A complete PHP language pack for CodeQL
Extractor · AST · CFG · SSA · interprocedural taint · framework models · security queries
PHP powers a huge share of the web, yet has no first-party CodeQL support. This fork adds a
php/ language pack that plugs into the standard CodeQL toolchain and reuses the language-agnostic
shared/ engine (dataflow, SSA, control-flow, tree-sitter extractor) — so PHP gets the same global
taint tracking, path queries and Models-as-Data extensibility as Java, Ruby or Python.
The guiding principle is no blind spots: no execution path or data-flow branch is silently dropped because a syntactic case wasn't modelled. Where the static model is incomplete, the analysis over-approximates (a possible false positive) rather than cutting a path (a silent false negative).
php/
├── extractor/ Rust extractor (tree-sitter-php → TRAP), ~250 LOC over shared/tree-sitter-extractor
├── ql/lib/ The language library:
│ ├── ast/ AST wrappers (classes, calls, expressions, statements, namespaces)
│ ├── controlflow/ CFG with real branching for if / if-else and while / do loops (SSA φ at joins)
│ ├── dataflow/ SSA, local flow, type inference, interprocedural taint steps
│ ├── security/ Sources, sinks, sanitizers, framework abstractions
│ └── ext/ Models-as-Data: Laravel · Symfony · WordPress · PrestaShop · TYPO3 · crypto
├── ql/src/ 13 security queries + coverage/routing utilities
└── ql/test/ 45 tests (30 query-tests + 15 library-tests)
- Type-based call resolution. A dedicated type-inference layer (
exprClass,viableCallable) resolves method targets by the receiver's type (new C(),$this, typed params/properties, SSA, declared returns, fluentreturn $this,clone, dynamicnew $c()), with a name-based fallback for recall.$safe->run()is no longer a false positive. - Real control-flow branching.
if/if-elseproduce genuine SSA φ at the join, and taint crosses the join via phi-input flow (definitionReachingValue) — not a linearised approximation. - All the PHP that trips other tools. Magic methods (
__get/__call/__invoke/__toString/…), named arguments, references (&), generators, closures/arrow captures,parse_str, exceptions, higher-order callbacks,$GLOBALS, cross-file globals, dynamic instantiation, type juggling (CWE-697). - Frameworks as data. Laravel, Symfony, WordPress, PrestaShop and TYPO3 sources/sinks/steps ship
as
ext/*.model.yml— community-extensible with zero engine changes.
Requires the CodeQL CLI. See
DEV.mdfor the full, reproducible setup.
# 1. Build the extractor + pack
php/build.sh
# 2. Create a database from a PHP project
codeql database create mydb --language=php --source-root=/path/to/app --search-path=php
# 3. Run the security suite
codeql database analyze mydb php/ql/src/codeql-suites/php-security.qls \
--format=csv --output=results.csv --search-path=php --additional-packs=.
# 4. Run the tests
codeql test run php/ql/test --search-path=php --additional-packs=.Benchmarked on DVWA (Damn Vulnerable Web Application): 50 taint findings across SQLi, command
injection, XSS, path traversal, etc., 17 type-juggling findings, and only the paths in
impossible.php (prepared-statement guarded) are surfaced — a documented, bounded over-approximation.
The php/ql/test suite has 45 green tests covering each engine feature.
This is active research toward a production-grade PHP analyzer. The engine foundations (type
inference, dispatch, taint steps, framework models, and if/if-else control-flow branching) are in
place and tested. Remaining work — loops, switch/match, short-circuit operators, sanitizer
guards, engine-level post-update, and a labelled precision/recall corpus — is tracked, per pipeline
stage and test-first, in:
PROJECT_STATUS.md— single-page handoff: done / remaining / how to resumeSTRUCTURAL_ROADMAP.md— detailed roadmap by CodeQL pipeline stageIMPROVEMENTS.md— audit-driven improvement plan (~30 items)THREAT_MODEL.md— soundness scope and assumed over-approximations
Built on github/codeql, licensed under the
MIT License. The added php/ pack follows the same license.
This repository is a research fork and is not affiliated with or endorsed by GitHub.