Its MIT declaration, focused four-file tree, and matching repository make its purpose clear. The organization-backed repository is not archived, but it lacks security policy and scanning, and appears lightly maintained.
43%
Total Score
50
100
75
83
The latest release was over seven years ago, with no releases in the past 12 months. Only four releases exist, so ongoing compatibility and maintenance are uncertain.
There were no commits and no active maintainers in the last three months, consistent with the repository having stopped moving after March 2019. This is a substantial abandonment concern.
There has been no issue or pull-request activity in the last month, with one issue still open. This offers no evidence of current maintenance.
Composer is used for builds, but no security-scanning tooling was detected. For a small ruleset this is a modest transparency and maintenance gap rather than a decisive risk.
The repository has no security policy. That weakens disclosure transparency, although this package's narrow configuration role limits the significance of the gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
slevomat/coding-standard Version ^5.0 | — | — |
escapestudios/symfony2-coding-standard Version ^3.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.