What you are looking for is called SCA (Software Composition Analysis) and SonarQube CE or greater doesn’t provide such a feature. We do SAST and detect vulnerabilities in your PHP code.
The recommended version if you care about code security is at minimum SonarQube Developer Edition.