The repository has tests, a changelog, recent commits from two contributors, and release notes for this version. All 18 workflow action references are unpinned, and the project lacks a security policy.
82%
Total Score
75
100
94
50
The package has been maintained since 2020 with 34 releases and a release in the last year, although only one release occurred in that period, indicating a slower current cadence.
Two contributors are active, but one accounts for 80% of recent commits, leaving maintenance somewhat concentrated.
The repository has no security policy, which is a transparency gap, although this small static-analysis rules package does use Dependabot.
Both workflows were analyzed without high-confidence audit findings or untrusted-trigger sinks, but all 18 action references are unpinned, reducing build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
phpstan/phpstan Version ^2.0 | — | — |
larastan/larastan Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.