The focused seven-file package has a usable README and its repository matches the package, but it has no security scanning and one unresolved issue. Its stable version and organization backing help, though ongoing maintenance capacity is unclear.
47%
Total Score
67
81
50
No declared license, license file, or repository license file was detected. This is a transparency and adoption concern because downstream users cannot establish clear reuse terms.
The latest release was published over three years ago, with no releases in the last 12 months and only three releases overall. This indicates a meaningful maintenance concern for a development tool.
The repository recorded no commits and had no active maintainers in the last three months. The package is small, but this still leaves current compatibility and maintenance uncertain.
One issue remains open, with no issue or pull-request activity in the last month. This is a modest sign of limited project attention rather than evidence of abandonment on its own.
The repository uses Composer, but no security-scanning tooling was detected. For a small configuration package this is a hygiene gap, though it is partly offset by the limited file tree.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
phpro/grumphp Version ^1.0 | — | — |
phpstan/phpstan Version ^1.8 | — | — |
squizlabs/php_codesniffer Version ^3.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.