SonarSource Rules
  • Products

    In-IDE

    Code Quality and Security in your IDE with SonarQube Ide

    IDE extension that lets you fix coding issues before they exist!

    Discover SonarQube for IDE

    SaaS

    Code Quality and Security in the cloud with SonarQube Cloud

    Setup is effortless and analysis is automatic for most languages

    Discover SonarQube Cloud

    Self-Hosted

    Code Quality and Security Self-Hosted with SonarQube Server

    Fast, accurate analysis; enterprise scalability

    Discover SonarQube Server
  • SecretsSecrets
  • ABAPABAP
  • AnsibleAnsible
  • ApexApex
  • AzureResourceManagerAzureResourceManager
  • CC
  • C#C#
  • C++C++
  • CloudFormationCloudFormation
  • COBOLCOBOL
  • CSSCSS
  • DartDart
  • DockerDocker
  • FlexFlex
  • GitHub ActionsGitHub Actions
  • GoGo
  • HTMLHTML
  • JavaJava
  • JavaScriptJavaScript
  • JSONJSON
  • JCLJCL
  • KotlinKotlin
  • KubernetesKubernetes
  • Objective CObjective C
  • PHPPHP
  • PL/IPL/I
  • PL/SQLPL/SQL
  • PythonPython
  • RPGRPG
  • RubyRuby
  • RustRust
  • ScalaScala
  • ShellShell
  • SwiftSwift
  • TerraformTerraform
  • TextText
  • TypeScriptTypeScript
  • T-SQLT-SQL
  • VB.NETVB.NET
  • VB6VB6
  • XMLXML
  • YAMLYAML
PHP

PHP static code analysis

Unique rules to find Bugs, Vulnerabilities, Security Hotspots, and Code Smells in your PHP code

  • All rules 273
  • Vulnerability42
  • Bug51
  • Security Hotspot34
  • Code Smell146
Filtered: 10 rules found
clumsy
    Impact
      Clean code attribute
        1. Jump statements should not be redundant

           Code Smell
        2. "catch" clauses should do more than rethrow

           Code Smell
        3. String literals should not be concatenated

           Code Smell
        4. Local variables should not be declared and then immediately returned or thrown

           Code Smell
        5. A "while" loop should be used instead of a "for" loop

           Code Smell
        6. Overriding methods should do more than simply call the same method in the super class

           Code Smell
        7. "empty()" should be used to test for emptiness

           Code Smell
        8. Return of boolean expressions should not be wrapped into an "if-then-else" statement

           Code Smell
        9. Boolean literals should not be redundant

           Code Smell
        10. Mergeable "if" statements should be combined

           Code Smell

        Local variables should not be declared and then immediately returned or thrown

        intentionality - clear
        maintainability
        Code Smell
        • clumsy

        Why is this an issue?

        Declaring a variable only to immediately return or throw it is considered a bad practice because it adds unnecessary complexity to the code. This practice can make the code harder to read and understand, as it introduces an extra step that doesn’t add any value. Instead of declaring a variable and then immediately returning or throwing it, it is generally better to return or throw the value directly. This makes the code cleaner, simpler, and easier to understand.

        Noncompliant code example

        function computeDurationInMilliseconds() {
          $duration = ((($hours * 60) + $minutes) * 60 + $seconds ) * 1000 ;
          return $duration;
        }
        

        Compliant solution

        function computeDurationInMilliseconds() {
          return ((($hours * 60) + $minutes) * 60 + $seconds ) * 1000;
        }
        
          Available In:
        • SonarQube IdeCatch issues on the fly,
          in your IDE
        • SonarQube CloudDetect issues in your GitHub, Azure DevOps Services, Bitbucket Cloud, GitLab repositories
        • SonarQube Community BuildAnalyze code in your
          on-premise CI
          Available Since
          9.1
        • SonarQube ServerAnalyze code in your
          on-premise CI
          Developer Edition
          Available Since
          9.1

        © 2008-2025 SonarSource SA. All rights reserved.

        Privacy Policy | Cookie Policy | Terms of Use