The source includes tests, useful documentation, a matching repository, and a GitHub release, with no install-time scripts. Workflow references are unpinned and the repository has no security policy, which weakens maintenance hygiene.
62%
Total Score
75
100
75
75
This is the only release, published about 162 days ago, so there is little release history from which to judge sustained maintenance. The project is still relatively new rather than demonstrably abandoned.
There were zero commits and zero active maintainers in the last three months. With only one release, this leaves maintenance continuity unproven, although the package is still young.
The repository has zero stars, forks, and watchers, providing no community adoption signal. Popularity is supporting evidence, so this does not by itself make the package unsafe.
Composer build tooling is present, but no security scanning tool was detected. For a small package this is a hygiene limitation rather than evidence of abandonment.
The repository has no security policy. That reduces transparency about vulnerability reporting and response expectations, though it is not a severe risk on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
friendsofphp/php-cs-fixer Version ^3.68 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.