The project has one registry maintainer, no security scanning, and no recent issue activity. Its MIT license, README, and matching repository improve transparency, but the old toolchain shows no current maintenance.
35%
Total Score
0
67
75
The package has had no release in more than seven years: its latest release was in September 2019, with no releases in the last 12 months. This is strong evidence of abandonment for a tooling package.
The repository recorded zero commits and zero active maintainers in the last 3 months, reinforcing the long release gap rather than showing ongoing maintenance.
The repository has zero stars and forks and only one watcher. Popularity is not required for health, but these figures provide no supporting evidence of an active user or maintainer community.
The repository uses Make and Composer, which supports reproducible project tasks, but it has no security scanning tooling. That is a maintenance and transparency gap, though not severe by itself.
No security policy is present in the repository, leaving no documented channel or process for reporting vulnerabilities. This matters for a package that supplies development tooling and dependencies.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpmd/phpmd Version ^2.7 | — | — |
symfony/test-pack Version ^1.0 | — | — |
mavimo/phpstan-junit Version ^0.2.3 | — | — |
phpstan/phpstan-symfony Version ^0.11.6 | — | — |
friendsofphp/php-cs-fixer Version ^2.15 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.