The package is clearly documented, licensed, tested in its repository, and released with notes. Maintenance depends on one contributor, while workflow template-injection findings and unpinned actions leave avoidable supply-chain hygiene concerns.
67%
Total Score
50
88
83
The registry namespace and repository are owned by the same user account, which supports package identity but does not provide the maintenance redundancy of organization ownership.
One contributor made all commits in the last three months, concentrating maintenance responsibility entirely in a single person. The repository owner is a user account, so no organization backing is shown to offset that concentration.
Only two commits were made in the last three months, showing limited recent activity even though a release was published during that period.
Composer is used for the build, but no repository security-scanning tool was detected. This is a modest transparency and assurance gap rather than evidence of unsafe code.
The repository has no security policy, leaving no documented path for reporting vulnerabilities or explaining security response expectations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpstan/phpstan Version ^2.0 | — | — |
phpstan/phpstan-strict-rules Version ^2.0 | — | — |
swissspidy/phpstan-no-private Version ^1.0 | — | — |
szepeviktor/phpstan-wordpress Version ^2.0 | — | — |
phpstan/phpstan-deprecation-rules Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.