The single maintainer and missing security policy leave limited support and disclosure context. The package is clearly licensed, has a recent release with notes, and its repository is active enough to remain usable.
63%
Total Score
50
92
50
Only one registry account has publish access, limiting publishing redundancy; the repository is user-owned, so no organizational backing compensates for that narrow base.
The package has existed since 2019 with 18 releases, but only one release appeared in the last 12 months; this suggests a slower recent cadence despite its long history.
There were no commits and no active maintainers in the last three months. Although the repository was recently pushed for the assessed release, the short-term development gap raises maintenance risk.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities.
The only workflow was fully analyzed with no dangerous sinks or audit findings, but all 6 action references are unpinned, weakening build reproducibility and update control.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
slevomat/coding-standard Version ^8.0 | — | — |
squizlabs/php_codesniffer Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.