Usable with caveats: the package is licensed, clearly backed by a matching repository, tested, and not deprecated. However, it has had no registry release in about two years and no commits in the last three months, so future compatibility and maintenance are uncertain.
62%
Total Score
75
50
94
80
The package has five runtime dependencies, including Psalm and Twig, which is reasonable for an HTML-report plugin but creates compatibility obligations as those projects evolve.
Only two releases were published, with no releases in the last 12 months; the latest release is about two years old. This is a meaningful maintenance and compatibility concern for a Psalm plugin.
There were zero commits and zero active maintainers in the last three months. The recent repository push provides some compensation, but the current lack of development activity raises abandonment risk.
The repository has no security policy. This is a transparency gap, although the small plugin scope and other repository safeguards partly reduce its practical importance.
The sole workflow does not declare top-level token permissions. No write permissions were observed, but explicit least-privilege configuration would provide stronger CI safeguards.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.0 | — | — |
vimeo/psalm Version ^5.0 | — | — |
jetbrains/phpstorm-attributes Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.