Documentation and tests make integration straightforward, with a matching repository and a clean, read-only workflow audit. Its very recent release history and complete reliance on one contributor leave meaningful maturity and continuity concerns.
72%
Total Score
88
50
78
83
The package has five runtime dependencies, including the installer plugin and coding-standard libraries. This is reasonable for a PHPCS ruleset but creates several upstream compatibility points.
Only two releases exist and the package is less than one day old, so there is not yet enough history to establish long-term maintenance or release stability.
All 653 recent commits came from one contributor, creating a significant continuity risk. Organization backing partly compensates because maintenance can potentially be handed off.
The repository has one star and no forks or watchers. Low popularity is only supporting evidence and does not outweigh the strong recent activity.
Composer build tooling is present, but no security-scanning tools were detected. For a code-quality ruleset this is a modest transparency gap rather than a severe concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
slevomat/coding-standard Version ^8.15 | — | — |
squizlabs/php_codesniffer Version ^3.13 | — | — |
sirbrillig/phpcs-variable-analysis Version ^3.0 | — | — |
dealerdirect/phpcodesniffer-composer-installer Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.