Consumers get little evidence about ongoing compatibility or change management. The repository has had no commits since June 2021 and the registry shows only one release; MIT licensing and a matching repository provide basic transparency but do not offset the inactivity.
42%
Total Score
75
71
75
The published artifact contains only composer.json and one source file. That may fit a narrowly scoped test fixer, but it provides little implementation and documentation surface for assessing maturity.
This is the sole release, published about five years ago, with no releases in the last 12 months. That strongly limits evidence of ongoing maintenance.
There were zero commits and zero active maintainers in the last three months. Combined with the single old release, this is strong evidence of inactive maintenance.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these counters provide no additional adoption or review signal.
Composer is used as the build tool, which fits the package ecosystem, but no security scanning tools were detected. This is a modest transparency and hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
phpunit/phpunit Version ^6.5 | — | — |
friendsofphp/php-cs-fixer Version ^2.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.