Skip to content

SuspiciousFunctionCalls ​

error on by default

Group: Probable bugs · PhpStorm name: SuspiciousFunctionCallsInspection

A string comparison function called with the same expression as both operands always yields "equal" — typically a copy-paste slip where one side should have been a different variable.

Example ​

php
<?php
function verify(string $token, string $expected, array $row) {
    $a = hash_equals($token, $token);
    $b = \strcasecmp($row['name'], $row[ 'name' ]);
    $c = substr_compare($token, $token, 0, 4);
    $d = strncmp($token, $expected, 4);
    $e = strnatcmp($token, ($token));
    return [$a, $b, $c, $d, $e];
}

Reported:

  • line 3: Both compared strings are the same expression; one of them is probably wrong.
  • line 4: Both compared strings are the same expression; one of them is probably wrong.
  • line 5: Both compared strings are the same expression; one of them is probably wrong.

Configure ​

In custos.json:

json
{
  "rules": {
    "SuspiciousFunctionCalls": {
      "enabled": false
    }
  }
}

Suppress ​

Before the statement or declaration (or the first statement of the file), either of:

php
// @custos-ignore SuspiciousFunctionCalls

/**
 * @noinspection SuspiciousFunctionCallsInspection
 */

Released under the MIT License. Rule catalogue modelled on Php Inspections (EA Extended); independent clean-room implementation.