At the moment we don’t have a rule that would catch such cross site scripting suspects. We’re actively working on this, so stay tuned for upcoming releases later this year. Note however that such rule might be limited to SonarQube/SonarCloud in the short-mid term, and not be available in SonarLint.
I’m doing this and working on it for MSc so could you give me an access to API or source code? and I will share results with you if you acknowledge my name.
We are working to provided XSS detection capabilities for Java, C# and PHP. This will be available in SonarCloud and with the SonarQube Developer Edition.
I’m resurrecting this old thread to confirm that the rule S5131 able to detect this PHP XSS issue is available on SonarQube 7.9.1 LTS and SonarCloud.io.