         | checking instead. Found: @file_exists( dirname(...\n  52 | WARNING | Silencing errors is strongly discouraged. Use proper error\n     |         | checking instead. Found: @file_exists( dirname(...\n  75 | ERROR   | Overriding WordPress globals is prohibited. Found assignment\n     |         | to $path\n  78 | ERROR   | Detected usage of a possibly undefined superglobal array\n     |         | index: $_SERVER['REQUEST_URI']. Use isset() or empty() to\n     |         | check the index exists before using it\n  78 | ERROR   | $_SERVER['REQUEST_URI'] not unslashed before sanitization. Use\n     |         | wp_unslash() or similar\n  78 | ERROR   | Detected usage of a non-sanitized input variable:\n     |         | $_SERVER['REQUEST_URI']\n 104 | ERROR   | All output should be run through an escaping function (see the\n     |         | Security sections in the WordPress Developer Handbooks), found\n     |         | '$die'.\n 104 | ERROR   | All output should be run through an escaping function (see the\n     |         | Security sections in the WordPress Developer Handbooks), found\n     |         | '__'.\n--------------------------------------------------------------------------------\n```\n\n### Using PHPCS and WordPressCS from within your IDE\n\nThe [wiki](https://github.com/WordPress/WordPress-Coding-Standards/wiki) contains links to various in- and external tutorials about setting up WordPressCS to work in your IDE.\n\n\n## Running your code through WordPressCS automatically using Continuous Integration tools\n\n- [Running in GitHub Actions](https://github.com/WordPress/WordPress-Coding-Standards/wiki/Running-in-GitHub-Actions)\n- [Running in Travis](https://github.com/WordPress/WordPress-Coding-Standards/wiki/Running-in-Travis)\n\n\n## Fixing errors or ignoring them\n\nYou can find information on how to deal with some of the more frequent issues in the [wiki](https://github.com/WordPress/WordPress-Coding-Standards/wiki).\n\n### Tools shipped with WordPressCS\n\nSince version 1.2.0, WordPressCS has a special sniff category `Utils`.\n\nThis sniff category contains some tools which, generally speaking, will only be needed to be run once over a codebase and for which the fixers can be considered _risky_, i.e. very careful review by a developer is needed before accepting the fixes made by these sniffs.\n\nThe sniffs in this category are disabled by default and can only be activated by adding some properties for each sniff via a custom ruleset.\n\nAt this moment, WordPressCS offer the following tools:\n* `WordPress.Utils.I18nTextDomainFixer` - This sniff can replace the text domain used in a code-base.\n    The sniff will fix the text domains in both I18n function calls as well as in a plugin/theme header.\n    Passing the following properties will activate the sniff:\n    - `old_text_domain`: an array with one or more (old) text domain names which need to be replaced;\n    - `new_text_domain`: the correct (new) text domain as a string.\n\n\n## Contributing\n\nSee [CONTRIBUTING](.github/CONTRIBUTING.md), including information about [unit testing](.github/CONTRIBUTING.md#unit-testing) the standard.\n\n## Funding\n\nIf you want to sponsor the work on WordPressCS, you can do so by donating to the [PHP_CodeSniffer Open Collective](https://opencollective.com/php_codesniffer).\n\n## License\n\nSee [LICENSE](LICENSE) (MIT).\n","funding_links":["https://opencollective.com/php_codesniffer"],"categories":["\u003ca id=\"7bf0f5839fb2827fdc1b93ae6ac7f53d\"\u003e\u003c/a\u003e工具","\u003ca id=\"1d9dec1320a5d774dc8e0e7604edfcd3\"\u003e\u003c/a\u003e工具-新添加的"],"sub_categories":["\u003ca id=\"32739127f0c38d61b14448c66a797098\"\u003e\u003c/a\u003e嗅探\u0026\u0026Sniff","\u003ca id=\"8f1b9c5c2737493524809684b934d49a\"\u003e\u003c/a\u003e文章\u0026\u0026视频"],"project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fwordpress%2Fwordpress-coding-standards","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fwordpress%2Fwordpress-coding-standards","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fwordpress%2Fwordpress-coding-standards/lists"}