Psalm (github.com/vimeo/psalm (https://github.com/vimeo/psalm 5,890 ), begun at Vimeo) is stable at 6.18.0 (21 September 2026), with 7.0 in beta since March 2025. vendor/bin/psalm --init src 3 writes psalm.xml; its levels run from 8 (loosest) to 1. On Invoice.php it reported the null fetch, the typo and the string argument, plus two info issues. Its standout is taint analysis, which follows user input to dangerous sinks. psalm --taint-analysis public/search.php on a reflected XSS:
<?php
$q = $_GET['q'] ?? '';
echo '<h1>Results for ' . $q . '</h1>'; // reflected XSS (Section 4.17.5)... ERROR: TaintedHtml - public/search.php:3:6 - Detected tainted HTML (see https://psalm.dev/245) ... $_GET['q'] - public/search.php:2:6 ...
With htmlspecialchars($q) the run prints "No errors found!"; the same analysis finds TaintedSql and TaintedShell.
| PHPStan 2.2 | Psalm 6.18 | |
|---|---|---|
| Levels | 0 (loose) to 10 (strict) | 8 (loose) to 1 (strict) |
| Taint analysis | No | Built in |
| Baseline | --generate-baseline | --set-baseline |
| Automatic fixes | --fix (experimental) | Psalter (--alter) |
Both read the same docblock types. PHPStan has the larger plugin ecosystem (Larastan 6,520 , Doctrine 159,716 ); Psalm's taint analysis earns it a place on code that handles input.