Usable with caveats: it is actively released, clearly licensed, tested, and backed by an organization. The main concerns are that all recent commits come from one contributor, the README calls the standard a work in progress for internal use, and the repository lacks a security policy and explicit top-level workflow permissions.
72%
Total Score
88
100
88
80
The package includes a substantial README, tests, a changelog, and release notes for version 1.0.11. The README also transparently describes the standard as a work in progress and primarily used by the owning organization, which limits confidence for external consumers.
All five recent commits came from one contributor, creating a real continuity risk. Organization backing provides some ability to hand off maintenance, but no second active contributor is shown.
Composer is used for builds, but no security-scanning tool was detected. This is a transparency and assurance gap, though it is not by itself evidence of an unsafe package.
The repository has no SECURITY.md or other detected security policy, leaving vulnerability-reporting and response expectations unclear.
Neither workflow declares top-level token permissions, and only one has job-level permissions. Explicit least-privilege permissions would provide stronger protection for the release automation.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
wp-coding-standards/wpcs Version ^3.0 | — | — |
phpcsstandards/phpcsextra Version ^1.2.0 | — | — |
phpcsstandards/phpcsutils Version ^1.0 | — | — |
squizlabs/php_codesniffer Version ^3.13 | — | — |
phpcompatibility/php-compatibility Version ^9.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.