Healthy and suitable to depend on. It has a long release history, recent releases, active work from five contributors, clear licensing, documentation, and organizational backing; the main gap is the absence of a published security policy or security-scanning tooling.
92%
Total Score
100
100
94
90
Composer is used as a build tool, supporting reproducible project management. No security-scanning tools were detected, leaving a modest transparency and assurance gap.
The repository has no published security policy. For a maintained organization-backed package this is a documentation gap rather than evidence of abandonment, but it reduces clarity about vulnerability reporting.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
composer/semver Version ^3.4.2 | — | — |
composer/spdx-licenses Version ~1.6.0 | — | — |
phpcsstandards/phpcsextra Version 1.5.1 | — | — |
squizlabs/php_codesniffer Version 3.13.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.