Search by

zalas / toolbox

jakzal

Helps to discover and install tools

Package info

github.com/jakzal/toolbox

Type:project

pkg:composer/zalas/toolbox

Fund package maintenance!

jakzal

Statistics

Installs: 78

Dependents: 0

Suggesters: 0

Stars: 201

Open Issues: 3

v1.112.0 2026-08-13 20:04 UTC

This package is auto-updated.

Last update: 2026-09-13 20:39:05 UTC


README

Build Status

Helps to discover and install tools.

Use cases

Toolbox started its life as a simple script in the phpqa docker image. Its purpose was to install set of tools while building the docker image and it's still its main goal. It has been extracted as a separate project to make maintenance easier and enable new use cases.

Available tools

Name Description PHP 8.3 PHP 8.4 PHP 8.5
behat Helps to test business expectations ✅ ✅ ✅
box Fast, zero config application bundler with PHARs ✅ ✅ ✅
churn Discovers good candidates for refactoring ✅ ✅ ✅
codeception Codeception is a BDD-styled PHP testing framework ✅ ✅ ✅
composer Dependency Manager for PHP ✅ ✅ ✅
composer-bin-plugin Composer plugin to install bin vendors in isolated locations ✅ ✅ ✅
composer-lock-diff Composer plugin to check what has changed after a composer update ✅ ✅ ✅
composer-normalize Composer plugin to normalize composer.json files ✅ ✅ ✅
composer-require-checker Verify that no unknown symbols are used in the sources of a package. ❌ ✅ ✅
composer-require-checker-3 Verify that no unknown symbols are used in the sources of a package. ✅ ✅ ✅
composer-unused Show unused packages by scanning your code ✅ ✅ ✅
cyclonedx-php-composer Composer plugin to create Software-Bill-of-Materials (SBOM) in CycloneDX format ✅ ✅ ✅
dephpend Detect flaws in your architecture ✅ ✅ ✅
deprecation-detector Finds usages of deprecated code ✅ ✅ ✅
deptrac Enforces dependency rules between software layers ✅ ✅ ✅
diffFilter Applies QA tools to run on a single pull request ✅ ✅ ✅
ecs Sets up and runs coding standard checks ✅ ✅ ✅
gherkin-lint-php Gherkin linter for PHP ✅ ✅ ✅
infection AST based PHP Mutation Testing Framework ✅ ✅ ✅
jack Helps to upgrade outdated Composer dependencies incrementally ✅ ✅ ✅
kahlan Kahlan is a full-featured Unit & BDD test framework a la RSpec/JSpec ✅ ✅ ✅
larastan PHPStan extension for Laravel ✅ ✅ ✅
lines CLI tool for quick metrics of PHP projects ✅ ✅ ✅
mago A blazing fast linter, formatter, and static analyzer for PHP, written in Rust ✅ ✅ ✅
parallel-lint Checks PHP file syntax ✅ ✅ ✅
paratest Parallel testing for PHPUnit ✅ ✅ ✅
pdepend Static Analysis Tool ✅ ✅ ✅
phan Static Analysis Tool ✅ ✅ ✅
phive PHAR Installation and Verification Environment ✅ ✅ ✅
php-cs-fixer PHP Coding Standards Fixer ✅ ✅ ✅
php-fuzzer A fuzzer for PHP, which can be used to find bugs in libraries by feeding them 'random' inputs ✅ ✅ ✅
php-semver-checker Suggests a next version according to semantic versioning ✅ ✅ ✅
phpa Checks for weak assumptions ✅ ✅ ✅
phparkitect Helps to put architectural constraints in a PHP code base ✅ ✅ ✅
phpat Easy to use architecture testing tool ✅ ✅ ✅
phpbench PHP Benchmarking framework ✅ ✅ ✅
phpca Finds usage of non-built-in extensions ✅ ✅ ✅
phpcb PHP Code Browser ✅ ✅ ✅
phpcbf Automatically corrects coding standard violations ✅ ✅ ✅
phpcodesniffer-composer-install Easy installation of PHP_CodeSniffer coding standards (rulesets). ✅ ✅ ✅
phpcov a command-line frontend for the PHP_CodeCoverage library ❌ ✅ ✅
phpcpd Copy/Paste Detector ❌ ✅ ✅
phpcpd-next Copy/Paste Detector (next generation) ❌ ❌ ✅
phpcs Detects coding standard violations ✅ ✅ ✅
phpcs-security-audit Finds vulnerabilities and weaknesses related to security in PHP code ✅ ✅ ✅
phpdd Finds usage of deprecated features ✅ ✅ ✅
phpDocumentor Documentation generator ✅ ✅ ✅
phpinsights Analyses code quality, style, architecture and complexity ✅ ✅ ✅
phplint Lints php files in parallel ✅ ✅ ✅
phploc A tool for quickly measuring the size of a PHP project ✅ ✅ ✅
phpmd A tool for finding problems in PHP code ✅ ✅ ✅
phpmetrics Static Analysis Tool ✅ ✅ ✅
phpmnd Helps to detect magic numbers ✅ ✅ ✅
phpspec SpecBDD Framework ✅ ✅ ✅
phpstan Static Analysis Tool ✅ ✅ ✅
phpstan-banned-code PHPStan rules for detecting calls to specific functions you don't want in your project ✅ ✅ ✅
phpstan-beberlei-assert PHPStan extension for beberlei/assert ✅ ✅ ✅
phpstan-deprecation-rules PHPStan rules for detecting deprecated code ✅ ✅ ✅
phpstan-doctrine Doctrine extensions for PHPStan ✅ ✅ ✅
phpstan-ergebnis-rules Additional rules for PHPstan ✅ ✅ ✅
phpstan-larastan Separate installation of phpstan for larastan ✅ ✅ ✅
phpstan-phpunit PHPUnit extensions and rules for PHPStan ✅ ✅ ✅
phpstan-strict-rules Extra strict and opinionated rules for PHPStan ✅ ✅ ✅
phpstan-symfony Symfony extension for PHPStan ✅ ✅ ✅
phpstan-webmozart-assert PHPStan extension for webmozart/assert ✅ ✅ ✅
phpunit The PHP testing framework ❌ ✅ ✅
phpunit-10 The PHP testing framework (10.x version) ✅ ✅ ✅
phpunit-11 The PHP testing framework (11.x version) ✅ ✅ ✅
phpunit-12 The PHP testing framework (12.x version) ✅ ✅ ✅
phpunit-8 The PHP testing framework (8.x version) ✅ ✅ ✅
phpunit-9 The PHP testing framework (9.x version) ✅ ✅ ✅
pint Opinionated PHP code style fixer for Laravel ✅ ✅ ✅
psalm Finds errors in PHP applications ✅ ✅ ✅
psalm-plugin-doctrine Stubs to let Psalm understand Doctrine better ✅ ✅ ✅
psalm-plugin-phpunit Psalm plugin for PHPUnit ✅ ✅ ✅
psalm-plugin-symfony Psalm Plugin for Symfony ✅ ✅ ✅
psecio-parse Scans code for potential security-related issues ✅ ✅ ✅
rector Tool for instant code upgrades and refactoring ✅ ✅ ✅
roave-backward-compatibility-check Tool to compare two revisions of a class API to check for BC breaks ✅ ✅ ✅
simple-phpunit Provides utilities to report legacy tests and usage of deprecated code ✅ ✅ ✅
twig-cs-fixer Automatically corrects twig files following the official coding standard rules ✅ ✅ ✅
twig-lint Standalone cli twig 1.X linter ✅ ✅ ✅
twig-linter Standalone cli twig 3.X linter ✅ ✅ ✅
twigcs The missing checkstyle for twig! ✅ ✅ ✅
yaml-lint Compact command line utility for checking YAML file syntax ✅ ✅ ✅

Removed tools

Name Summary
analyze Visualizes metrics and source code
box-legacy Legacy version of box
design-pattern Detects design patterns
local-php-security-checker Checks composer dependencies for known security vulnerabilities
parallel-lint Checks PHP file syntax
pest The elegant PHP Testing Framework
php-coupling-detector Detects code coupling issues
php-formatter Custom coding standards fixer
phpcf Finds usage of deprecated features
phpcpd Copy/Paste Detector
phpda Generates dependency graphs
phpdoc-to-typehint Automatically adds type hints and return types based on PHPDocs
phpstan-exception-rules PHPStan rules for checked and unchecked exceptions
phpstan-localheinz-rules Additional rules for PHPstan
phpunit-5 The PHP testing framework (5.x version)
phpunit-7 The PHP testing framework (7.x version)
security-checker Checks composer dependencies for known security vulnerabilities
testability Analyses and reports testability issues of a php codebase

Installation

Get the toolbox.phar from the latest release. The command below should do the job:

curl -Ls https://github.com/jakzal/toolbox/releases/latest/download/toolbox.phar -o toolbox && chmod +x toolbox

Usage

List available tools

./toolbox list-tools

Filter tools by tags

To exclude some tools from the listing multiple --exclude-tag options can be added. The --tag option can be used to filter tools by tags.

./toolbox list-tools --exclude-tag exclude-php:8.3 --exclude-tag foo --tag bar

Install tools

./toolbox install

Install tools in a custom directory

By default tools are installed in the /usr/local/bin directory. To perform an installation in another location, pass the --target-dir option to the install command. Also, to change the location composer packages are installed in, export the COMPOSER_HOME environment variable.

mkdir /tools
export COMPOSER_HOME=/tools/.composer
export PATH="/tools:$COMPOSER_HOME/vendor/bin:$PATH"
./toolbox install --target-dir /tools

The target dir can also be configured with the TOOLBOX_TARGET_DIR environment variable.

Dry run

To only see what commands would be executed, use the dry run mode:

./toolbox install --dry-run

Filter tools by tags

To exclude some tools from the installation multiple --exclude-tag options can be added. The --tag option can be used to filter tools by tags.

./toolbox install --exclude-tag exclude-php:8.3 --exclude-tag foo --tag bar

Test if installed tools are usable

./toolbox test

Dry run

To only see what commands would be executed, use the dry run mode:

./toolbox test --dry-run

Filter tools by tags

To exclude some tools from the generated test command multiple --exclude-tag options can be added. The --tag option can be used to filter tools by tags.

./toolbox test --exclude-tag exclude-php:8.3 --exclude-tag foo --tag bar

Tools definitions

By default the following files are used to load tool definitions:

  • resources/pre-installation.json
  • resources/architecture.json
  • resources/checkstyle.json
  • resources/compatibility.json
  • resources/composer.json
  • resources/deprecation.json
  • resources/documentation.json
  • resources/linting.json
  • resources/metrics.json
  • resources/phpstan.json
  • resources/psalm.json
  • resources/refactoring.json
  • resources/security.json
  • resources/test.json
  • resources/tools.json

Definitions can be loaded from customised files by passing the --tools option(s):

./toolbox list-tools --tools path/to/file1.json --tools path/to/file2.json

Tool definition location(s) can be also specified with the TOOLBOX_JSON environment variable:

TOOLBOX_JSON='path/to/file1.json,path/to/file2.json' ./toolbox list-tools

Tool tags

Tools can be tagged in order to enable grouping and filtering them.

The tags below have a special meaning:

  • pre-installation - these tools will be installed before any other tools.
  • exclude-php:8.3, exclude-php:8.4 etc - used to exclude installation on the specified php version.

Contributing

Please read the Contributing guide to learn about contributing to this project. Please note that this project is released with a Contributor Code of Conduct. By participating in this project you agree to abide by its terms.