This is a clearly identified, MIT-licensed QA metapackage with a matching repository and a documented release. The clean install profile and organization ownership provide useful reassurance, though the project remains young and lightly staffed.
69%
Total Score
67
100
93
83
One contributor made all 28 recent commits, creating a real continuity risk; organization ownership offers some handoff capacity but does not provide evidence of a second active maintainer.
The repository recorded 28 commits in the last 3 months, indicating active work, although all activity came from one maintainer.
Composer is used for builds, but no security-scanning tooling was detected, leaving a modest supply-chain hygiene gap.
The repository has no security policy, which weakens transparency about vulnerability reporting and response expectations for a package intended to be reused.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
phpat/phpat Version ^0.12.4 | — | — |
phpmd/phpmd Version ^2.5 | — | — |
povils/phpmnd Version ^3.6 | — | — |
rector/rector Version ^2.5 | — | — |
seld/jsonlint Version ^1.12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.