The repository released version 4.0.3 recently and includes tests, release notes, and a clear license. Maintenance is concentrated in one contributor, workflow actions are all unpinned, and the package points to a replacement, so pinning this release is a poor long-term choice.
44%
Total Score
67
100
75
50
The package is marked abandoned at package scope and names infinum/eightshift-coding-standards as its replacement. This is the strongest adoption warning, even though the repository remains active.
All 3 commits in the last 3 months came from one contributor, giving the project a concentrated short-term maintenance base. Organization backing provides some handoff capacity but does not remove the current concentration.
The repository had 3 commits in the last 3 months, so activity has not stopped, but the volume is modest for a project with an active release cadence.
The repository name does not match the assessed package name and its README does not mention that package. This weakens package-to-source transparency, even though a renamed or replacement project may explain the mismatch.
The repository uses Composer for builds but reports no security-scanning tools. For a coding-standards package this is a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
slevomat/coding-standard Version 8.22.1 | — | — |
wp-coding-standards/wpcs Version 3.4.1 | — | — |
phpcompatibility/phpcompatibility-wp Version 3.0.0-alpha2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.