A set of phpcs sniffs for modern php development.
38%
Total Score
50
70
83
The package borrows the identity of automattic/vipwpcs, which has 20 stable releases and about 431,424 monthly downloads, while this package has one release and no downloads in the measured period. Although artifact overlap is low, the identity borrowing makes it a serious risk that consumers wanted the established package instead.
This package has one release, with no releases in the last 12 months, and its latest release was in January 2018. That is strong evidence of stagnation for a package developers may need to keep compatible with modern projects.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's long release hiatus and increasing abandonment risk.
The repository has only 1 star and 2 forks, offering little supporting evidence of broad adoption or community scrutiny. Low popularity is not decisive by itself, but it provides no compensation for the inactivity.
Composer build tooling is present, but no security-scanning tooling was detected. This is a hygiene gap rather than proof of an unsafe release, and it matters more because maintenance activity is already absent.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.