Package Health

imbo/imbo-coding-standard

Imbo coding standard for PHP-CS-Fixer

Latest v3.0.10PackagistPackagist

65%

Total Score

caution

Usable with caveats: workflow automation has broad tokens and high-confidence injection findings.

Health Score Breakdown

Repo commit activitycaution

The repository reports zero commits and zero active maintainers in the last three months, a maintenance warning. The recent release history and same-day push partly offset this concern.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tooling was detected. For a small coding-standard package this is a modest transparency and maintenance gap.

Security policycaution

The linked repository has no security policy. This limits vulnerability-reporting transparency, though it does not by itself indicate abandonment.

Workflow auditcaution

All three workflows were analyzed, but one has a script-injection finding and top-level write permissions, while high-confidence findings report GitHub App tokens with blanket repository access and template-injection risks. The absence of untrusted checkouts reduces the likelihood of immediate exploitation, but the automation remains a meaningful supply-chain hygiene concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Christer Edvartsen
Contributors

Direct Dependencies

DependencyLast ReleaseScore
kubawerlos/php-cs-fixer-custom-fixers
Version ^3.35
—
—

Weekly Downloads

Info

Last Published
4 months ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform