The source remains identifiable, licensed, tested, and recently pushed, but its workflow references are all unpinned. Use phpstan/phpstan instead, which Packagist identifies as the replacement.
18%
Total Score
50
75
83
Packagist marks the entire package abandoned and names phpstan/phpstan as its replacement. This is a severe adoption and future-maintenance risk.
The package has four releases since November 2022, with no release in the last 12 months; the latest release was in November 2024. This supports the abandonment concern.
The repository had no commits and no active maintainers in the last three months, despite a push in September 2025. Recent inactivity weakens confidence in ongoing maintenance.
The single workflow was fully analyzed with no dangerous findings, but all 6 action references are unpinned. This is a supply-chain hygiene gap, not a severe risk by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpstan/phpstan Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.