
Security News
OpenClaw Skill Marketplace Emerges as Active Malware Vector
Security researchers report widespread abuse of OpenClaw skills to deliver info-stealing malware, exposing a new supply chain risk as agent ecosystems scale.
devsense-php-ls
Advanced tools
This package provides language server for PHP.
The language server is provided as a platform-specific binary executable file, located in node_modules/devsense-php-ls-${os}-${cpu}/dist/devsense.php.ls.
The functionality is provided to end-users under a freemium model. See 🔐 Activation section below for details.
The language server is controlled using the Language Server Protocol according to https://microsoft.github.io/language-server-protocol/specifications/lsp/3.17/specification/ through STDIN/STDOUT.
There are several additions:
"initialize" method, parameter:{
"initializationOptions": {
"0": "KEY or {JSON CODE}",
"clientFeatures": [],
// VSCode settings and their values listed on
// https://docs.devsense.com/vscode/configuration/
// "setting-id": "value",
},
// process ID of client allowing
// LS to automatically kill itself if client exits
"processId": 123456,
// ...
}
"devsense/loadStatus" notification sent from server to client.The language server provides free features and premium features which needs to be activated by end-user.
Note to developers: To unlock the premium features of this package, instruct end-users to follow the steps below:
Purchase a License: User needs to purchase license on official purchase page: https://www.devsense.com/purchase
Activate Language Server
Set the value of license key into DEVSENSE_PHP_LS_LICENSE environment variable or "initializationOptions"."0". Language Server will try to activate automatically upon starting (requires Internet connection).
Optional: Offline Activation
In case there is no Internet connection: User will follow the link below to validate license and receive a {JSON CODE}: devsense.com/purchase/validation
Pass the entire {JSON CODE} into the language server's initialize method, as a "initializationOptions"."0" property:
{
"initializationOptions": {
"0": "{JSON CODE}",
},
}
Or store the {JSON CODE} into environment variable DEVSENSE_PHP_LS_LICENSE.
If you encounter any issues during the activation process, please refer to our documentation or contact support.
By including this package as a dependency in your project—whether for personal, commercial, or open-source use—you agree to the following:
Attribution is required: You must include a visible link to this README file in your project documentation (e.g. in your README.md, about page, or developer docs).
This is to ensure that end users and developers are aware:
This visibility helps support ongoing development and ensures fair use under our freemium model.
If you cannot comply with this requirement or need a custom license, please contact us for a commercial agreement.
FAQs
Devsense PHP Language Server
The npm package devsense-php-ls receives a total of 1,991 weekly downloads. As such, devsense-php-ls popularity was classified as popular.
We found that devsense-php-ls demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Security researchers report widespread abuse of OpenClaw skills to deliver info-stealing malware, exposing a new supply chain risk as agent ecosystems scale.

Security News
Claude Opus 4.6 has uncovered more than 500 open source vulnerabilities, raising new considerations for disclosure, triage, and patching at scale.

Research
/Security News
Malicious dYdX client packages were published to npm and PyPI after a maintainer compromise, enabling wallet credential theft and remote code execution.