Usable with caveats: it is an established, actively released ruleset with matching organization-backed source and no deprecation or archive status. The main concerns are one-person recent commit activity, no tests or security policy, and very low repository adoption.
72%
Total Score
70
100
83
90
A README and changelog are present, but neither the package nor repository contains tests; for a small ruleset this is a real maintenance and regression-testing gap.
All recent commits came from one contributor, creating concentration risk; the organization-owned repository provides some ability to hand maintenance off, so this is a caution rather than a severe risk.
Only one commit was recorded in the last 3 months and it came from one active maintainer; recent releases and a current repository push compensate for this being sparse, but it still limits evidence of sustained maintenance capacity.
There are 4 open issues and no new or closed issues in the last month, but one pull request was merged; this suggests limited public activity without clear abandonment.
The repository has only 2 stars and 1 fork, offering little external adoption evidence; popularity is supporting evidence rather than a decisive health requirement for a specialized internal ruleset.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpstan/phpstan Version ^2 | — | — |
phpstan/phpstan-dibi Version ^2 | — | — |
phpstan/phpstan-nette Version ^2 | — | — |
staabm/phpstan-todo-by Version ^0.3 | — | — |
phpstan/phpstan-strict-rules Version ^2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.