The MIT license and README make its purpose and use clear, and the repository matches the package. Its single-user ownership and lack of security tooling add little support for long-term maintenance.
39%
Total Score
25
79
50
Only two releases were published, with the latest on February 13, 2017 and no releases in the following 12 months; this indicates about 9 years of release inactivity.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the long release gap and a high abandonment risk.
One registry maintainer is a thin publishing base for a package that aggregates 12 quality-assurance tools, leaving limited visible maintenance capacity.
Composer and Phing provide build tooling, but no security scanning tools were detected, leaving a transparency and maintenance gap for an old dependency bundle.
The repository has no security policy, reducing guidance for reporting or handling vulnerabilities; this reinforces the maintenance concerns but is not severe alone.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phing/phing Version ^2 | — | — |
phpmd/phpmd Version ^2.6 | — | — |
symfony/yaml Version ^2.8 | — | — |
phploc/phploc Version ^2.1 | — | — |
theseer/phpdox Version 0.8.1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.