Usable with caveats: it has a stable release, clear licensing, tests, release notes, and an active organization-owned repository. However, only two releases arrived in the last year, there were no commits in the last three months, and the project lacks a security policy and automated security scanning.
68%
Total Score
75
88
90
The package has seven releases over roughly three years, with two releases in the last 12 months and a median interval of about 126 days. This indicates ongoing but relatively infrequent maintenance.
The repository recorded zero commits and zero active maintainers in the last three months. Although a release was published recently, the absence of recent development activity raises abandonment and maintenance-risk concerns.
Composer is used for builds, but no security scanning tools were detected. The missing scanning is a transparency and preventive-maintenance gap, though it is not evidence that the package is unsafe.
No repository security policy was found. This leaves vulnerability-reporting and response expectations undocumented, which is a meaningful but not decisive project-hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
slevomat/coding-standard Version ^8.15 | — | — |
squizlabs/php_codesniffer Version ^3.13.3 || ^4.0 | — | — |
phpcompatibility/php-compatibility Version ^10.0.0@dev | — | — |
dealerdirect/phpcodesniffer-composer-installer Version ^0.7 || ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.