chore: add php lint, phpcs and phpstan - #12
Merged
Merged
Conversation
Signed-off-by: YvesCesar <yvesamorim73@gmail.com>
…nd php versions Signed-off-by: YvesCesar <yvesamorim73@gmail.com>
Signed-off-by: YvesCesar <yvesamorim73@gmail.com>
Signed-off-by: YvesCesar <yvesamorim73@gmail.com>
vitormattos
approved these changes
Sep 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The theme had no Composer setup, no lint, no coding standard and no CI beyond the translation workflows. This adds PHP lint, PHPCS and PHPStan, each as a Composer script and a GitHub workflow.
Tooling
composer lint,composer cs,composer stanandcomposer ci(all three, in this order).vendor-bin/project (bamarni/composer-bin-plugin), so their dependencies do not mix.php-lint.yml,phpcs.yml,phpstan.yml. The PHP versions come fromcomposer.json(>=8.3 <8.6) throughtypisttech/php-matrix-action, so the matrix is 8.3, 8.4 and 8.5.WordPress-Extra, so the diff stays reviewable. PHPStan runs at level 5 with the WordPress extension and the WooCommerce stubs.style.cssandreadme.txtnow declareRequires at least: 7.0,Tested up to: 7.0andRequires PHP: 8.3, the versions the checks run against.readme.txtsaidRequires PHP: 5.7.Changes to the theme
libresign_theme_andlibresign_. Thelibresign-wp-customizationsplugin also useslibresign_, and both are loaded on the same site, so a function added to either one with a name the other already has is a fatal error. The 23 functions that usedlibresign_now uselibresign_theme_, the prefix the fragment and webhook code already had. Option names, theme mods, user meta and error codes keep their values. Code that unhooks the old names, such asremove_filter( 'get_custom_logo', 'libresign_filter_custom_logo' ), stops working; none of the LibreSign plugins installed alongside the theme references them.woocommerce/myaccount/form-login.phpis excluded from the prefix rule. The hooks it fires are WooCommerce's own, and WooCommerce includes the template inside a function, so its variables are not global. The username and email fields echo the posted value back escaped, like the WooCommerce template does; the nonce is checked by WooCommerce before the form is processed, so those lines addNonceVerification.Missingto the existing ignore.redirect_togoes throughwp_sanitize_redirect()beforewp_validate_redirect(), which already calls it, andREQUEST_URIgoes throughesc_url_raw()before only its path is compared with/lost-password/.text-centered-statement-smallpattern is built inline and the sentence is printed throughwp_kses_post(). The rendered markup is the same.is_wp_error()on aWP_Error,isset()on a regex group that always exists,is_string()on astrtok()of a non-empty locale), andarray_filter( ..., 'strlen' )became a callback that drops empty strings. The salts used to decrypt the deploy token (AUTH_KEY,SECURE_AUTH_SALT,NONCE_SALT) are defined inwp-config.php, andWC()->cartisnulluntil WooCommerce loads the cart although the stubs type it asWC_Cart; both are ignored inphpstan.neon.dist, scoped to their file.Verification
composer cipasses locally./lost-password/,?action=lostpassword, the shop, the cart, two product pages, the checkout redirect and a 404 is byte for byte the same onmainand on this branch (nonces and asset versions normalized).