Infection
- Android app
- Not listed
- Free plan
- No
- Runs on
- Linux, Mac, Web

Summary
Infection is a free PHP mutation-testing library that checks whether a test suite catches changes to source code. It creates mutations using predefined operators, runs tests that cover changed lines, and records mutations detected by tests as well as survivors, errors, and timeouts. Its Mutation Score Indicator reports the proportion of generated mutations caught by tests; additional metrics include Mutation Code Coverage and Covered Code Mutation Score Indicator. Infection supports PHPUnit, PhpSpec, Codeception, and Testo. It can run tests for mutated code in parallel, focus mutations on changed lines or files, and enforce configured minimum mutation scores in a build. Optional PHPStan and Mago integrations can help identify escaped mutants involving type violations, dead code, and unreachable paths. The command-line tool is available through PHAR, Phive, Composer, Git, and Homebrew. A browser playground lets users run mutation testing on PHP code and tests without installing Composer, Infection, or PHPUnit. Infection requires PHP 8.3 or newer and Xdebug, phpdbg, or pcov. Parallel runs can give false positives when tests depend on each other or use a database. The project is released under the BSD-3-Clause license.
Who it is for
Infection suits PHP developers who want to assess whether their test suites detect code changes, including within CI builds. It is especially relevant to projects using one of its supported test frameworks.
What is good
- Works with PHPUnit, PhpSpec, Codeception, and Testo
- Can restrict mutation testing to changed lines or files
- Minimum mutation scores can fail a build
- Browser playground works without local tool installation
What to know first
- Requires PHP 8.3 or newer
- Requires Xdebug, phpdbg, or pcov
- Parallel runs can produce false positives with dependent or database tests
Everything Xiaomi review
Infection: the full review
Infection provides mutation metrics, changed-code analysis, and score thresholds for PHP test suites. Check its runtime requirements and the warning about parallel runs when tests depend on each other or use a database.
Infection is a command-line mutation-testing library for PHP, aimed at teams that want to see whether their tests catch plausible code changes. It is a strong fit for PHPUnit and other supported PHP test suites that need mutation scores in CI, but parallel runs need care when tests share state.
Overview
Rather than merely checking which lines tests execute, Infection changes PHP code through predefined mutation operators and runs tests against those changes. It records whether each mutant is killed, survives, errors, or times out, giving teams a sharper measure of whether covered code is actually protected by assertions.
Its Mutation Score Indicator (MSI) reports the percentage of generated mutations detected by the test suite. Mutation Code Coverage and Covered Code Mutation Score Indicator add coverage-aware views, helping teams distinguish a weak test assertion from a mutant that tests never reached.
Key features
Scores and CI gates
The --min-msi and --min-covered-msi options can fail a build when scores fall below configured thresholds. That makes Infection useful for enforcing test-quality expectations, though teams should choose thresholds with their codebase and suite in mind rather than treating a single score as a complete measure of quality. It can also emit GitHub annotations and GitLab Code Quality reports.
Targeted analysis and parallel runs
With --git-diff-lines, Infection can limit mutation work to touched lines; --git-diff-filter can narrow it to changed files. These options make incremental analysis more practical during active development than rerunning mutation testing across an entire project for every change. The --threads option runs tests for mutants in parallel, with --threads=max detecting CPU cores automatically. But parallel execution can cause false positives when tests depend on one another or use a database, so that speed-up is not safe for every suite.
Mutators and integrations
The project describes more than 100 mutators, including arithmetic, boolean, equality, conditional-boundary, return-value and visibility changes, organized into profiles. Custom mutator support extends the set of changes teams can examine. Optional PHPStan and Mago integrations can identify escaped mutants involving type violations, dead code and unreachable paths.
Infection supports PHPUnit, PhpSpec, Codeception and Testo. It can publish mutation badges and HTML reports through Stryker Dashboard using a project API key. The browser-based Infection Playground lets users try PHP code and tests without installing Composer, Infection or PHPUnit, a useful way to explore the method before adding it to a project.
Installation and security
Installation options include PHAR, Phive, Composer, Git and Homebrew. The recommended PHAR bundles the four supported test frameworks, and its signature can be verified using the documented GPG key. Infection is released under the BSD-3-Clause license. Its security policy supports only the latest version, though older releases may be patched depending on vulnerability severity; security issues should be reported privately on GitHub. Community help is available through Discord and GitHub Discussions, and the project welcomes issues and pull requests.
Pricing
Infection is free, with a free plan and no paid tiers to weigh against its core mutation-testing capabilities. Its BSD-3-Clause license is suitable for use in open-source and commercial projects. The main costs are operational: teams need a compatible PHP runtime and test runner, and mutation testing adds work beyond an ordinary test run.
Platforms
Infection supports Linux and macOS, and offers a web playground. It targets PHP rather than multiple programming languages. Current documentation requires PHP 8.3 or newer plus Xdebug, phpdbg or pcov, so older PHP environments cannot meet its documented runtime requirements.
Who it's for
Infection suits PHP teams that already maintain automated tests and want to measure whether those tests detect code-level faults, particularly when mutation thresholds and changed-code analysis can fit into CI. Its range of test-framework integrations and reporting options makes it relevant beyond PHPUnit-only projects.
It is less suitable for teams on older PHP runtimes, projects written in other languages, or suites whose shared state makes parallel mutation runs unreliable. Teams can still use targeted analysis, but should not assume that more threads always mean trustworthy results.
Pros and cons
- Pro: Multiple mutation and coverage-aware metrics, plus score thresholds, make test effectiveness measurable and enforceable in CI.
- Pro: Changed-line and changed-file modes focus analysis on current work, avoiding a full-project mutation run for every edit.
- Pro: Four supported PHP test frameworks, several installation routes and the browser playground lower adoption friction for different workflows.
- Con: PHP 8.3 or newer and a supported coverage driver are required, excluding environments that cannot meet those prerequisites.
- Con: Parallel runs can report false positives for interdependent or database-using tests, limiting the reliability of automatic speed-ups.
- Con: The security policy centers support on the latest version, so teams that stay on older releases may have less assurance of a patch.
Alternatives
For open-source projects wanting a freemium alternative with a free tier and trial, consider ArcMutate; its Base plan is 8.00 USD per month. Mutant is another freemium option: public repositories get its full feature set free, while its Commercial monthly plan is 30.00 USD per month per developer for any number of repositories. For a free, open-source PHP-oriented choice, Mutatest is an alternative.
PIT is a free mutation-testing alternative. muttest is another free option. Teams working in JavaScript, TypeScript, C# or Scala should consider Stryker Mutator, a free open-source tool for those languages. Cosmic Ray and Gambit are also free alternatives.
For more options, browse Mutation Testing Tools.
Verdict
PHP teams seeking a free, CI-ready way to check whether tests catch realistic code changes should choose Infection, especially if changed-code analysis can keep runs focused. Its broad mutator set, score gates and framework support make it a substantial testing tool rather than a simple coverage counter. Look elsewhere if the project is not PHP, the runtime cannot reach PHP 8.3, or shared-state tests make parallel execution too risky.
Compared on mutation testing tools
- Free plan
- Yesinfection.github.io
- Supported languages
- PHPinfection.github.io
- Test frameworks
- PHPUnit, PhpSpec, Codeception, Testoinfection.github.io
- Incremental analysis
- Yesinfection.github.io
- Parallel execution
- Yesinfection.github.io
- Surviving mutant reports
- Yesinfection.github.io
- Mutation quality gate
- Yesinfection.github.io
- Mutation operators
- Arithmetic, boolean, cast, conditional boundary, conditional negotiation, equality, function signature, nullify, number, operator, regex, removal, return value, visibility, and unwrap mutatorsinfection.github.io
Facts
- Purpose
- Infection mutates PHP source code and reports which changes a test suite fails to catch.infection.github.io · 30 Sept 2026
- Testing method
- It is a PHP mutation-testing library based on abstract-syntax-tree mutations and runs as a CLI tool from a project root.infection.github.io · 30 Sept 2026
- Runtime requirements
- The current documentation requires PHP 8.3 or newer and Xdebug, phpdbg or pcov.infection.github.io · 30 Sept 2026
- Mutation metrics
- Infection provides Mutation Score Indicator, Mutation Code Coverage and Covered Code Mutation Score Indicator metrics.infection.github.io · 30 Sept 2026
- CI thresholds
- The --min-msi and --min-covered-msi options can fail a build when configured mutation scores are not reached.infection.github.io · 30 Sept 2026
- Changed-code mode
- The --git-diff-lines option mutates only touched lines, and --git-diff-filter can restrict mutation to changed files.infection.github.io · 30 Sept 2026
- Mutators
- The homepage describes more than 100 mutators grouped into profiles, plus custom mutator support.infection.github.io · 30 Sept 2026
- Static analysis
- Infection supports optional PHPStan and Mago integrations to catch escaped mutants involving type violations, dead code and unreachable paths.infection.github.io · 30 Sept 2026
- Cloud reporting
- Infection can send mutation badges and HTML reports to Stryker Dashboard using a project API key.infection.github.io · 30 Sept 2026
- Distribution
- The recommended PHAR distribution bundles PHPUnit, PhpSpec, Codeception and Testo, and the PHAR signature can be verified with the documented GPG key.infection.github.io · 30 Sept 2026
- License
- The project is released under the BSD-3-Clause license.infection.github.io · 30 Sept 2026
- Security policy
- Only the latest Infection version is supported under its security policy, although older versions may be patched depending on vulnerability severity; vulnerabilities should be reported privately on GitHub.github.com · 30 Sept 2026
- Community support
- The project links to Discord and GitHub Discussions for community help and states that it welcomes pull requests and issues.github.com · 30 Sept 2026
- How it works
- It creates mutants using predefined mutation operators, runs tests covering changed lines, and records killed or escaped mutants, errors, and timeouts.infection.github.io · 2 Oct 2026
- Mutation score
- It reports a Mutation Score Indicator (MSI) that measures the percentage of generated mutations detected by the tests.infection.github.io · 2 Oct 2026
- CI reports
- Infection can emit GitHub annotations and GitLab Code Quality reports, and can publish mutation badges and HTML reports through Stryker Dashboard.infection.github.io · 2 Oct 2026
- Installation
- The maker documents PHAR, Phive, Composer, Git, and Homebrew installation methods.infection.github.io · 2 Oct 2026
- Security
- The maker says its PHAR distribution is signed with a GPG key and documents how to verify the signature and fingerprint.infection.github.io · 2 Oct 2026
- Browser playground
- The Infection Playground lets users write PHP code and tests in a browser and run mutation testing without installing Composer, Infection, or PHPUnit.infection.github.io · 2 Oct 2026
- Caveat
- The command-line guide warns that parallel runs can produce false positives when tests depend on one another or use a database.infection.github.io · 2 Oct 2026
Best Infection alternatives
See all 20Where it ranks on Everything Xiaomi
Is Infection yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- infection.github.io· checked 30 Sept 2026
- infection.github.io/guide/· checked 30 Sept 2026
- infection.github.io/guide/using-with-ci.html· checked 30 Sept 2026
- infection.github.io/guide/how-to.html· checked 30 Sept 2026
- infection.github.io/guide/static-analysis-integration.html· checked 30 Sept 2026
- infection.github.io/guide/mutation-badge.html· checked 30 Sept 2026
- infection.github.io/guide/installation.html· checked 30 Sept 2026
- github.com/infection/infection/blob/master/SECURIT· checked 30 Sept 2026
- github.com/infection/infection· checked 30 Sept 2026
- infection.github.io/guide/command-line-options.html· checked 2 Oct 2026
- infection.github.io/guide/infection-playground.html· checked 2 Oct 2026



