PHP source review
SkillDatabases & dataSecurity review of PHP code, dangerous sinks and framework pitfalls (Laravel/Symfony/WordPress). Load when reviewing a PHP codebase/PR, on .php source in scope, or "review this PHP". Signals: composer.json, index.php, Laravel/Symfony/WP, unserialize, include/require with variables, mysqli/PDO.
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the PHP source review skill
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/code-review/code-review-php/SKILL.md and read by ahel’s review.
When it applies
Reviewing PHP source (a repo, a PR, or a leaked webroot). PHP's defaults and dynamic features make several classes easy to introduce, so a grep-then-trace pass finds most of them fast.
Why it works
Many PHP sinks execute or include whatever string they're given, and loose typing turns comparison
and casting into logic bugs. Tracing each sink back to a request source ($_GET/$_POST/$_REQUEST/ $_COOKIE/$_SERVER, php://input) tells you which are actually reachable.
Sinks & patterns (grep, then trace to user input)
- Code exec:
eval,assert,preg_replacewith/e,create_function,call_user_func(_array). - Command exec:
system,exec,shell_exec,passthru,proc_open,popen, backticks. - File include (LFI/RFI):
include/require(_once) with a variable;allow_url_include. - SQLi: string-interpolated queries into
mysqli_query/PDO::query(vs prepared statements). - Deserialization:
unserialize()on input (POP chains);phar://via file functions. - File / path:
file_get_contents,fopen,readfile,move_uploaded_filewith user paths. - Other:
extract()on input (variable overwrite),parse_str, SSRF viacurl/file_get_contents.
Framework specifics
- Laravel:
DB::raw/whereRaw, Blade{!! !!}(unescaped), mass assignment ($guarded=[]),unserializein queues,Storagepath traversal. - Symfony: unsafe deserialization, Twig
|raw, expression-language injection. - WordPress: unsanitised
$wpdb->query, missing nonce/cap checks, unsafeadd_query_arg, unauthenticated AJAX/REST callbacks.
Method
rgthe sinks above; for each, trace the argument back to a request source.- Note type-juggling auth checks (
==vs===,strcmpreturning0/null) and loose casts. - Check upload handlers (extension/content-type allowlist, exec in upload dir).
- Confirm exploitability with the matching runtime skill (
web-command-injection,web-deserialization,web-lfi-path-traversal,web-sqli).
Gotchas
- A sink is only a bug if input reaches it — don't report unreachable
eval. - WordPress plugins: unauthenticated
wp_ajax_nopriv_*and REST endpoints are the high-value paths. ==type juggling ("0e123"=="0e456") still breaks weak hash/token comparisons.
References
OWASP PHP security; RIPS/progpilot sink catalogue; PHP unserialize POP-chain research (PHentication).
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
code-review-php- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
Related picks
Skill · michtio
The pick for PHPfeature-flags-php
Skill · posthog
The pick for PHPlaravel-specialist
Skill · jeffallan
The pick for Laravellaravel-best-practices
Skill · promovaweb
The pick for Laravelphp-pro
Skill · jeffallan
The pick for Symfonyaudit-dependencies
Skill · stbenjam
The pick for Dependencies