The package is small and focused, with a clear README, MIT license, and no install-time scripts. Its last release and repository activity were in 2018, so ongoing compatibility support is uncertain.
45%
Total Score
50
100
72
83
The package has only three releases, all around February 2018, and no releases in the last eight years. This is strong evidence of a potentially abandoned dependency, even if the configuration may be stable.
There were no commits or active maintainers in the last three months, consistent with the release history showing no activity since 2018.
The repository has one star, zero forks, and one watcher, indicating little independent adoption or visible community support. Low popularity alone is not disqualifying, but it provides no compensating maintenance signal.
Composer is used for the build, but no security-scanning tool is configured. For this small coding-standard package that is a modest transparency gap, not a standalone severe risk.
The repository is not archived, but it was last pushed in April 2018, so its unarchived status does not demonstrate current maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
squizlabs/php_codesniffer Version ^3.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.