The linked project shows no recent maintenance or security policy, and its repository does not identify this package. Composer tooling and a stable version offer little reassurance.
15%
Total Score
50
25
50
Packagist marks the entire package as abandoned and points to a replacement package, making this release unsuitable for a new dependency despite the replacement guidance.
The latest release was nearly 12 years ago, with no releases in the last 12 months. This strongly indicates abandonment rather than an actively maintained stable package.
No license declaration or license file was found. That creates a real adoption and redistribution concern for a package intended as a dependency.
The repository recorded no commits or active maintainers in the last 3 months, and its last push was about 8 years ago. This leaves current maintenance capacity unproven.
The repository name does not match the package name and its README does not mention the package, so the linkage is not clearly established. Organization backing provides some context but does not resolve that gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
squizlabs/php_codesniffer Version >=1.4.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.