Documentation and packaging are in good shape for a small coding-standard package. Its recent history is short, and all three recent commits came from one contributor; the organization backing reduces, but does not remove, that continuity concern. No security policy or scanning tooling is present.
70%
Total Score
63
100
81
83
Only one registry publishing account is listed. The organization-backed repository makes a short registry maintainer list less concerning, but it does not demonstrate multiple active publishers.
The package is only 43 days old with two releases about 16 days apart, so there is some release activity but limited history to establish long-term maintenance.
One contributor made all three commits in the last three months. Organization ownership provides some handoff capacity, but current activity is still concentrated in one person.
Three commits were made in the last three months, indicating recent work, but the small volume provides limited evidence of sustained maintenance.
Composer build tooling is present, but no security-scanning tooling was detected. For a small coding-standard package this is a modest transparency and maintenance gap rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
squizlabs/php_codesniffer Version ^3.11 | — | — |
dealerdirect/phpcodesniffer-composer-installer Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.