PHPStan 376,908 (github.com/phpstan/phpstan (https://github.com/phpstan/phpstan 14,112 ), 2.2.14 of 12 September 2026, composer require --dev phpstan/phpstan) has rule levels 0 to 10, each adding checks, so old code can start low. Errors in Invoice from phpstan analyse --level=N:
| Level | Adds (PHPStan docs) | Errors |
|---|---|---|
| 0-4 | Unknown symbols, PHPDocs, return types, dead code | 1 |
| 5 | Argument types | 2 |
| 6-7 | Missing type declarations, partly wrong unions | 4 |
| 8-9 | Nullable access, explicit mixed | 5 |
| 10 | Implicit mixed (new in 2.0) | 10 |
Level 8 suits new code. On old code, phpstan analyse --generate-baseline records today's errors (here 5) in phpstan-baseline.neon; include it, and CI fails only on new ones:
includes:
- phpstan-baseline.neon
parameters:
level: 8
paths:
- srcThe next day someone adds Coupon, which calls $cart->total(). The old errors stay silent:
...
8 Call to an undefined method Acme\Shop\Cart::total().
🪪 method.notFound
...// @phpstan-ignore method.notFound silences one check on one line; fixed baseline entries are reported as stale, so the baseline only shrinks.