Search by

rlorenzo / mago-wordpress

rlorenzo

Mago extension for WordPress: WPCS-equivalent linter rules.

Package info

github.com/rlorenzo/mago-wordpress

pkg:composer/rlorenzo/mago-wordpress

Fund package maintenance!

rlorenzo

Statistics

Installs: 8

Dependents: 0

Suggesters: 0

Stars: 0

Open Issues: 12

v1.2.0 2026-10-02 00:53 UTC

README

CI Packagist version Packagist downloads PHP 8.1+ Mago 1.47+ License: MIT

WordPress Coding Standards for Mago. This extension ports the WPCS lint sniffs to Mago's linter, so a plugin or theme is checked in seconds, not minutes.

2–12× faster than phpcs

Bar chart: phpcs WordPress-Extra vs mago + mago-wordpress lint time on the top 10 WordPress.org plugins by active installs and WordPress core, from WooCommerce (33.40 s vs 3.32 s) down to Akismet (0.52 s vs 0.26 s)

8.1× faster overall on the top 10 WordPress.org plugins plus WordPress core. Method and numbers: Benchmarks.

Install

composer require --dev carthage-software/mago rlorenzo/mago-wordpress
# mago.toml
extends = "vendor/rlorenzo/mago-wordpress/wordpress.mago.toml"

Run mago lint. You get this package's 52 default rules, Mago's own WordPress security rules and a WordPress formatter preset.

The worker runs as PHP inside your project and loads its Composer autoloader, like PHPUnit or PHPStan, so only lint projects you trust.

Configure

Settings go in composer.json:

{
  "extra": {
    "mago-wordpress": {
      "text-domains": ["my-plugin"],
      "prefixes": ["myplugin"],
      "minimum-wp-version": "6.4"
    }
  }
}
  • Already using phpcs? Without this block, the same settings and exclusions are read from your phpcs.xml.
  • Existing phpcs:ignore and phpcs:disable comments still work.
  • Turn a rule off with exclude-patterns, under its WPCS code. [linter.rules] doesn't accept wordpress/* codes.

All settings: Configuration.

Migrate from phpcs

vendor/bin/mago-wordpress migrate          # print the mago.toml and composer.json settings
vendor/bin/mago-wordpress migrate --write  # save them

It also lists anything it couldn't carry over. See Migrating from phpcs.

Format

mago format can't add the spaces WordPress puts inside parentheses, so a lint fix adds them afterwards. Always run the three steps together, because mago format removes the spaces again:

mago lint --fix --only array-style
mago format
mago lint --fix --only wordpress/parentheses-spacing

See Formatting.

Docs

  • Rules: the 53 rules, their levels and their autofixes.
  • Configuration: every setting, the phpcs.xml fallback and suppression comments.
  • Formatting: the preset and what still differs from WPCS.
  • Migrating from phpcs: what migrate converts and what it can't.
  • WPCS coverage: Mago's own WordPress rules, WordPress-Docs, the generic sniffs, and what isn't ported.
  • Benchmarks: method and full results.

Development

composer install   # also points git at .githooks (pre-commit runs `just check`)
just check         # composer validate, format-check, PHPUnit, mago lint + analyze, corpus

Rule tests run a real Mago worker against tests/corpus/rules/<rule>/. Each expected report is marked with // @mago-expect lint:wordpress/<rule> on the line before it, and any report without a matching expectation fails. CI runs just check on PHP 8.1, 8.4 and 8.5.

Credits

Generic syntax helpers are adapted from amateescu/mago-drupal (MIT) and the rule data from WordPress Coding Standards (MIT); see NOTICE.md. The rules were first written in Rust for the Mago fork at rlorenzo/mago and ported here after Mago gained worker extensions.