IxDF coding standard: PHP_CodeSniffer rules and shared PHP-CS-Fixer configuration.
78%
Total Score
83
100
67
All 9 recent commits came from one contributor, creating a meaningful continuity risk. Organization ownership provides some handoff capacity, but no second active contributor is shown.
The repository has no security policy, leaving vulnerability-reporting expectations and response procedures undocumented.
All 16 analyzed action references are pinned, and no untrusted checkouts or script injections were found. The audit only identified low-confidence cache-poisoning patterns and one workflow with broad write permissions, so this is a minor hygiene concern rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
slevomat/coding-standard Version ^8.29 | — | — |
friendsofphp/php-cs-fixer Version ^3.89 | — | — |
squizlabs/php_codesniffer Version ^4.0 | — | — |
dealerdirect/phpcodesniffer-composer-installer Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.