Skip to content
 
 

Latest commit

 

History

88,790 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

CodeQL for PHP

A complete PHP language pack for CodeQL
Extractor · AST · CFG · SSA · interprocedural taint · framework models · security queries

tests queries frameworks status


Why

PHP powers a huge share of the web, yet has no first-party CodeQL support. This fork adds a php/ language pack that plugs into the standard CodeQL toolchain and reuses the language-agnostic shared/ engine (dataflow, SSA, control-flow, tree-sitter extractor) — so PHP gets the same global taint tracking, path queries and Models-as-Data extensibility as Java, Ruby or Python.

The guiding principle is no blind spots: no execution path or data-flow branch is silently dropped because a syntactic case wasn't modelled. Where the static model is incomplete, the analysis over-approximates (a possible false positive) rather than cutting a path (a silent false negative).

What's inside

php/
├── extractor/        Rust extractor (tree-sitter-php → TRAP), ~250 LOC over shared/tree-sitter-extractor
├── ql/lib/           The language library:
│   ├── ast/          AST wrappers (classes, calls, expressions, statements, namespaces)
│   ├── controlflow/  CFG with real branching for if / if-else and while / do loops (SSA φ at joins)
│   ├── dataflow/     SSA, local flow, type inference, interprocedural taint steps
│   ├── security/     Sources, sinks, sanitizers, framework abstractions
│   └── ext/          Models-as-Data: Laravel · Symfony · WordPress · PrestaShop · TYPO3 · crypto
├── ql/src/           13 security queries + coverage/routing utilities
└── ql/test/          45 tests (30 query-tests + 15 library-tests)

Highlights

  • Type-based call resolution. A dedicated type-inference layer (exprClass, viableCallable) resolves method targets by the receiver's type (new C(), $this, typed params/properties, SSA, declared returns, fluent return $this, clone, dynamic new $c()), with a name-based fallback for recall. $safe->run() is no longer a false positive.
  • Real control-flow branching. if / if-else produce genuine SSA φ at the join, and taint crosses the join via phi-input flow (definitionReachingValue) — not a linearised approximation.
  • All the PHP that trips other tools. Magic methods (__get/__call/__invoke/__toString/…), named arguments, references (&), generators, closures/arrow captures, parse_str, exceptions, higher-order callbacks, $GLOBALS, cross-file globals, dynamic instantiation, type juggling (CWE-697).
  • Frameworks as data. Laravel, Symfony, WordPress, PrestaShop and TYPO3 sources/sinks/steps ship as ext/*.model.yml — community-extensible with zero engine changes.

Quick start

Requires the CodeQL CLI. See DEV.md for the full, reproducible setup.

# 1. Build the extractor + pack
php/build.sh

# 2. Create a database from a PHP project
codeql database create mydb --language=php --source-root=/path/to/app --search-path=php

# 3. Run the security suite
codeql database analyze mydb php/ql/src/codeql-suites/php-security.qls \
    --format=csv --output=results.csv --search-path=php --additional-packs=.

# 4. Run the tests
codeql test run php/ql/test --search-path=php --additional-packs=.

Validation

Benchmarked on DVWA (Damn Vulnerable Web Application): 50 taint findings across SQLi, command injection, XSS, path traversal, etc., 17 type-juggling findings, and only the paths in impossible.php (prepared-statement guarded) are surfaced — a documented, bounded over-approximation. The php/ql/test suite has 45 green tests covering each engine feature.

Status & roadmap

This is active research toward a production-grade PHP analyzer. The engine foundations (type inference, dispatch, taint steps, framework models, and if/if-else control-flow branching) are in place and tested. Remaining work — loops, switch/match, short-circuit operators, sanitizer guards, engine-level post-update, and a labelled precision/recall corpus — is tracked, per pipeline stage and test-first, in:

License

Built on github/codeql, licensed under the MIT License. The added php/ pack follows the same license.

This repository is a research fork and is not affiliated with or endorsed by GitHub.

About

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

Resources

Code of conduct

Contributing

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages