Preview

Proceedings of the Southwest State University. Series: IT Management, Computer Science, Computer Engineering. Medical Equipment Engineering

Advanced search

Comparative study of PHP code static analysis tools

https://doi.org/10.21869/2223-1536-2026-16-2-167-181

Abstract

The purpose of the research is a comparative analysis of static PHP code analysis tools to assess their effectiveness in identifying errors, potential vulnerabilities, and typing problems in the early stages of web application development. Particular attention is paid to determining the practical applicability of the solutions under consideration in projects of various scales, as well as their impact on improving software quality, reducing the number of defects in the code and minimizing security risks.

Methods. The study uses a comparative analysis method based on testing tools on a set of typical scenarios reflecting common errors and vulnerabilities of PHP applications. The tools were evaluated according to the criteria of completeness of error detection, accuracy of diagnosis, flexibility of rule configuration, ease of integration into the development process, productivity and resource consumption. Additionally, an analysis of documentation and configuration options was performed. All experiments were carried out repeatedly to ensure the statistical reliability of the results.

Results. The study revealed differences in the depth of analysis, the rigor of type checking, and the mechanisms for configuring rules. It has been found that the tools exhibit varying sensitivity to logical errors, type inconsistencies, and potentially unsafe designs. Their strengths and weaknesses have been identified in the context of use in small and large projects.

Conclusion. The results confirm the effectiveness of using static analysis tools as a means of improving the quality and security of PHP code. The choice of a specific solution should be based on the requirements of the project, the level of rigor of the analysis and the specifics of the development process. Regular use of such tools can significantly reduce the risk of defects and vulnerabilities, increasing the reliability and stability of web applications.

About the Authors

Ya. V. Ognevoy
Moscow Polytechnic University
Russian Federation

Yaroslav V. Ognevoy, Student at the Faculty of Information Technologies

38 Bolshaya Semyonovskaya Str., Moscow 107023



A. G. Spevakov
Moscow Polytechnic University
Russian Federation

Alexander G. Spevakov, Cand. Sci. (Engineering), Associate Professor

38 Bolshaya Semyonovskaya Str., Moscow 107023



I. V. Kalutskiy
Moscow Polytechnic University
Russian Federation

Igor V. Kalutskiy, Cand. Sci. (Engineering), Associate Professor

38 Bolshaya Semyonovskaya Str., Moscow 107023



P. A. Klimenko
Kursk Branch of the Financial University under the Government of the Russian Federation
Russian Federation

Pavel A. Klimenko, Cand. Sci. (Economics), Associate Professor

3 Lomonosova Str., Kursk 305016



References

1. Skripnikov A.V., Denisenko V.V., Vysotskaya I.A., Savchenko I.I., Evteeva K.S. Checking code for vulnerabilities at all stages of development. Sovremennye naukoemkie tekhnologii = Modern Science-Intensive Technologies. 2021;(3): 77-81. (In Russ.)

2. Pozin B.A., et al. A methodology for searching for vulnerabilities in software written in several programming languages. Trudy Instituta sistemnogo programmirovaniya RAN = Proceedings of the Institute for System Programming of the Russian Academy of Sciences. 2025;37(1):122–132. (In Russ.)

3. Kubrin G.S., Zegzhda D.P. Search for software vulnerabilities using an ensemble of algorithms for analyzing graph representation of code. Problemy informatsionnoi bezopasnosti. Komp'yuternye sistemy = Problems of Information Security. Computer Systems. 2023;(4):148–158. (In Russ.)

4. Seara J.P., Serrão C. Automation of system security vulnerabilities detection using open-source software. Electronics. 2024;13(5):873. 5. Rio A., Fernando Brito e Abreu. PHP code smells in web apps: Evolution, survival and anomalies. Journal of Systems and Software. 2023;200:111644.

5. Lenarduzzi V., et al. A critical comparison on six static analysis tools: Detection, agreement, and precision. Journal of Systems and Software. 2023;198:111575.

6. Zhao J., et al. Benchmarking static analysis for PHP applications security. Entropy. 2025;27(9):926.

7. Charugin V.V., et al. Analysis of software code preprocessing methods to improve the efficiency of using large language models in vulnerability detection tasks. Computational Nanotechnology. 2025;12(3):67-79. (In Russ.)

8. Schuckert F., Katt B., Langweg H. Insecurity refactoring: Automated injection of vulnerabilities in source code. Computers & Security. 2023;128(10):103121. https://doi.org/10.1016/j.cose.2023.103121.

9. Mazhar T., et al. Analysis of IoT security challenges and its solutions using artificial intelligence. Brain Sciences. 2023;13(4):683.

10. Benzekki K., Messai M.L. Empowering Cybersecurity Analysis: Unifying CVE, CWE, and CPE through Knowledge Graphs. Computers & Security. 2025;160:104726. https://doi.org/10.1016/j.cose.2025.104726.

11. Shaikhelislamov D.S., Drobyshevskiy M.D., Belevantsev A.A. Ensuring Trustworthy Code: Leveraging a Static Analyzer to Identify and Mitigate Defects in Generated Code. Journal of Mathematical Sciences. 2024;540:233-251.

12. Pilkevich P.V., Spevakov A.G., Kalutskiy I.V. Model of a Decision-Making System Based on Incident Monitoring. Trudy MAI = Proceedings of the MAI. 2025;(143):1-27. (In Russ.)

13. Vorotnikova T.Yu. Reliable Code: Static Analysis of Program Code as a Means of Improving the Reliability of Information Systems Software. Informatsionnye tekhnologii v UIS = Information Technologies in the UIS. 2020;(2):22–27. (In Russ.)

14. Markov A.S., et al. Comparative Analysis and Selection of Static Code Security Analyzers. Voprosy kiberbezopasnosti = Cybersecurity Issues. 2024;(5):79–88. (In Russ.)

15. Alqaradaghi M., Morse G., Kozsik T. Detecting Security Vulnerabilities with Static Analysis – A Case Study. Pollack Periodica. 2022;17(2):1–7.

16. Ignacio Samuel Crespo-Martínez, Ángel Manuel Guerrero-Higueras, Adrián Campazas Vega, Virginia Riego. SQL injection attack detection in network flow data. Computers & Security. 2023;127(4):103093.

17. Qiuhua Wang, Chuangchuang Li, Lifeng Yuan, Dong Wang, Yeru Wang, Yizhi Ren, Weizhi Meng. An XSS Attack Detection Model Based on Two-Stage AST Analysis. IEEE Transactions on Dependable and Secure Computing. 2026;23(2):4071-4084.

18. Vasileva V.I., Borodin A.E., Volkov A.E. Detection of dead function calls as source code defects through static analysis. Trudy Instituta sistemnogo programmirovaniya RAN = Proceedings of ISP RAS. 2025;37(4):65-78.

19. Ciprian Oprisa, Dominic Octavian Grigoruţ, Haralambos Mouratidis, Eftychia Lakka. A large scale analysis of code security in public repositories. International Journal of Information Security. 2026;25(1):24. https://doi.org/10.1007/s10207-025-01187-w.


Review

For citations:


Ognevoy Ya.V., Spevakov A.G., Kalutskiy I.V., Klimenko P.A. Comparative study of PHP code static analysis tools. Proceedings of the Southwest State University. Series: IT Management, Computer Science, Computer Engineering. Medical Equipment Engineering. 2026;16(2):167-181. (In Russ.) https://doi.org/10.21869/2223-1536-2026-16-2-167-181

Views: 56

JATS XML


Creative Commons License
This work is licensed under a Creative Commons Attribution 4.0 License.


ISSN 2223-1536 (Print)