Rule for PHPStan that detects when production code depends on classes from Composer dev-dependencies, with flexible configuration to selectively allow certain classes or namespaces where needed.
62%
Total Score
50
100
88
50
Only one account has registry publishing access. The repository is user-owned rather than organization-backed, so there is limited visible publishing redundancy.
All three releases arrived on the first day, and there has been no newer release for about nine months. This suggests limited demonstrated maintenance, though the package is still relatively young.
The repository had zero commits and zero active maintainers in the last three months. Combined with the roughly nine-month release gap, this is meaningful evidence of currently inactive maintenance.
The project uses Composer for its build, but no security-scanning tool was detected. For a small static-analysis extension this is a modest transparency and maintenance gap.
No security policy was found in the repository. This weakens the documented process for reporting and handling dependency or rule issues, though it is not by itself evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpstan/phpstan Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.