<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xml:lang="ru"><front><journal-meta><journal-id journal-id-type="publisher-id">uprinmatus</journal-id><journal-title-group><journal-title xml:lang="ru">Известия Юго-Западного государственного университета. Серия: Управление, вычислительная техника, информатика. Медицинское приборостроение</journal-title><trans-title-group xml:lang="en"><trans-title>Proceedings of the Southwest State University. Series: IT Management, Computer Science, Computer Engineering. Medical Equipment Engineering</trans-title></trans-title-group></journal-title-group><issn pub-type="ppub">2223-1536</issn><publisher><publisher-name>Юго-Западный государственный университет</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.21869/2223-1536-2026-16-2-167-181</article-id><article-id custom-type="elpub" pub-id-type="custom">uprinmatus-488</article-id><article-categories><subj-group subj-group-type="heading"><subject>Research Article</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="ru"><subject>СИСТЕМНЫЙ АНАЛИЗ И ПРИНЯТИЕ РЕШЕНИЙ</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="en"><subject>SYSTEM ANALYSIS AND DECISION-MAKING</subject></subj-group></article-categories><title-group><article-title>Сравнительное исследование инструментов статического анализа РНР-кода</article-title><trans-title-group xml:lang="en"><trans-title>Comparative study of PHP code static analysis tools</trans-title></trans-title-group></title-group><contrib-group><contrib contrib-type="author" corresp="yes"><contrib-id contrib-id-type="orcid">https://orcid.org/0009-0009-5291-4561</contrib-id><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Огневой</surname><given-names>Я. В.</given-names></name><name name-style="western" xml:lang="en"><surname>Ognevoy</surname><given-names>Ya. V.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Огневой Ярослав Владимирович, студент факультета информационных технологий</p><p>ул. Большая Семёновская, д. 38, г. Москва 107023</p></bio><bio xml:lang="en"><p>Yaroslav V. Ognevoy, Student at the Faculty of Information Technologies</p><p>38 Bolshaya Semyonovskaya Str., Moscow 107023</p></bio><email xlink:type="simple">ya.ognevoy@yandex.ru</email><xref ref-type="aff" rid="aff-1"/></contrib><contrib contrib-type="author" corresp="yes"><contrib-id contrib-id-type="orcid">https://orcid.org/0000-0003-3940-9607</contrib-id><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Спеваков</surname><given-names>А. Г.</given-names></name><name name-style="western" xml:lang="en"><surname>Spevakov</surname><given-names>A. G.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Спеваков Александр Геннадьевич, кандидат технических наук, доцент</p><p>ул. Большая Семёновская, д. 38, г. Москва 107023</p></bio><bio xml:lang="en"><p>Alexander G. Spevakov, Cand. Sci. (Engineering), Associate Professor</p><p>38 Bolshaya Semyonovskaya Str., Moscow 107023</p></bio><email xlink:type="simple">aspev@yandex.ru</email><xref ref-type="aff" rid="aff-1"/></contrib><contrib contrib-type="author" corresp="yes"><contrib-id contrib-id-type="orcid">https://orcid.org/0000-0003-0575-3055</contrib-id><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Калуцкий</surname><given-names>И. В.</given-names></name><name name-style="western" xml:lang="en"><surname>Kalutskiy</surname><given-names>I. V.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Калуцкий Игорь Владимирович, кандидат технических наук, доцент</p><p>ул. Большая Семёновская, д. 38, г. Москва 107023</p></bio><bio xml:lang="en"><p>Igor V. Kalutskiy, Cand. Sci. (Engineering), Associate Professor</p><p>38 Bolshaya Semyonovskaya Str., Moscow 107023</p></bio><email xlink:type="simple">kalutsky_igor@mail.ru</email><xref ref-type="aff" rid="aff-1"/></contrib><contrib contrib-type="author" corresp="yes"><contrib-id contrib-id-type="orcid">https://orcid.org/0000-0003-2577-4144</contrib-id><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Клименко</surname><given-names>П. А.</given-names></name><name name-style="western" xml:lang="en"><surname>Klimenko</surname><given-names>P. A.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Клименко Павел Алексеевич, кандидат экономических наук, доцент</p><p>ул. Ломоносова, д. 3, г. Курск 305016</p></bio><bio xml:lang="en"><p>Pavel A. Klimenko, Cand. Sci. (Economics), Associate Professor</p><p>3 Lomonosova Str., Kursk 305016</p></bio><email xlink:type="simple">paaklimenko@fa.ru</email><xref ref-type="aff" rid="aff-2"/></contrib></contrib-group><aff-alternatives id="aff-1"><aff xml:lang="ru"><institution>Московский политехнический университет</institution><country>Россия</country></aff><aff xml:lang="en"><institution>Moscow Polytechnic University</institution><country>Russian Federation</country></aff></aff-alternatives><aff-alternatives id="aff-2"><aff xml:lang="ru"><institution>Курский филиал Финансового университета при Правительстве Российской Федерации</institution><country>Россия</country></aff><aff xml:lang="en"><institution>Kursk Branch of the Financial University under the Government of the Russian Federation</institution><country>Russian Federation</country></aff></aff-alternatives><pub-date pub-type="collection"><year>2026</year></pub-date><pub-date pub-type="epub"><day>07</day><month>08</month><year>2026</year></pub-date><volume>16</volume><issue>2</issue><fpage>167</fpage><lpage>181</lpage><permissions><copyright-statement>Copyright &amp;#x00A9; Огневой Я.В., Спеваков А.Г., Калуцкий И.В., Клименко П.А., 2026</copyright-statement><copyright-year>2026</copyright-year><copyright-holder xml:lang="ru">Огневой Я.В., Спеваков А.Г., Калуцкий И.В., Клименко П.А.</copyright-holder><copyright-holder xml:lang="en">Ognevoy Y.V., Spevakov A.G., Kalutskiy I.V., Klimenko P.A.</copyright-holder><license xml:lang="ru" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>Данная работа распространяется под лицензией Creative Commons Attribution 4.0.</license-p></license><license xml:lang="en" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>This work is licensed under a Creative Commons Attribution 4.0 License.</license-p></license></permissions><self-uri xlink:href="https://uprinmatus.elpub.ru/jour/article/view/488">https://uprinmatus.elpub.ru/jour/article/view/488</self-uri><abstract><p>Целью исследования является сравнительный анализ инструментов статического анализа РНР-кода для оценки их эффективности в выявлении ошибок, потенциальных уязвимостей и проблем типизации на ранних этапах разработки веб-приложений. Особое внимание уделяется определению практической применимости рассматриваемых решений в проектах различного масштаба, а также их влиянию на повышение качества программного обеспечения, снижение числа дефектов в коде и минимизацию рисков безопасности.</p><sec><title>Методы</title><p>Методы. В исследовании использован метод сравнительного анализа, основанный на тестировании инструментов на наборе типовых CUEHAPUES, отражающих распространённые ошибки и уязвимости РНР-приложений. Оценка инструментов проводилась по критериям полноты выявления ошибок, точности диагностики, гибкости настройки правил, удобства интеграции в процесс разработки, производительности и потребления ресурсов. Дополнительно был выполнен анализ документации и возможностей конфигурации. Все эксперименты проводились многократно для обеспечения статистической достоверности результатов.</p></sec><sec><title>Резулытаты</title><p>Резулытаты. В ходе исследования выявлены различия в глубине анализа, строгости проверки типов и механизмах настройки правил. Установлено, что инструменты демонстрируют различную чувствительность к логическим ошибкам, несоответствиям типов и потенциально небезопасным конструкциям. Определены их сильные и слабые стороны в контексте использования в малых и крупных проектах.</p></sec><sec><title>Заключение</title><p>Заключение. Результаты подтверждают эффективность применения инструментов статического анализа как средства повышения качества и безопасности РНР-кода. Выбор конкретного решения должен основываться на требованиях проекта, уровне строгости анализа и особенностях процесса разработки. Регулярное использование таких инструментов позволяет существенно снизить риск появления дефектов и уязвимостей, повышая надёжность и устойчивость веб-приложений.</p></sec></abstract><trans-abstract xml:lang="en"><p>The purpose of the research is a comparative analysis of static PHP code analysis tools to assess their effectiveness in identifying errors, potential vulnerabilities, and typing problems in the early stages of web application development. Particular attention is paid to determining the practical applicability of the solutions under consideration in projects of various scales, as well as their impact on improving software quality, reducing the number of defects in the code and minimizing security risks.</p><sec><title>Methods</title><p>Methods. The study uses a comparative analysis method based on testing tools on a set of typical scenarios reflecting common errors and vulnerabilities of PHP applications. The tools were evaluated according to the criteria of completeness of error detection, accuracy of diagnosis, flexibility of rule configuration, ease of integration into the development process, productivity and resource consumption. Additionally, an analysis of documentation and configuration options was performed. All experiments were carried out repeatedly to ensure the statistical reliability of the results.</p></sec><sec><title>Results</title><p>Results. The study revealed differences in the depth of analysis, the rigor of type checking, and the mechanisms for configuring rules. It has been found that the tools exhibit varying sensitivity to logical errors, type inconsistencies, and potentially unsafe designs. Their strengths and weaknesses have been identified in the context of use in small and large projects.</p></sec><sec><title>Conclusion</title><p>Conclusion. The results confirm the effectiveness of using static analysis tools as a means of improving the quality and security of PHP code. The choice of a specific solution should be based on the requirements of the project, the level of rigor of the analysis and the specifics of the development process. Regular use of such tools can significantly reduce the risk of defects and vulnerabilities, increasing the reliability and stability of web applications.</p></sec></trans-abstract><kwd-group xml:lang="ru"><kwd>статический анализ кода</kwd><kwd>безопасность PHP</kwd><kwd>анализ уязвимостей</kwd><kwd>качество программного обеспечения</kwd><kwd>безопасная разработка</kwd><kwd>автоматизированные инструменты анализа</kwd></kwd-group><kwd-group xml:lang="en"><kwd>static code analysis</kwd><kwd>PHP security</kwd><kwd>vulnerability analysis</kwd><kwd>software quality</kwd><kwd>secure development</kwd><kwd>automated analysis tools</kwd></kwd-group></article-meta></front><back><ref-list><title>References</title><ref id="cit1"><label>1</label><citation-alternatives><mixed-citation xml:lang="ru">Проверка кода на уязвимости на всех стадиях разработки / А. В. Скрыпников, В. В. Денисенко, И. А. Высоцкая, И. И. Савченко, K. С. Евтеева // Современные наукоемкие технологии. 2021. № 3. С. 77-81.</mixed-citation><mixed-citation xml:lang="en">Skripnikov A.V., Denisenko V.V., Vysotskaya I.A., Savchenko I.I., Evteeva K.S. Checking code for vulnerabilities at all stages of development. Sovremennye  naukoemkie tekhnologii = Modern Science-Intensive Technologies. 2021;(3): 77-81. (In Russ.)</mixed-citation></citation-alternatives></ref><ref id="cit2"><label>2</label><citation-alternatives><mixed-citation xml:lang="ru">Методика поиска уязвимостей в программном обеспечении, написанном на нескольких языках программирования / Б. А. Позин [и др.] // Труды Института системного программирования РАН. 2025. Т. 37, № 1. С. 122-132.</mixed-citation><mixed-citation xml:lang="en">Pozin B.A., et al. A methodology for searching for vulnerabilities in software written in several programming languages. Trudy  Instituta  sistemnogo  programmirovaniya RAN = Proceedings of  the  Institute  for System Programming of  the Russian Academy of  Sciences. 2025;37(1):122–132. (In Russ.)</mixed-citation></citation-alternatives></ref><ref id="cit3"><label>3</label><citation-alternatives><mixed-citation xml:lang="ru">Кубрин Г. C., Зегжда Д. П. Поиск уязвимостей программного обеспечения с применением ансамбля алгоритмов анализа графового представления кода // Проблемы информационной безопасности. Компьютерные системы. 2023. № 4. С. 148—158.</mixed-citation><mixed-citation xml:lang="en">Kubrin G.S., Zegzhda D.P. Search for software vulnerabilities using an ensemble of algorithms for analyzing graph representation of code. Problemy  informatsionnoi  bezopasnosti.  Komp'yuternye  sistemy  =  Problems  of  Information  Security.  Computer  Systems. 2023;(4):148–158. (In Russ.)</mixed-citation></citation-alternatives></ref><ref id="cit4"><label>4</label><citation-alternatives><mixed-citation xml:lang="ru">Seara J. Р., Serrdao С. Automation of system security vulnerabilities detection using open-source software // Electronics. 2024. Vol. 13, N 5. P. 873.</mixed-citation><mixed-citation xml:lang="en">Seara J.P., Serrão C. Automation of system security vulnerabilities detection using open-source software. Electronics. 2024;13(5):873. 5. Rio A., Fernando Brito e Abreu. PHP code smells in web apps: Evolution, survival and anomalies. Journal of Systems and Software. 2023;200:111644.</mixed-citation></citation-alternatives></ref><ref id="cit5"><label>5</label><citation-alternatives><mixed-citation xml:lang="ru">Rio А., Fernando Brito e Abreu. PHP code smells in web apps: Evolution, survival and anomalies // Journal of Systems and Software. 2023. Vol. 200. P. 111644.</mixed-citation><mixed-citation xml:lang="en">Lenarduzzi V., et al. A critical comparison on six static analysis tools: Detection, agreement, and precision. Journal of Systems and Software. 2023;198:111575.</mixed-citation></citation-alternatives></ref><ref id="cit6"><label>6</label><citation-alternatives><mixed-citation xml:lang="ru">A critical comparison on six static analysis tools: Detection, agreement, and precision/ V. Lenarduzzi [et al.] // Journal оf Systems and Software. 2023. Vol. 198. P. 111575. https://doi.org/10.48550/arXiv.2101.08832.</mixed-citation><mixed-citation xml:lang="en">Zhao J., et al. Benchmarking static analysis for PHP applications security. Entropy. 2025;27(9):926.</mixed-citation></citation-alternatives></ref><ref id="cit7"><label>7</label><citation-alternatives><mixed-citation xml:lang="ru">Benchmarking static analysis for PHP applications security / J. Zhao [et al.] // Entroру. 2025. Vol. 27, N 9. P. 926.</mixed-citation><mixed-citation xml:lang="en">Charugin V.V., et al. Analysis of software code preprocessing methods to improve the efficiency of using large language models in vulnerability detection tasks. Computational Nanotechnology. 2025;12(3):67-79. (In Russ.)</mixed-citation></citation-alternatives></ref><ref id="cit8"><label>8</label><citation-alternatives><mixed-citation xml:lang="ru">Анализ методов предобработки программного кода для повышения эффективности применения больших языковых моделей в задачах обнаружения уязвимостей / В. В. Чаругин [и др.] // Computational nanotechnology. 2025. Vol. 12, N 3. Р. 67—79.</mixed-citation><mixed-citation xml:lang="en">Schuckert F., Katt B., Langweg H. Insecurity refactoring: Automated injection of vulnerabilities in source code. Computers  &amp;  Security. 2023;128(10):103121. https://doi.org/10.1016/j.cose.2023.103121.</mixed-citation></citation-alternatives></ref><ref id="cit9"><label>9</label><citation-alternatives><mixed-citation xml:lang="ru">Schuckert F., Katt B., Langweg H. Insecurity refactoring: Automated injection of vulnerabilities in source code // Computers &amp; Security. 2023. Vol. 128, N 10. P. 103121. https://doi.org/10.1016/j.cose.2023.103121.</mixed-citation><mixed-citation xml:lang="en">Mazhar T., et al. Analysis of IoT security challenges and its solutions using artificial intelligence. Brain Sciences. 2023;13(4):683.</mixed-citation></citation-alternatives></ref><ref id="cit10"><label>10</label><citation-alternatives><mixed-citation xml:lang="ru">Analysis of IoT security challenges and its solutions using artificial intelligence / T. Mazhar [et al.] // Brain sciences. 2023. Vol. 13, N 4. P. 683.</mixed-citation><mixed-citation xml:lang="en">Benzekki K., Messai M.L. Empowering Cybersecurity Analysis: Unifying CVE, CWE, and CPE through Knowledge Graphs. Computers  &amp;  Security. 2025;160:104726. https://doi.org/10.1016/j.cose.2025.104726.</mixed-citation></citation-alternatives></ref><ref id="cit11"><label>11</label><citation-alternatives><mixed-citation xml:lang="ru">Benzekki K., Messai M. L. Empowering Cybersecurity Analysis: Unifying CVE, CWE, and CPE through Knowledge Graphs // Computers &amp; Security. 2025. Vol. 160. P. 104726. https://doi.org/10.1016/j.cose.2025.104726.</mixed-citation><mixed-citation xml:lang="en">Shaikhelislamov D.S., Drobyshevskiy M.D., Belevantsev A.A. Ensuring Trustworthy Code: Leveraging a Static Analyzer to Identify and Mitigate Defects in Generated Code. Journal of Mathematical Sciences. 2024;540:233-251.</mixed-citation></citation-alternatives></ref><ref id="cit12"><label>12</label><citation-alternatives><mixed-citation xml:lang="ru">Shaikhelislamov D. S., Drobyshevskiy M. D., Belevantsev A. A. Ensuring Trustworthy Code: Leveraging a Static Analyzer to Identify and Mitigate Defects in Generated Code // Journal of Mathematical Sciences. 2024. Vol. 540. P. 233–251.</mixed-citation><mixed-citation xml:lang="en">Pilkevich P.V., Spevakov A.G., Kalutskiy I.V. Model of a Decision-Making System Based on Incident Monitoring. Trudy  MAI  =  Proceedings  of  the  MAI. 2025;(143):1-27. (In Russ.)</mixed-citation></citation-alternatives></ref><ref id="cit13"><label>13</label><citation-alternatives><mixed-citation xml:lang="ru">Пилькевич П. B., Спеваков А. Г., Калуцкий И. В. Модель системы принятия решений на основании мониторинга инцидентов // Труды МАИ. 2025. № 143. С. 1-27.</mixed-citation><mixed-citation xml:lang="en">Vorotnikova T.Yu. Reliable Code: Static Analysis of Program Code as a Means of Improving the Reliability of Information Systems Software.  Informatsionnye  tekhnologii  v UIS = Information Technologies in the UIS. 2020;(2):22–27. (In Russ.)</mixed-citation></citation-alternatives></ref><ref id="cit14"><label>14</label><citation-alternatives><mixed-citation xml:lang="ru">Воротникова Т. Ю. Надежный код: статический анализ программного кода как средство повышения надежности программного обеспечения информационных систем // Информационные технологии в УИС. 2020. № 2. С. 22-27.</mixed-citation><mixed-citation xml:lang="en">Markov A.S., et al. Comparative Analysis and Selection of Static Code Security Analyzers. Voprosy kiberbezopasnosti = Cybersecurity Issues. 2024;(5):79–88. (In Russ.)</mixed-citation></citation-alternatives></ref><ref id="cit15"><label>15</label><citation-alternatives><mixed-citation xml:lang="ru">Сравнительный анализ и выбор статических анализаторов безопасности кода / А. С. Марков, И. С. Антипов, С. С. Арустамян, Н. А. Магакелова // Вопросы кибербезопасности. 2024. № 5 (63). С. 79—88.</mixed-citation><mixed-citation xml:lang="en">Alqaradaghi M., Morse G., Kozsik T. Detecting Security Vulnerabilities with Static Analysis – A Case Study. Pollack Periodica. 2022;17(2):1–7.</mixed-citation></citation-alternatives></ref><ref id="cit16"><label>16</label><citation-alternatives><mixed-citation xml:lang="ru">Alqaradaghi M., Morse G., Kozsik T. Detecting security vulnerabilities with static analysis – A case study // Pollack Periodica. 2022. Vol. 17, N 2. %. 1–7. 17. SQL injection attack detection in network flow data / Ignacio Samuel Crespo- Martínez, Ángel Manuel Guerrero-Higueras, Adrián Campazas Vega, Virginia Riego // Computers &amp; Security. 2023. Vol. 127, N 4. P. 103093.</mixed-citation><mixed-citation xml:lang="en">Ignacio Samuel Crespo-Martínez, Ángel Manuel Guerrero-Higueras, Adrián Campazas Vega, Virginia Riego. SQL injection attack detection in network flow data. Computers &amp; Security. 2023;127(4):103093.</mixed-citation></citation-alternatives></ref><ref id="cit17"><label>17</label><citation-alternatives><mixed-citation xml:lang="ru">An XSS Attack Detection Model Based on Two-Stage AST Analysis / Qiuhua Wang, Chuangchuang Li, Lifeng Yuan, Dong Wang, Yeru Wang, Yizhi Ren, Weizhi Meng // IEEE Transactions on Dependable and Secure Computing. 2026. Vol. 23, is. 2. P. 4071–4084.</mixed-citation><mixed-citation xml:lang="en">Qiuhua Wang, Chuangchuang Li, Lifeng Yuan, Dong Wang, Yeru Wang, Yizhi Ren, Weizhi Meng. An XSS Attack Detection Model Based on Two-Stage AST Analysis. IEEE Transactions on Dependable and Secure Computing. 2026;23(2):4071-4084.</mixed-citation></citation-alternatives></ref><ref id="cit18"><label>18</label><citation-alternatives><mixed-citation xml:lang="ru">Vasileva V.1, Borodin А. Е., Volkov А. Е. Detection оf dead function calls аs source code defects through static analysis // Труды Института системного программирования РАН. 2025. Т. 37, Ne 4. С. 65-78.</mixed-citation><mixed-citation xml:lang="en">Vasileva V.I., Borodin A.E., Volkov A.E. Detection of dead function calls as source code defects through static analysis. Trudy Instituta sistemnogo programmirovaniya RAN = Proceedings of ISP RAS. 2025;37(4):65-78.</mixed-citation></citation-alternatives></ref><ref id="cit19"><label>19</label><citation-alternatives><mixed-citation xml:lang="ru">A large scale analysis of code security in public repositories / Ciprian Oprisa, Dominic Octavian Grigoruţ, Haralambos Mouratidis, Eftychia Lakka // International Journal of Information Security. 2026. Vol. 25, N 1. P. 24. https://doi.org/10.1007/s10207-025-01187-w.</mixed-citation><mixed-citation xml:lang="en">Ciprian Oprisa, Dominic Octavian Grigoruţ, Haralambos Mouratidis, Eftychia Lakka. A large scale analysis of code security in public repositories. International Journal of Information Security. 2026;25(1):24. https://doi.org/10.1007/s10207-025-01187-w.</mixed-citation></citation-alternatives></ref></ref-list><fn-group><fn fn-type="conflict"><p>The authors declare that there are no conflicts of interest present.</p></fn></fn-group></back></article>
