Recent releases, active commits, and broad contributor activity show strong ongoing maintenance. Clear licensing, tests and changelog in the repository, and security tooling support adoption, though workflow dependency pinning remains weak.
62%
Total Score
100
88
67
Packagist marks the entire package abandoned and names friendsofphp/php-cs-fixer as its replacement, which creates meaningful dependency and support risk despite the repository remaining active.
A post-autoload-dump install script runs during Composer installation, adding execution during setup; this is a modest operational concern rather than evidence of poor maintenance.
All 14 workflows were analyzed with no high- or medium-severity findings and no untrusted checkout or script-injection sinks. However, all 28 action references are unpinned, four workflows grant top-level write permissions, and one high-confidence audit found an ad hoc package install.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react/socket Version ^1.16 | — | — |
react/stream Version ^1.4 | — | — |
sebastian/diff Version ^4.0.6 || ^5.1.1 || ^6.0.2 || ^7.0 || ^8.0 || ^9.0 | — | — |
symfony/finder Version ^5.4.45 || ^6.4.24 || ^7.0 || ^8.0 | — | — |
composer/semver Version ^3.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.