The source repository is still active and has tests, release notes, security scanning, and a security policy. Its lone active contributor and long release gap add maintenance risk, while the package's declared replacement makes continued adoption a poor choice.
20%
Total Score
75
79
100
Packagist marks the entire package abandoned and names ghostwriter/phpstan-extension as a replacement, making this release unsuitable for a new dependency despite other healthy evidence.
Only three releases appeared, all within 12 days in August 2023, with no registry release in the last 12 months; this indicates a long release gap.
All 9 recent commits came from one contributor, so maintenance depends entirely on a single active person.
The single workflow was fully analyzed with no audit findings and uses no unpinned actions, but it grants top-level write permissions, which is a mild workflow-hygiene concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.