PHP Best Practices
Modern PHP 8.x patterns, PSR standards, type system best practices, and SOLID principles. Contains 51 rules for writing clean, maintainable PHP code.
Step 1: Detect PHP Version
Always check the project's PHP version before giving any advice. Features vary significantly across 8.0 - 8.5. Never suggest syntax that doesn't exist in the project's version.
Check composer.json for the required PHP version:
Also check the runtime version:
Feature Availability by Version
Only suggest features available in the detected version. If the user asks about upgrading or newer features, mention what becomes available at each version.
When to Apply
Reference these guidelines when:
- Writing or reviewing PHP code
- Implementing classes and interfaces
- Using PHP 8.x modern features
- Ensuring type safety
- Following PSR standards
- Applying design patterns
Rule Categories by Priority
Quick Reference
1. Type System (CRITICAL) — 9 rules
type-strict-mode- Declare strict types in every filetype-return-types- Always declare return typestype-parameter-types- Type all parameterstype-property-types- Type class propertiestype-union-types- Use union types effectivelytype-intersection-types- Use intersection typestype-nullable-types- Handle nullable types properlytype-void-never- Use void/never for appropriate return typestype-mixed-avoid- Avoid mixed type when possible
2. Modern PHP Features (CRITICAL) — 16 rules
8.0+:
modern-constructor-promotion- Constructor property promotionmodern-match-expression- Match over switchmodern-named-arguments- Named arguments for claritymodern-nullsafe-operator- Nullsafe operator (?->)modern-attributes- Attributes for metadata
8.1+:
modern-enums- Enums instead of constantsmodern-enums-methods- Enums with methods and interfacesmodern-readonly-properties- Readonly for immutable datamodern-first-class-callables- First-class callable syntaxmodern-arrow-functions- Arrow functions (7.4+, pairs well with 8.1 features)
8.2+:
modern-readonly-classes- Readonly classes
8.3+:
modern-typed-constants- Typed class constants (const string NAME = 'foo')modern-override-attribute-#[\Override]to catch parent method typos
8.4+:
modern-property-hooks- Property hooks replacing getters/settersmodern-asymmetric-visibility-public private(set)for controlled access
8.5+:
modern-pipe-operator- Pipe operator (|>) for functional chaining
3. PSR Standards (HIGH) — 6 rules
psr-4-autoloading- Follow PSR-4 autoloadingpsr-12-coding-style- Follow PSR-12 coding stylepsr-naming-classes- Class naming conventionspsr-naming-methods- Method naming conventionspsr-file-structure- One class per filepsr-namespace-usage- Proper namespace usage
4. SOLID Principles (HIGH) — 5 rules
solid-srp- Single Responsibility: one reason to changesolid-ocp- Open/Closed: extend, don't modifysolid-lsp- Liskov Substitution: subtypes must be substitutablesolid-isp- Interface Segregation: small, focused interfacessolid-dip- Dependency Inversion: depend on abstractions
5. Error Handling (HIGH) — 5 rules
error-custom-exceptions- Create specific exceptions for different errorserror-exception-hierarchy- Organize exceptions into meaningful hierarchyerror-try-catch-specific- Catch specific exceptions, not generic \Exceptionerror-finally-cleanup- Use finally for guaranteed resource cleanuperror-never-suppress- Never use @ error suppression operator
6. Performance (MEDIUM) — 5 rules
perf-avoid-globals- Avoid global variables, use dependency injectionperf-lazy-loading- Defer expensive operations until neededperf-array-functions- Use native array functions over manual loopsperf-string-functions- Use native string functions over regexperf-generators- Use generators for large datasets
7. Security (CRITICAL) — 5 rules
sec-input-validation- Validate and sanitize all external inputsec-output-escaping- Escape output based on context (HTML, JS, URL)sec-password-hashing- Use password_hash/verify, never MD5/SHA1sec-sql-prepared- Use prepared statements for all SQL queriessec-file-uploads- Validate file type, size, name; store outside web root
Essential Guidelines
For detailed examples and explanations, see the rule files:
- type-strict-mode.md [blocked] - Strict types declaration
- modern-constructor-promotion.md [blocked] - Constructor property promotion
- modern-enums.md [blocked] - PHP 8.1+ enums with methods
- solid-srp.md [blocked] - Single responsibility principle
Key Patterns (Quick Reference)
Output Format
When auditing code, output findings in this format:
Example:
How to Use
Read individual rule files for detailed explanations:


