rlorenzo / mago-wordpress
Mago extension for WordPress: WPCS-equivalent linter rules.
Fund package maintenance!
Requires
- php: ^8.1
- ext-dom: *
- ext-libxml: *
- ext-tokenizer: *
- carthage-software/mago: ^1.47.1
Requires (Dev)
- phpunit/phpunit: ^10.5 || ^11.5 || ^12.0
Suggests
None
Provides
None
Conflicts
None
Replaces
None
- dev-main
- v1.2.0
- v1.1.0
- v1.0.1
- v1.0.0
- v0.2.0
- v0.1.0
- dev-stack/12-port-group-3
- dev-stack/11-port-group-2
- dev-stack/10-port-group-1
- dev-stack/09-worker-memory-validation
- dev-stack/08-preset-levels-and-core-rules
- dev-stack/07-format-and-convert-fixes
- dev-stack/06-adoption-guide
- dev-stack/05-tokenizer-perf
- dev-stack/04-severity-levels
- dev-stack/03-presets-and-standard
- dev-stack/02-convert-comments
- dev-stack/01-format-command
- dev-fix/phpcs-array-properties
- dev-feat/port-db-alt
- dev-feat/port-escape-output
- dev-feat/port-input-nonce
This package is auto-updated.
Last update: 2026-10-03 06:07:43 UTC
README
WordPress Coding Standards for Mago. This extension ports the WPCS lint sniffs to Mago's linter, so a plugin or theme is checked in seconds, not minutes.
2–12× faster than phpcs
8.1× faster overall on the top 10 WordPress.org plugins plus WordPress core. Method and numbers: Benchmarks.
Install
composer require --dev carthage-software/mago rlorenzo/mago-wordpress
# mago.toml extends = "vendor/rlorenzo/mago-wordpress/wordpress.mago.toml"
Run mago lint. You get this package's 52 default rules, Mago's own WordPress security rules
and a WordPress formatter preset.
The worker runs as PHP inside your project and loads its Composer autoloader, like PHPUnit or PHPStan, so only lint projects you trust.
Configure
Settings go in composer.json:
{
"extra": {
"mago-wordpress": {
"text-domains": ["my-plugin"],
"prefixes": ["myplugin"],
"minimum-wp-version": "6.4"
}
}
}
- Already using phpcs? Without this block, the same settings and exclusions are read from your
phpcs.xml. - Existing
phpcs:ignoreandphpcs:disablecomments still work. - Turn a rule off with
exclude-patterns, under its WPCS code.[linter.rules]doesn't acceptwordpress/*codes.
All settings: Configuration.
Migrate from phpcs
vendor/bin/mago-wordpress migrate # print the mago.toml and composer.json settings vendor/bin/mago-wordpress migrate --write # save them
It also lists anything it couldn't carry over. See Migrating from phpcs.
Format
mago format can't add the spaces WordPress puts inside parentheses, so a lint fix adds them
afterwards. Always run the three steps together, because mago format removes the spaces again:
mago lint --fix --only array-style mago format mago lint --fix --only wordpress/parentheses-spacing
See Formatting.
Docs
- Rules: the 53 rules, their levels and their autofixes.
- Configuration: every setting, the
phpcs.xmlfallback and suppression comments. - Formatting: the preset and what still differs from WPCS.
- Migrating from phpcs: what
migrateconverts and what it can't. - WPCS coverage: Mago's own WordPress rules,
WordPress-Docs, the generic sniffs, and what isn't ported. - Benchmarks: method and full results.
Development
composer install # also points git at .githooks (pre-commit runs `just check`) just check # composer validate, format-check, PHPUnit, mago lint + analyze, corpus
Rule tests run a real Mago worker against tests/corpus/rules/<rule>/. Each expected report is
marked with // @mago-expect lint:wordpress/<rule> on the line before it, and any report without
a matching expectation fails. CI runs just check on PHP 8.1, 8.4 and 8.5.
Credits
Generic syntax helpers are adapted from amateescu/mago-drupal
(MIT) and the rule data from WordPress Coding Standards
(MIT); see NOTICE.md. The rules were first written in Rust for the Mago fork at
rlorenzo/mago and ported here after Mago gained worker extensions.