The minimal artifact contains only composer.json and LICENSE, with no tests or security policy. Organization backing, a matching repository, and an MIT license provide useful transparency, but the seven runtime dependencies are unusually heavy for a code-analysis pack.
58%
Total Score
50
50
78
50
There were no commits and no active maintainers in the last three months, consistent with the absence of releases in the last year and increasing abandonment risk.
Seven runtime dependencies are declared, including PHP analysis and style tools such as Psalm, PHP CS Fixer, and PHP Insights. This is a substantial runtime dependency surface for a small code-analysis pack.
The package and repository each contain only LICENSE and composer.json. That may fit a small configuration pack, but it leaves little visible implementation or documentation to assess.
The artifact has no README, tests, or changelog, while the repository also reports no tests or changelog. The GitHub release exists for this version, but it has no release notes; this limits transparency for consumers.
The package has six releases over roughly four years, but none in the last 12 months; its latest release was over a year ago, which weakens confidence in ongoing maintenance.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
vimeo/psalm Version ^6.13 | — | — |
psalm/plugin-symfony Version ^5.2 | — | — |
phpmetrics/phpmetrics Version ^2.7 | — | — |
nunomaduro/phpinsights Version ^2.0 | — | — |
friendsofphp/php-cs-fixer Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.