Psalm and How the Two Compare

Psalm (github.com/vimeo/psalm (https://github.com/vimeo/psalm 5,890 ), begun at Vimeo) is stable at 6.18.0 (21 September 2026), with 7.0 in beta since March 2025. vendor/bin/psalm --init src 3 writes psalm.xml; its levels run from 8 (loosest) to 1. On Invoice.php it reported the null fetch, the typo and the string argument, plus two info issues. Its standout is taint analysis, which follows user input to dangerous sinks. psalm --taint-analysis public/search.php on a reflected XSS:

public/search.php, a reflected XSS (Subsection 4.17.5)PHP
<?php
$q = $_GET['q'] ?? '';
echo '<h1>Results for ' . $q . '</h1>';          // reflected XSS (Section 4.17.5)
Output
...
ERROR: TaintedHtml - public/search.php:3:6 - Detected tainted HTML (see https://psalm.dev/245)
...
  $_GET['q'] - public/search.php:2:6
...

With htmlspecialchars($q) the run prints "No errors found!"; the same analysis finds TaintedSql and TaintedShell.

PHPStan 376,908 and Psalm compared (both MIT, September 2026)
PHPStan 2.2 Psalm 6.18
Levels 0 (loose) to 10 (strict) 8 (loose) to 1 (strict)
Taint analysis No Built in
Baseline --generate-baseline --set-baseline
Automatic fixes --fix (experimental) Psalter (--alter)

Both read the same docblock types. PHPStan has the larger plugin ecosystem (Larastan 6,520 , Doctrine 159,716 ); Psalm's taint analysis earns it a place on code that handles input.