Skip to content

PdoApiUsage ​

info on by default quick-fix

Group: Control flow · PhpStorm name: PdoApiUsageInspection

Preparing a statement with PDO::prepare() and immediately running it with an argument-less execute() gains nothing from the prepare step: no parameters are bound. A single PDO::query() call does the same job.

Example ​

php
<?php
class Repo
{
    /** @var \PDO */
    private $db;
    private $stmt;

    public function __construct(\PDO $db) { $this->db = $db; }

    public function warmup(\PDO $conn)
    {
        $ping = $conn->prepare('SELECT 42');
        // ready to go
        /** note */
        $ping->execute();

        $this->stmt = $this->db->prepare('SELECT now()');
        $this->stmt->execute();

        $bound = $conn->prepare('SELECT * FROM t WHERE id = ?');
        $bound->execute([7]);

        $later = $conn->prepare('SELECT 1');
        log_it('x');
        $later->execute();

        $used = $conn->prepare('SELECT 2');
        if ($used->execute()) {
            return $used;
        }

        $conn->query('SELECT 3');
        return null;
    }
}
php
<?php
class Repo
{
    /** @var \PDO */
    private $db;
    private $stmt;

    public function __construct(\PDO $db) { $this->db = $db; }

    public function warmup(\PDO $conn)
    {
        $ping = $conn->query('SELECT 42');
        // ready to go
        /** note */

        $this->stmt = $this->db->query('SELECT now()');

        $bound = $conn->prepare('SELECT * FROM t WHERE id = ?');
        $bound->execute([7]);

        $later = $conn->prepare('SELECT 1');
        log_it('x');
        $later->execute();

        $used = $conn->prepare('SELECT 2');
        if ($used->execute()) {
            return $used;
        }

        $conn->query('SELECT 3');
        return null;
    }
}

Reported:

  • line 15: No parameters are bound; call query() instead of prepare() + execute().
  • line 18: No parameters are bound; call query() instead of prepare() + execute().

Configure ​

In custos.json:

json
{
  "rules": {
    "PdoApiUsage": {
      "enabled": false
    }
  }
}

Suppress ​

Before the statement or declaration (or the first statement of the file), either of:

php
// @custos-ignore PdoApiUsage

/**
 * @noinspection PdoApiUsageInspection
 */

Released under the MIT License. Rule catalogue modelled on Php Inspections (EA Extended); independent clean-room implementation.