Healthy and suitable to use. It has a long release history, a recent stable release, active organization backing, and two recent contributors; the main caveats are limited recent repository activity and no published security policy.
88%
Total Score
90
100
94
75
There are only four open issues and one open pull request, but no issues or pull requests were opened or closed in the last month; this is a mild activity gap, partly offset by the recent release and commits.
The repository uses Composer build tooling, but no security scanning tools were detected; this is a transparency gap, not evidence of unsafe behavior.
No repository security policy was found, leaving vulnerability-reporting guidance unclear; the package's otherwise active organization-backed maintenance partially reduces the concern but does not remove it.
The repository workflow has no top-level token permissions declaration. No write permissions were observed, but explicit least-privilege settings would improve workflow transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpstan/phpdoc-parser Version ^2.1 | — | — |
slevomat/coding-standard Version ^8.23 | — | — |
squizlabs/php_codesniffer Version ^4.0.2 | — | — |
dealerdirect/phpcodesniffer-composer-installer Version ^1.1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.