AppSecNews
SAST Open source Established

Psalm

by Psalm project (originated at Vimeo)

Static analyzer for PHP combining type inference with an opt in taint mode that traces untrusted input to dangerous sinks.

Visit psalm.dev (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run Psalm in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What we still need to verify : 2 points in this profile are not yet confirmed against vendor documentation.
  • Maintenance cadence: the project's activity level has varied since its original maintainer stepped back, confirm current status
  • Integration list: confirm which editor and CI integrations are actively maintained

Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.

What it does

Psalm reads PHP source and builds a type model of the whole project, inferring types from signatures, docblocks, assignments and control flow, then reporting code that contradicts that model. It supports a richer annotation vocabulary than PHP's own type system: array shapes, literal string and integer types, class-string, template annotations for generics, and assertions that let you teach it what a custom validation function guarantees. Strictness is graded across error levels so an existing codebase can be adopted incrementally, and a baseline file can freeze existing violations while failing the build on new ones.

What sets it apart from a pure type checker is taint analysis, enabled explicitly rather than by default. In that mode Psalm treats data arriving from request superglobals and similar entry points as tainted, propagates the taint through assignments and function calls using the type graph it has already built, and reports when tainted data reaches a sink such as a database query, a shell execution, an include, or unescaped output. Annotations let you declare your own sources, sinks and sanitizers so the analysis understands your framework's escaping helpers instead of flagging every template write.

Where it fits

It is a composer installed command line tool run by developers locally and as a required continuous integration check. The taint pass is usually a separate, slower job than the type checking pass because it needs a full project graph. A language server lets editors show findings inline. For the taint results to be useful someone has to invest in annotating the codebase's own sanitizers, which means a security engineer and a developer working together for the first pass rather than turning a flag on and reading the output.

Strengths

  • Taint analysis in an open source PHP tool, which is uncommon and reaches injection classes type checkers cannot.
  • Expressive annotation system including generics and array shapes, allowing precise types where PHP itself has none.
  • Baselines and error levels give a workable path onto a legacy codebase.

Limitations

  • Taint mode is materially slower than plain analysis and needs custom sanitizer annotations before the false positive rate becomes tolerable.
  • PHP only. It says nothing about the JavaScript, infrastructure or dependencies around your application.
  • Project activity has been uneven, so verify maintenance status and the currency of PHP version support before making it a build gate.

Who it suits

A strong choice for a PHP team that wants type safety and is prepared to invest in annotations to get security findings from the same tool. If you want vulnerability detection with no configuration effort, or you need coverage beyond PHP, look at a dedicated scanner instead.

Used Psalm? Recommend it under your own name and title.

Recommend this tool