The repository has tests, a clear package match, and a long release history. Recent repository activity is quiet despite six releases in the last year, and its workflows use unpinned actions; no security policy is also a transparency gap.
66%
Total Score
50
100
94
75
The repository is owned by an individual rather than an organization, so the observed quiet commit activity provides limited evidence of maintenance capacity.
The repository recorded zero commits and zero active maintainers in the last three months, a meaningful maintenance concern even though the registry shows six releases in the last year.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest project-hygiene gap.
No security policy was found in the linked repository, reducing transparency for reporting and handling vulnerabilities.
Both workflows were analyzed successfully with no audit findings, and the pull_request_target workflow has no untrusted checkout or script-injection sink. However, both actions are unpinned, which leaves their exact revisions mutable.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version >=3.4.0 | — | — |
slevomat/coding-standard Version ^8.25.1 | — | — |
squizlabs/php_codesniffer Version ^4.0.1 | — | — |
sirbrillig/phpcs-variable-analysis Version ^2.13 | — | — |
dealerdirect/phpcodesniffer-composer-installer Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.