The repository is clearly tied to the package and backed by an organization, with a useful README and changelog. Its dependency bundle is expected for a linting preset, but the project has no security policy or automated security scanning.
62%
Total Score
75
100
89
83
This is a new package, only 94 days old, with one release and no established release cadence. That limits evidence of long-term maintenance.
One contributor made 100% of the two recent commits. Organization backing partly offsets the concentration, but maintenance still depends on a single observed contributor.
Only two commits were recorded in the last three months, with activity from one maintainer. This provides limited evidence of ongoing maintenance.
The repository uses Composer, but no security-scanning tools were detected. For a package that distributes configuration and tooling dependencies, this is a modest transparency gap.
No security policy was found in the repository. This is a maintenance and reporting gap, though the package is a development-time linting bundle rather than a runtime service.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpmd/phpmd Version ^3.x-dev | — | — |
mockery/mockery Version ^1.6 | — | — |
tightenco/tlint Version ^9.5 | — | — |
larastan/larastan Version ^3.0 | — | — |
phpstan/phpstan-mockery Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.