Its MIT licensing, focused dependency set, matching repository, and recent release notes support routine use. Maintenance has paused for three months, while workflow actions are unpinned and no security policy or scanning is present.
70%
Total Score
75
100
94
83
There were no commits and no active maintainers in the last three months. The recent release partly offsets this, but the current pause lowers confidence in ongoing maintenance.
Composer and Make are used for project tooling, but no security scanning tool is configured. For a small configuration package this is a modest transparency and hygiene gap.
The repository has no security policy. This is a real transparency gap, though the package is small and has no reported workflow audit findings.
The workflow audit completed cleanly with no dangerous triggers, sinks, or findings, but both action references are unpinned. That leaves avoidable dependency-integrity risk in the build workflow.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
friendsofphp/php-cs-fixer Version ^3.93 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.