phpcpd-next: PHP 8.5+ Copy/Paste Detector CLI | Mohamed Said       [Skip to content](#main)  [ ![](https://cdn.msaied.com/01KT78WE565VEMM3PSNQAAB0MH.png) Mohamed SaidLaravel Backend Engineer ](https://www.msaied.com/public) - [Home](https://www.msaied.com/public)
- [Projects](https://www.msaied.com/public/projects)
- [Articles](https://www.msaied.com/public/articles)
- [Certificates](https://www.msaied.com/public/certificates)
- [About](https://www.msaied.com/public#about)

           [  Contact](https://www.msaied.com/public#contact) Menu 

Menu
----

Close 

 - [HomeStart here](https://www.msaied.com/public)
- [ProjectsCase studies](https://www.msaied.com/public/projects)
- [ArticlesEngineering notes](https://www.msaied.com/public/articles)
- [CertificatesCredentials](https://www.msaied.com/public/certificates)
- [AboutHow I work](https://www.msaied.com/public#about)
- [ContactGet in touch](https://www.msaied.com/public#contact)

  [Start a conversation](https://www.msaied.com/public#contact) [WhatsApp](https://wa.me/201094619204) [Email](mailto:hello@msaied.com) 

 1. [Home](https://www.msaied.com/public)
2. /
3. [Articles](https://www.msaied.com/public/articles)
4. /
5. [Composer Pacakge](https://www.msaied.com/public/articles?category=composer-pacakge)
6. /
7. phpcpd-next: A Modern Copy/Paste Detector CLI for PHP 8.5+

   [Composer Pacakge](https://www.msaied.com/public/articles?category=composer-pacakge) [PHP](https://www.msaied.com/public/articles?category=php) 

 phpcpd-next: A Modern Copy/Paste Detector CLI for PHP 8.5+
===========================================================

 phpcpd-next is a drop-in successor to Sebastian Bergmann's archived phpcpd tool. It detects exact, reordered, and gapped code clones in PHP 8.5+ projects with zero Composer runtime dependencies and built-in Laravel preset support.

 ![](https://cdn.msaied.com/01M22N44A70A5MC2S599JP0MPH.webp) [Mohamed Said](https://www.msaied.com/public#person) Published 2 Jul 2026 · Updated 3 Jul 2026 · 3 min read

ShareCopy linkCopied

 ![phpcpd-next: A Modern Copy/Paste Detector CLI for PHP 8.5+](https://cdn.msaied.com/354/6acc1ed3419cc5284564bf3c7862cb82.png) 

  On this page +1. [phpcpd-next: A Modern Copy/Paste Detector for PHP 8.5+](#phpcpd-next-a-modern-copypaste-detector-for-php-85)
2. [Three Detection Engines](#three-detection-engines)
3. [SARIF Output for GitHub Code Scanning](#sarif-output-for-github-code-scanning)
4. [Headless API and PHPUnit Assertions](#headless-api-and-phpunit-assertions)
5. [Incremental Caching for CI](#incremental-caching-for-ci)
6. [Laravel Preset and Installation](#laravel-preset-and-installation)
7. [Key Takeaways](#key-takeaways)

 phpcpd-next: A Modern Copy/Paste Detector for PHP 8.5+
------------------------------------------------------

Code duplication is one of those problems that sneaks past review and compounds quietly over time. [phpcpd-next](https://github.com/phpcpd-next/phpcpd) is a CLI tool that scans your PHP codebase and reports duplicated blocks — including cases that a simple text diff would miss.

Maintained by Luciano Federico Pereira as a successor to Sebastian Bergmann's archived `phpcpd`, it keeps the same `phpcpd` command so existing scripts and CI pipelines need no changes.

Three Detection Engines
-----------------------

Most copy/paste detectors only catch word-for-word duplicates. phpcpd-next ships three engines:

- **Rabin-Karp** — exact contiguous matches, fast by default
- **TokenBag** — order-invariant overlap, catches shuffled statements
- **Suffix tree** — opt-in gapped Type-3 clones, where a statement was inserted or removed between otherwise identical blocks

Rabin-Karp and TokenBag run together on every default scan. The suffix-tree engine is opt-in:

```bash
# Default: exact + reordered detection
phpcpd src/

# Rabin-Karp only
phpcpd --rk src/

# Gapped clones via suffix tree
phpcpd --algorithm=suffixtree src/

```

Console output points at the duplicated ranges and suggests a refactor:

```sql
Found 2 code clones with 21 duplicated lines in 2 files:
  - app/Services/Billing.php:12-33 (21 lines)
    app/Services/Invoicing.php:40-61
    → Consider extracting the shared lines into a reusable method or constant.

```

SARIF Output for GitHub Code Scanning
-------------------------------------

phpcpd-next writes four output formats: console text, PMD-CPD XML, JSON, and SARIF 2.1.0. The SARIF format integrates directly with GitHub Code Scanning, surfacing clones in the Security tab. Diverged clones map to `warning` severity; exact clones map to `note`.

```yaml
- name: Detect duplicated code
  run: vendor/bin/phpcpd --log-sarif=phpcpd.sarif src/ || true
- name: Upload results
  uses: github/codeql-action/upload-sarif@v3
  with:
    sarif_file: phpcpd.sarif

```

Headless API and PHPUnit Assertions
-----------------------------------

Detection can run in-process via a static `detect()` call — no subprocess, no report files:

```php
use LucianoPereira\PhpcpdNext\Phpcpd;

$clones = Phpcpd::detect(
    paths: 'app',
    minTokens: 60,
    algorithm: null, // Rabin-Karp + TokenBag
    preset: 'laravel',
);

```

A bundled PHPUnit trait turns duplication into a regression test:

```php
use LucianoPereira\PhpcpdNext\PHPUnit\AssertNoDuplication;
use PHPUnit\Framework\TestCase;

final class DuplicationTest extends TestCase
{
    use AssertNoDuplication;

    public function test_app_is_dry(): void
    {
        $this->assertNoDuplication(__DIR__ . '/../app', minTokens: 70);
    }
}

```

Incremental Caching for CI
--------------------------

For larger codebases, `--cache` stores results keyed by a configuration fingerprint and file-manifest hash. `--incremental` goes further, re-tokenizing only changed files and reusing the rest from a per-file index (Rabin-Karp only):

```yaml
- uses: actions/cache@v4
  with:
    path: .phpcpd-cache
    key: phpcpd-${{ hashFiles('**/*.php') }}
    restore-keys: phpcpd-
- run: vendor/bin/phpcpd --incremental --cache-dir .phpcpd-cache src/

```

Laravel Preset and Installation
-------------------------------

The tool requires PHP 8.5+, `ext-dom`, and `ext-mbstring`. Install it as a dev dependency:

```bash
composer require --dev phpcpd-next/phpcpd
vendor/bin/phpcpd src/

```

A built-in Laravel preset scans `app`, `routes`, `database`, and `config` while automatically excluding vendor code, Blade views, migrations, and IDE-helper files:

```bash
vendor/bin/phpcpd --preset=laravel app/Services --min-tokens=60

```

Key Takeaways
-------------

- Drop-in replacement for the archived `phpcpd` with the same CLI command
- Three engines: exact (Rabin-Karp), reordered (TokenBag), and gapped (suffix tree)
- SARIF 2.1.0 output integrates with GitHub Code Scanning out of the box
- PHPUnit trait makes duplication a first-class test assertion
- Incremental indexing keeps CI scans fast on large codebases
- Zero Composer runtime dependencies; requires PHP 8.5+
- Built-in Laravel preset with sensible exclusions

---

*Source: [Laravel News — A Copy/Paste Detector CLI for PHP 8.5+](https://laravel-news.com/a-copypaste-detector-cli-for-php-85)*

- [PHP](https://www.msaied.com/public/articles?search=PHP)
- [Code Quality](https://www.msaied.com/public/articles?search=Code%20Quality)
- [CLI Tools](https://www.msaied.com/public/articles?search=CLI%20Tools)
- [Laravel](https://www.msaied.com/public/articles?search=Laravel)
- [Static Analysis](https://www.msaied.com/public/articles?search=Static%20Analysis)
- [PHPUnit](https://www.msaied.com/public/articles?search=PHPUnit)

 Frequently asked questions 
---------------------------

  What is the difference between phpcpd-next and the original phpcpd?phpcpd-next is a maintained successor to Sebastian Bergmann's archived phpcpd. It keeps the same `phpcpd` command as a drop-in replacement but adds two additional detection engines (TokenBag for reordered clones and a suffix-tree engine for gapped clones), four output formats including SARIF 2.1.0, a headless PHP API, a PHPUnit assertion trait, incremental CI caching, and framework presets including Laravel.

   How do I integrate phpcpd-next with GitHub Code Scanning?Run phpcpd-next with the `--log-sarif` flag to produce a SARIF 2.1.0 file, then upload it using the `github/codeql-action/upload-sarif@v3` action. Diverged clones appear as warnings and exact clones as notes in the GitHub Security tab.

   Does phpcpd-next slow down CI on large codebases?No. The `--cache` flag stores results keyed by a configuration fingerprint and file-manifest hash, replaying cached results when nothing has changed. The `--incremental` flag goes further by re-tokenizing only modified files and reusing the per-file index for everything else, printing a summary such as `(incremental index: 412 reused, 3 scanned)`.

   ![Mohamed Said](https://cdn.msaied.com/01M22N44A70A5MC2S599JP0MPH.webp)About the author
----------------

[Mohamed Said](https://www.msaied.com/public#person)Senior Backend Engineer specializing in Laravel, scalable SaaS platforms, APIs, and cloud infrastructure. I build secure, high-performance web applications that help businesses grow.

[About](https://www.msaied.com/public#about) [GitHub ↗](https://github.com/EG-Mohamed) [LinkedIn ↗](https://www.linkedin.com/in/msaiedm/) [WhatsApp ↗](https://wa.me/201094619204) [Email Address ↗](mailto:hello@msaied.com) [My CV ↗](https://drive.google.com/file/u/0/d/1MF20IPRJyzfy32mhEutjL5EpSls0w2Q8/view)  

   [Previous articleLaravel Queues: Reliable Retry Strategies, Dead-Letter Handling, and Observability](https://www.msaied.com/public/articles/laravel-queues-reliable-retry-strategies-dead-letter-handling-and-observability) [Next articlePractical RAG in Laravel: pgvector, Embeddings, and Retrieval Pipelines](https://www.msaied.com/public/articles/practical-rag-in-laravel-pgvector-embeddings-and-retrieval-pipelines)  

   On this page
-------------

1. [phpcpd-next: A Modern Copy/Paste Detector for PHP 8.5+](#phpcpd-next-a-modern-copypaste-detector-for-php-85)
2. [Three Detection Engines](#three-detection-engines)
3. [SARIF Output for GitHub Code Scanning](#sarif-output-for-github-code-scanning)
4. [Headless API and PHPUnit Assertions](#headless-api-and-phpunit-assertions)
5. [Incremental Caching for CI](#incremental-caching-for-ci)
6. [Laravel Preset and Installation](#laravel-preset-and-installation)
7. [Key Takeaways](#key-takeaways)

 ###  Have a technical challenge?

 Tell me what you’re building. I reply within two working days.

[Start a conversation](https://www.msaied.com/public#contact) 

   Related articles
-----------------

 [ ![](https://cdn.msaied.com/740/cce86edc21eddcbdd2f2454fadaf9c70.png)  · 3 min read### The Pipeline Pattern in Laravel: Custom Pipelines Beyond Middleware

5 Oct 2026 ](https://www.msaied.com/public/articles/the-pipeline-pattern-in-laravel-custom-pipelines-beyond-middleware-1) [ ![](https://cdn.msaied.com/739/2d6897fdcdcf090613f96f72a64b8a78.png)  · 4 min read### MySQL Full-Text Search in Laravel: Indexes, Relevance Scoring, and Boolean Mode

4 Oct 2026 ](https://www.msaied.com/public/articles/mysql-full-text-search-in-laravel-indexes-relevance-scoring-and-boolean-mode) [ ![](https://cdn.msaied.com/738/073696a3fefe18bec825beec5ac658f5.png)  · 4 min read### Laravel Queue Rate-Limited Middleware: Throttling Jobs Without Losing Work

4 Oct 2026 ](https://www.msaied.com/public/articles/laravel-queue-rate-limited-middleware-throttling-jobs-without-losing-work) 

  Have a technical challenge?
----------------------------

Tell me what you’re building. I reply within two working days.

 [Discuss your project ↗](https://www.msaied.com/public#contact) 

  © 2026 Mohamed Said · Built with Laravel, meant to last.Senior Backend Engineer specializing in Laravel, scalable SaaS platforms, APIs, and cloud infrastructure. I build secure, high-performance web applications that help businesses grow.

 - [Home](https://www.msaied.com/public)
- [Articles](https://www.msaied.com/public/articles)
- [Certificates](https://www.msaied.com/public/certificates)
- [GitHub](https://github.com/EG-Mohamed)
- [LinkedIn](https://www.linkedin.com/in/msaiedm/)
- [WhatsApp](https://wa.me/201094619204)
- [Email Address](mailto:hello@msaied.com)
- [My CV](https://drive.google.com/file/u/0/d/1MF20IPRJyzfy32mhEutjL5EpSls0w2Q8/view)
- [Sitemap](https://www.msaied.com/public/sitemap.xml)
