k-kinzal / sql-catalog
Catalog the SQL statements a PHP application issues, by static analysis
dev-main
2026-09-28 02:32 UTC
Requires
- php: ^8.1
- ext-json: *
- k-kinzal/sql-formatter: dev-main
- k-kinzal/sql-parser: dev-main
- nikic/php-parser: ^5.0
- symfony/yaml: ^6.4
Requires (Dev)
- ext-pdo: *
- ext-pdo_sqlite: *
- brianium/paratest: ^7.3
- deptrac/deptrac: ^3.0
- friendsofphp/php-cs-fixer: ^3.95.25
- k-kinzal/php-ai-toolkit: dev-main
- k-kinzal/sql-faker: dev-main
- k-kinzal/sql-fixture: dev-main
- nikic/php-fuzzer: ^0.0.11
- opis/json-schema: ^2.4
- phpcompatibility/php-compatibility: ^10.0.0-alpha2
- phpmyadmin/sql-parser: ^5.11
- phpstan/phpstan: ^2.1
- phpstan/phpstan-strict-rules: ^2.0
- phpunit/phpunit: ^10.5
- squizlabs/php_codesniffer: ^4.0.4
Suggests
None
Provides
None
Conflicts
None
Replaces
None
This package is auto-updated.
Last update: 2026-09-28 02:32:41 UTC
README
SQL Catalog reads PHP source and reports every statement the code can send to a database: the statement text, the tables it names, the values bound to its placeholders, and where in the source it is issued. Nothing runs, and no database is needed. A statement assembled from a value the analyzer cannot follow is reported as the shape it has, with the gap marked and traced back to where the value came from.
Requirements
- PHP 8.1+
Getting Started
$ composer require --dev k-kinzal/sql-catalog $ vendor/bin/sql-catalog --help sql-catalog — catalog the SQL statements a PHP application issues Usage: sql-catalog [options] <path>... Output: -o, --output=DIR Write the report into DIR instead of standard output -r, --reporter=NAME Render with NAME (default: text on standard output, json into a directory) What to read: -c, --config=FILE Read catalog settings (default: .catalog.yaml) -e, --extension=NAME Recognise the database calls of NAME; repeatable (default: pdo,mysqli) --dialect=NAME Framework builder grammar: mysql, pgsql or sqlite --exclude=PATTERN Skip source files whose reported path matches; repeatable --root=DIR Report paths relative to DIR (default: the working directory) What to keep: --namespace=NS Keep statements issued under a namespace; repeatable --method=NAME Keep statements issued in a function, as name or Class::method; repeatable --path=PATTERN Keep statements from files matching a pattern; repeatable --kind=KIND Keep statements of a kind, such as select or insert; repeatable --table=NAME Keep statements naming a table; repeatable --sink=ID Keep statements found at a database call, such as pdo.prepare; repeatable --severity=LEVEL Keep statements reported at LEVEL or above Exit status: --fail-on=LEVEL Exit with 1 when a statement is reported at LEVEL or above Information: --list-extensions List the extensions this build recognises --list-reporters List the reporters this build can render with -h, --help Show this help Values given to a repeatable option may also be written separated by commas.
License
MIT License. See LICENSE for details.