Regular releases, clear documentation, tests, and organizational ownership support continued use. The repository lacks a security policy and scanning, while all eight workflow action references are unpinned.
68%
Total Score
63
94
50
Post-install and post-update Composer scripts modify PHPCS configuration, which adds install-time behavior beyond passive library files and warrants modest caution.
One contributor made all seven recent commits, leaving a thin operational base; organization ownership provides some handoff capacity but no second active contributor is shown.
Seven commits landed in the last three months, showing recent work, but all activity is concentrated in one active maintainer.
The repository has 65 open issues and 31 open pull requests, with no issues or pull requests opened or closed in the last month; this is a mild maintenance concern but not evidence of abandonment by itself.
Composer build tooling is present, but no security scanning tools were detected, leaving a transparency and monitoring gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
rector/rector Version ^1.2.4 || ^2.0.0 | — | — |
webonyx/graphql-php Version ^15.0 | — | — |
phpcsstandards/phpcsutils Version ^1.2.2 | — | — |
squizlabs/php_codesniffer Version ^3.10.2 | — | — |
magento/php-compatibility-fork Version ^0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.