The package is clearly licensed, documented, and backed by an organization, with repository tests and release notes. Its workflow uses four unpinned actions, and no commits were recorded in the last three months.
68%
Total Score
75
100
100
No commits and no active maintainers were recorded in the last three months. A recent release and non-archived repository partly compensate, but the current maintenance pause remains a real concern.
The single workflow was fully analyzed, uses read-only permissions, and has no detected audit findings or untrusted checkout paths. However, all four action references are unpinned, leaving avoidable version-drift and action-supply-chain exposure.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
squizlabs/php_codesniffer Version ^3.6 || ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.