Healthy and reasonable to adopt. It has regular stable releases, active recent development, repository tests, and organization backing; the main caveat is that all recent commits come from one contributor and workflow permissions are not explicitly restricted.
82%
Total Score
88
100
94
90
All 19 recent commits came from one contributor, creating concentration risk; the organization-owned repository provides some compensation because maintenance can potentially be handed off internally.
Composer build tooling is present, but no security scanning tools were detected, leaving a security-hygiene gap without outweighing the repository's active maintenance and CI evidence.
All three workflows lack top-level token permission declarations, so their default GitHub Actions token access is not explicitly minimized.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpstan/phpstan Version ^2.2.6 | โ | โ |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikidoโs Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliantยฉ All Intel data is openly available and commercially licensed.