Shipping Confidence
“It works on my machine” is not a feature. Confidence, the actual, checkable kind that comes from a test suite that catches regressions, a static analyzer that catches whole categories of bugs before they run, and a scan that flags a known-vulnerable dependency before it ships, is a feature too. It’s the one where the bug gets caught before your user finds it, and it belongs in every project in this book, not just the ones with time left over at the end.
- Laravel: Pest, Larastan, and
composer auditcovers Laravel’s testing and static analysis stack. - Symfony: PHPUnit, PHPStan/Psalm, and Rector covers Symfony’s equivalent, plus automated upgrades.
- WordPress: PHPUnit, PHPCS/WPCS, and WPScan covers testing and security scanning for plugins and themes.
- Cross-Ecosystem: SAST, Dependency Scanning, and CI Gates covers what works the same everywhere, regardless of framework.
- Catching It in Production: Sentry and Flare ($) covers the moment confidence has to extend past your own test suite, into what’s actually happening for real users.