Usable with caveats: releases are regular and the current version is stable, but the package has no README, declares a proprietary license, and offers little transparency about its source. Review licensing and package contents before adopting it.
58%
Total Score
100
80
75
The manifest declares a proprietary license and no license file is included, which creates a material legal and transparency concern for an open-source dependency.
The release contains only five configuration-oriented files, providing little evidence about the implementation or how the package is maintained. This is a transparency gap for a tool intended to be used in Drupal projects.
The artifact has no README, making a developer-facing code-quality tool harder to understand and integrate. Missing tests and changelog files are not concerns here because they normally belong to the source repository rather than the published artifact.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
drupal/coder Version ^8.3.25 | — | — |
phpstan/phpstan Version ^2.2 | — | — |
phpro/grumphp-shim Version ^2.0 | — | — |
mglaman/phpstan-drupal Version ^2.0 | — | — |
squizlabs/php_codesniffer Version ^3.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.