miropen / mir-php
Fast static analyzer for PHP
Package info
Language:Rust
Type:composer-plugin
pkg:composer/miropen/mir-php
Requires
- php: >=8.1
- composer-plugin-api: ^2.0
Requires (Dev)
- composer/composer: ^2.0
Suggests
None
Provides
None
Conflicts
None
Replaces
None
- dev-main
- v0.83.0
- v0.82.0
- v0.81.0
- v0.80.0
- v0.79.0
- v0.78.0
- v0.77.0
- v0.76.0
- v0.75.0
- v0.74.0
- v0.73.0
- v0.72.1
- v0.72.0
- v0.71.0
- v0.70.1
- v0.70.0
- v0.69.0
- v0.68.0
- v0.67.0
- v0.66.1
- v0.66.0
- v0.65.0
- v0.64.0
- v0.63.0
- v0.62.0
- v0.61.0
- v0.60.0
- v0.59.2
- v0.59.1
- v0.59.0
- v0.58.0
- v0.57.0
- v0.56.0
- v0.55.1
- v0.55.0
- v0.54.0
- v0.53.1
- v0.52.0
- v0.51.0
- v0.50.2
- v0.50.1
- v0.50.0
- v0.49.0
- v0.48.0
- v0.47.0
- v0.46.0
- v0.45.0
- v0.44.0
- v0.43.0
- v0.42.0
- v0.41.0
- v0.40.0
- v0.39.0
- v0.38.0
- v0.37.0
- v0.36.0
- v0.35.1
- v0.35.0
- v0.34.0
- v0.33.0
- v0.32.0
- v0.31.0
- v0.30.0
- v0.29.0
- v0.28.0
- v0.27.0
- v0.26.0
- v0.25.0
- v0.24.0
- v0.23.0
- v0.22.0
- v0.21.2
- v0.21.1
- v0.21.0
- v0.20.0
- v0.19.0
- v0.18.0
- v0.17.3
- v0.17.2
- v0.17.1
- v0.17.0
- v0.16.2
- v0.16.0
- v0.15.0
- v0.14.0
- v0.13.0
- v0.12.0
- v0.11.1
- v0.11.0
- v0.10.0
This package is auto-updated.
Last update: 2026-10-01 22:34:22 UTC
README
mir
⚠️ Experimental. mir is under active development and not yet production-ready. APIs, CLI flags, issue codes, and output formats may change between releases; expect false positives and rough edges.
A fast, incremental PHP static analyzer written in Rust, inspired by Psalm.
Features
- 140+ diagnostic rules across type errors, undefined symbols, dead code, taint, and more
- Sound type system — scalars, objects, generics, unions, intersections, literals,
never,void - Full type inference — return types, literal narrowing,
if/match/instanceof/is_string()etc. - Call checking — argument count and types for user-defined and built-in functions/methods
- Class analysis — inheritance, interface compliance, abstract enforcement, visibility,
readonly,final - Dead code detection — unused variables, parameters, private methods, properties, and functions
- Taint analysis — tracks data from
$_GET/$_POSTto HTML/SQL/shell sinks - Incremental cache — unchanged files skipped on re-runs via content hashing
- Parallel analysis — rayon-powered; scales to available CPUs
- PHP 7.4–8.6 support with version-aware stub filtering
- Comprehensive built-in coverage — powered by JetBrains phpstorm-stubs (57 extensions, 500+ functions, 100+ classes)
Installation
From Composer (PHP projects)
composer require --dev miropen/mir-php vendor/bin/mir src/
A post-install-cmd hook downloads the prebuilt binary matching your version
and host platform from GitHub Releases. See the
getting started guide
for supported targets.
From crates.io
cargo install mir-php
Build from source
git clone https://github.com/jorgsowa/mir.git cd mir cargo build --release # binary at target/release/mir
Usage
mir # analyze current directory mir src/ lib/ # analyze specific paths mir --format json src/ # machine-readable output mir --baseline baseline.xml src/ # suppress known issues
See the CLI reference for all flags and options.
GitHub Actions
Use the mir GitHub Action to run analysis in your workflow:
- uses: jorgsowa/mir-action@v1 with: path: src
Suppressing issues inline
Use @mir-ignore, @mir-ignore-next-line, or @mir-ignore-file to suppress a
false positive directly in source. @psalm-suppress and @phpstan-ignore-*
aliases are accepted. See the suppression reference.
Documentation
Full documentation is available at jorgsowa.github.io/mir.
Contributing
See CONTRIBUTING.md.
License
MIT