V
V
VicTHOR2021-05-31 10:50:51
linux
VicTHOR, 2021-05-31 10:50:51

How to analyze PHP code for security without starting the server?

It is necessary to analyze the project folder for threats of XSS attacks, SQL injections and other things from the console and get the result in the same place in some json, is there a similar tool?

Answer the question

In order to leave comments, you need to log in

4 answer(s)
C
ComodoHacker, 2021-05-31
@ComodoHacker

https://duckduckgo.com/?q=php+static+analyzer

M
Maksim Fedorov, 2021-05-31
@Maksclub

Security Analysis in Psalm
Roave Security Advisories - installed as a composer package

V
Vitaly Karasik, 2021-05-31
@vitaly_il1

Such tools are called "static code scanner", for example https://www.sonarqube.org/

B
Boris Syomov, 2021-05-31
@kotomyava

The closest tool in terms of functionality is a qualified developer who will review the code. =)

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question