The repository remains active under an organization and the release includes a README and release notes. Its small footprint and absent tests fit a ruleset package, but the long release gap and missing license reduce confidence.
54%
Total Score
75
75
67
No declared license, license file, or repository license file was detected. That creates a real legal and transparency gap for downstream users.
The latest release was over 2 years ago, and there were no releases in the last 12 months. This weakens maintenance confidence, although the package has eight releases and the repository remains available.
There were no commits and no active maintainers during the last 3 months. This indicates limited recent development, though the repository is owned by an organization and was pushed recently.
Composer is used for the build, providing expected package tooling. No security scanning tools were detected, leaving a modest repository hygiene gap.
The repository has no security policy. For a coding-rules package this is not a severe dependency risk, but it reduces transparency about vulnerability reporting.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
wp-coding-standards/wpcs Version ^3.0 | — | — |
squizlabs/php_codesniffer Version ^3.0 | — | — |
dealerdirect/phpcodesniffer-composer-installer Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.