Usable with caveats: it is actively released, clearly licensed, and backed by an organization, but the project is only 50 days old and all recent commits come from one contributor. The repository also lacks tests and a security policy.
72%
Total Score
83
100
83
90
A README is present, but neither the artifact nor repository contains tests or a changelog. For a small coding-standard package this is a hygiene gap, though GitHub Releases provide some release tracking.
One contributor made all 16 commits in the last 3 months, creating a genuine continuity risk. Organization ownership partly compensates because maintenance can potentially be handed off, but no second active contributor is shown.
The repository has 0 stars, 0 forks, and 1 watcher, so there is little public adoption evidence. Popularity is supporting evidence only, and the organization backing and recent activity provide some compensation.
Composer is used as the build tool, which fits the PHP package. No security-scanning tools are configured, leaving a modest transparency and assurance gap.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a transparency gap, although the package is a small development-time coding-standard tool.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
slevomat/coding-standard Version ^8.22.1 | — | — |
wp-coding-standards/wpcs Version ^3.4.1 | — | — |
squizlabs/php_codesniffer Version ^3.13.6 | — | — |
phpcompatibility/php-compatibility Version ^9.3.5 | — | — |
phpcompatibility/phpcompatibility-wp Version ^2.1.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.