Documentation, tests, licensing, and a matching organization-owned repository make the package transparent to inspect. Its broad dependency set and install-time scripts add maintenance and integration risk, with no security policy or scanning evidence.
35%
Total Score
50
50
75
67
The package has made no releases in more than eight years, despite 51 releases overall; this strongly indicates that maintenance has stopped.
The repository recorded zero commits and zero active maintainers in the last three months, corroborating the long release gap rather than showing merely slower maintenance.
Fifteen runtime dependencies, including testing, linting, and code-quality tools, create a broad dependency surface for a development utility and increase maintenance burden.
Post-install and post-update scripts are relevant to a package that configures Git hooks, but they also execute automatically during dependency operations and increase integration risk.
The repository has zero stars and one fork, offering little supporting evidence of broad adoption; this is secondary to the direct inactivity evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpmd/phpmd Version ~2.6 | — | — |
symfony/flex Version ~1.0 | — | — |
symfony/yaml Version ~3.0|~4.0 | — | — |
seld/jsonlint Version ~1.5 | — | — |
symfony/config Version ~3.0|~4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.