Search by

glomberg / wpdb-unsafe-methods

Glomberg

Psalm plugin to forbid calling provided `$wpdb` methods

Package info

github.com/Glomberg/psalm-wpdb-unsafe-methods

Type:psalm-plugin

pkg:composer/glomberg/wpdb-unsafe-methods

Statistics

Installs: 2 480

Dependents: 0

Suggesters: 0

Stars: 0

Open Issues: 0

1.0.2 2026-09-07 05:49 UTC

This package is auto-updated.

Last update: 2026-09-07 05:51:15 UTC


README

Installation

composer require --dev glomberg/wpdb-unsafe-methods
vendor/bin/psalm --init
vendor/bin/psalm-plugin enable glomberg/wpdb-unsafe-methods

Features

  • Flags configured $wpdb methods when the SQL argument is a raw string, concatenation, interpolated string, or sprintf()-like function call.
  • Inspects the first argument only, so extra args such as ARRAY_A / OBJECT do not hide an unprepared query: $wpdb->query($sql, ARRAY_A) is treated the same as $wpdb->query($sql).
  • $wpdb->prepare(...) (and a variable assigned from prepare()) is allowed.
  • @psalm-suppress WpdbUnsafeMethodsIssue on the line above the call still silences the issue.

Configuration

If you follow the installation instructions, the psalm-plugin command will add this plugin configuration to the psalm.xml configuration file.

<?xml version="1.0"?>
<psalm errorLevel="1">
    <!--  project configuration -->

    <plugins>
        <pluginClass class="Glomberg\WpdbUnsafeMethods\Plugin" />
    </plugins>
</psalm>

Do not forget to add method tags with the names of the methods you want to forbid.

<pluginClass class="Glomberg\WpdbUnsafeMethods\Plugin">
    <method>query</method>
    <method>get_results</method>
</pluginClass>