The source repository is active and organization-owned, with recent releases, tests, release notes, and security scanning. However, the registry status makes this release a poor dependency choice; use the maintained replacement package named by the registry instead.
22%
Total Score
67
86
50
Packagist marks the entire package as abandoned and names facile-it/facile-coding-standard as its replacement. Package-level deprecation is a severe adoption risk even though other signals show ongoing repository activity.
One contributor made all commits in the last 3 months. Organization backing helps with handoff potential, but no second recently active contributor is shown.
Only 2 commits were made in the last 3 months by one active maintainer. Recent activity exists, but the low volume provides limited evidence of broad maintenance capacity.
The repository has no security policy. This is a transparency gap, although the available Dependabot and Psalm tooling provides some compensating security process evidence.
The complete audit found no high-confidence workflow findings, dangerous triggers, or untrusted checkouts. All 10 action references are unpinned, which is a supply-chain hygiene weakness, while the absence of a top-level permissions block is acceptable on its own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^5.4 || ^6.0 || ^7.0 || ^8.0 | — | — |
friendsofphp/php-cs-fixer Version ^3.88 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.