Usable with caveats: the package is actively released, stable, clearly backed by its matching organization repository, and has a useful README and tests. Maintenance is concentrated in one contributor, with only three commits in the last three months and limited security-policy hygiene.
72%
Total Score
80
100
94
80
All three recent commits came from one contributor, creating a meaningful continuity risk; organization backing provides some capacity to hand maintenance off, but no second active contributor is shown.
The repository received three commits in the last three months from one active maintainer, showing recent work but a thin maintenance cadence.
Composer build tooling is present, but no security scanning tools were detected, leaving a security-hygiene gap for a package that distributes development tooling.
The repository has no security policy, which makes vulnerability reporting and response expectations less transparent.
The only workflow does not declare top-level token permissions. No write permissions were observed, but explicit least-privilege settings would provide stronger CI safeguards.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
larastan/larastan Version ^v3.10.0 | — | — |
strictphp/conventions Version ^v2.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.