The package has explicit Composer dependencies, a matching repository, and a readable README with release notes. Its GPL-3.0 declaration improves clarity, but the absence of security scanning or a security policy leaves less evidence for safe upkeep.
40%
Total Score
25
100
83
83
The repository recorded zero commits and zero active maintainers in the last three months. That is strong evidence that maintenance has stopped, even though the repository is not formally archived.
The package and repository are owned by the same individual account, providing consistent ownership context. Individual ownership does not establish a broad maintenance team, so it does not offset the lack of recent activity.
This package has one release, published over seven years ago, with no releases in the last 12 months. A tiny, stable package can need few releases, but this long silence raises abandonment and compatibility concerns.
Composer is used as the build tool, which fits the package ecosystem. However, no security scanning tools are present, leaving a modest verification gap alongside the long maintenance silence.
The repository has no documented security policy. For a package that installs coding tools and a commit hook, this reduces transparency about reporting and handling dependency or release issues.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
automattic/vipwpcs Version * | — | — |
wp-coding-standards/wpcs Version 1.* | — | — |
phpcompatibility/phpcompatibility-wp Version * | — | — |
dealerdirect/phpcodesniffer-composer-installer Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.