The repository includes tests, release notes, and Dependabot-backed tooling, while the package is clearly licensed. Its single maintainer and quiet recent release history leave less evidence of sustained support.
65%
Total Score
67
100
93
75
Only one registry account has publish access. That is a limited publishing base, but it is consistent with the directly matching user-owned repository and does not by itself show abandonment.
There have been no releases in the last 12 months, despite a release cadence of roughly one every 98 days before then. This weakens evidence of ongoing maintenance, though the repository was pushed more recently.
The repository recorded zero commits and zero active maintainers in the last 3 months. That is a concrete sign of currently quiet development, although the repository is not archived and was pushed recently.
No repository security policy was found. This is a transparency gap, but it is less serious for a PHP coding-standard package than for software handling sensitive runtime data.
All four analyzed action references are unpinned, so workflow dependencies can drift; this is a hygiene concern. The workflow uses read-only permissions, has no untrusted checkout or injection findings, and the audit completed fully.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
slevomat/coding-standard Version ^8.14 | — | — |
squizlabs/php_codesniffer Version ^3.7 | — | — |
dealerdirect/phpcodesniffer-composer-installer Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.