﻿# How to use PVS\-Studio in JetBrains WebStorm and PhpStorm

PVS\-Studio analyzer can be used with the JetBrains WebStorm and PhpStorm IDEs\. PVS\-Studio IDE plugins provide a user\-friendly interface for analyzing JavaScript and TypeScript projects and individual files, as well as for handling the analyzer warnings\.

## Installing the plugin from the official JetBrains repository

To install PVS\-Studio plugin from the official JetBrains repository, open the settings window by selecting **File** \> **Settings** \> **Plugins**\. Then, select the **Marketplace** tab and enter **PVS\-Studio** in the search bar\. PVS\-Studio plugin appears in the search results:

 Click **Install** next to the plugin name\. After the installation, click **Restart IDE**\.



![WebStorm/image1.png](https://import.viva64.com/docx/blog/WebStorm/image1.png)

## After restarting the IDE, PVS\-Studio plugin is ready to analyze your code\.

##  Installing the plugin from the PVS\-Studio repository

In addition to the official JetBrains repository, PVS\-Studio plugin is also available in the PVS\-Studio repository\. To install the plugin from there, add this repository to the IDE\. To do this, click the **File \> Settings \> Plugins** command to open the plugin installation window\.

![WebStorm/image2.png](https://import.viva64.com/docx/blog/WebStorm/image2.png)

In that window, click the gear icon in the top\-right corner and select **Manage Plugin Repositories** in the drop\-down menu\. 

![WebStorm/image3.png](https://import.viva64.com/docx/blog/WebStorm/image3.png)

In the opened window, add [http://files\.pvs\-studio\.com/java/beta/pvsstudio\-webstorm\-plugins/updatePlugins\.xml](http://files.pvs-studio.com/java/beta/pvsstudio-webstorm-plugins/updatePlugins.xml) and click **OK**\.

The final installation step is the same as in the previous scenario of installing the plugin from the official repository: open the **Marketplace** tab and enter **PVS\-Studio** in the search box\. Select **PVS\-Studio for Rider** or **PVS\-Studio for JavaScript and TypeScript** in the search results, click **Install**, and restart the IDE\.

## How to install PVS\-Studio

To use PVS\-Studio analyzer in JetBrains WebStorm and PhpStorm, install the IDE plugin, as well as the analyzer core and its dependencies\.

If the plugin is installed via the PVS\-Studio installer on Windows, all the necessary components will be automatically installed and the step can be skipped\.

If the plugin was installed separately, download and install PVS\-Studio for the required platform\. The C\+\+ compiler components are also required to be installed\.

## How to enter a license

For detailed information on how to enter a license in WebStorm/PhpStorm, please refer to the [documentation](https://pvs-studio.com/en/docs/manual/0046/#JetBrainsProducts)\.

## How to configure the plugin

The plugin's settings panel includes several tabs\.

**Settings** contains settings of PVS\-Studio analyzer core\. To display the settings description, hover the mouse over a setting's name\. 

![WebStorm/image4.png](https://import.viva64.com/docx/blog/WebStorm/image4.png)

**Warnings** contains a list of all supported warning types\. If you uncheck the warning, all warnings of this type will be filtered out of the result table\.

![WebStorm/image5.png](https://import.viva64.com/docx/blog/WebStorm/image5.png)

**Analysis Paths** contains patterns for file names and paths that will be additionally included into or excluded from the analysis\.

![WebStorm/image6.png](https://import.viva64.com/docx/blog/WebStorm/image6.png)

**Registration** contains information about the current license\.

![WebStorm/image7.png](https://import.viva64.com/docx/blog/WebStorm/image7.png)

## How to analyze projects using PVS\-Studio

To analyze the current project, go to **Tools \> PVS\-Studio \> Check Project**\.

![WebStorm/image8.png](https://import.viva64.com/docx/blog/WebStorm/image8.png)

## How to handle analysis results

During the analysis, the table displays results in the **PVS\-Studio** window\. You can sort the entries in the table by any of them\. To change the sort order, click the column header\.

![WebStorm/image9.png](https://import.viva64.com/docx/blog/WebStorm/image9.png)

The table consists of seven columns \(from left to right\):

* **Favorite** marks a warning so you can quickly find it\.
* **Code** and **CWE** open a browser page that contains detailed descriptions of a warning or potential vulnerability\.
* **SAST** displays the compliance status of warnings according to various safety or security standards, such as SEI CERT, MISRA, AUTOSAR, etc\.
* **Message** contains a brief warning description\.
* **Position** contains a list of files related to the warning\.
* **False Alarms** displays warnings marked as false alarms\. The relevant subsection provides more details on handling false positives\.

Double\-click a row in the table to open the file at the line where the analyzer issued the warning: 

![WebStorm/image10.png](https://import.viva64.com/docx/blog/WebStorm/image10.png)

Above the table, arrow buttons allow switching to the previous \(Alt \+ \[\) or next \(Alt \+ \]\) analyzer message and opening the file in the code editor\.

There are also filters with warning certainty levels: **High**, **Medium**, **Low**, and **Fails** \(analyzer errors\)\.

![WebStorm/image11.png](https://import.viva64.com/docx/blog/WebStorm/image11.png)

Click the magnifying glass icon to open an additional panel with input fields for the columns: **Code**, **CWE**, **SAST**, **Message**, and **Position**\. Enter text into these fields to filter the messages in the table by the selected field or fields\.

![WebStorm/image12.png](https://import.viva64.com/docx/blog/WebStorm/image12.png)

To open the additional settings panel, click the button in the upper\-left corner:

![WebStorm/image13.png](https://import.viva64.com/docx/blog/WebStorm/image13.png)

To open the plugin main settings window, click the gear icon** **or go to **Tools \> PVS\-Studio \> Settings**\.

### Viewing interesting analyzer warnings

If you just getting started with a static analysis tool and want to evaluate their features, try to use the [Best Warnings](https://pvs-studio.com/en/docs/manual/6532/) mechanism\. It shows the most important and reliable warnings\. 

To view them, click the **Best** button:

![WebStorm/image14.png](https://import.viva64.com/docx/blog/WebStorm/image14.png)

### How to handle false positives

In some cases, the analyzer may report a warning for a line of code that does not actually contain an error\. Such warnings are referred to as [false positive](https://pvs-studio.com/en/blog/terms/6461/)\. 

In PVS\-Studio plugin, you can mark an analyzer warning as a false positive\. With this marker, you can hide warnings in future analysis runs\. 

To mark false alarms, select one or more analyzer messages in the **PVS\-Studio** table, right\-click any row in the table, and select **Mark selected messages as False Alarms from the context menu**:

![WebStorm/image15.png](https://import.viva64.com/docx/blog/WebStorm/image15.png)

The analyzer will add a special comment to the line for which a warning is issued: `//-Vxxx`, where `xxx` is PVS\-Studio diagnostic rule number\. You can manually add a comment to the code\.

To display false positives marked earlier in the PVS\-Studio window table, use the **Show False Alarms** setting via the **Tools \> PVS\-Studio \> Settings** menu command:

![WebStorm/image16.png](https://import.viva64.com/docx/blog/WebStorm/image16.png)

To remove the false positive mark from selected messages, use the **Remove False Alarm Marks From Selected Messages** context menu command\.

For detailed information on how to suppress warnings issued by PVS\-Studio, as well as information on other suppression methods, please refer to the [documentation](https://pvs-studio.com/en/docs/manual/0017/)\.

### The context menu for the warning table and keyboard shortcuts

To open a context menu that contains additional commands for the selected analyzer messages, right\-click a row with the analyzer message in the PVS\-Studio window table\. To change keyboard shortcuts, go to **File \> Settings \> Keymap** menu and enter **PVS\-Studio** in the search field:

![WebStorm/image17.png](https://import.viva64.com/docx/blog/WebStorm/image17.png)

* **Copy Selected Messages To Clipboard** \(`Ctrl + C`\) copies all warnings selected in PVS\-Studio plugin's analysis results window to the clipboard\.
* **Mark Selected Messages As Important** \(`Alt + Y`, `Alt + Y`\) marks a warning with a star to ease its find later when sorting by the **Favorite** column\.
* **Mark Selected Messages As False Alarms** \(`Alt + Y`, `Alt + A`\) marks selected analyzer messages as false alarms by adding a special comment to the code for which the warning was issued \(for more details, see the relevant subsection\)\.
* **Remove False Alarm Marks From Selected Messages** \(`Alt + Y`, `Alt + R`\) removes the false positive marks from the selected analyzer warnings\. 
* **Hide All** `<diagnostic number>` **Errors** \(`Alt + Y`, `Alt + H`\) hides all events that have that number\.
* **Exclude From Analysis** enables adding a path or part of a path to the file where the analyzer warning was detected to the list of directories excluded from analysis\. The filter will exclude from the analysis all files whose paths match the specified paths\.

The **Show Columns** submenu opens a list of column names that can be hidden or displayed\.

![WebStorm/image18.png](https://import.viva64.com/docx/blog/WebStorm/image18.png)

### How to save and load analysis results

To save or download analysis results, use the main menu commands available under **Tools \> PVS\-Studio**:

![WebStorm/image19.png](https://import.viva64.com/docx/blog/WebStorm/image19.png)

* **Open Report** opens the `.json` report file and loads its contents to a table in the **PVS\-Studio** window\.
* **Save Report** saves all warnings from the table \(including filtered ones\) to a `.json` report file\. If the current analysis results have not yet been saved, enter a name and select a location to save the report\.
* **Save Report As** saves all warnings from the table \(including filtered ones\) to the `.json` report file and allows selecting a location on the disk where to save the report\.