The MIT license, clear README, changelog, and release notes make installation and use understandable. It has no security policy or security scanning, so ongoing maintenance would need extra scrutiny.
45%
Total Score
50
75
75
The package has had only two releases, with none in the last 12 months; its latest release was in December 2021, about 4 years and 9 months before collection. This is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the long release gap and indicating no observed maintenance.
The repository uses Composer, which supports reproducible project management, but no security-scanning tools were detected. The missing scanning is a modest maintenance and assurance gap.
No security policy was found. For a developer-tool package this is a transparency gap, although it does not by itself show that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
phpro/grumphp Version ^1.3 | — | — |
phpunit/phpunit Version ^9.0 | — | — |
squizlabs/php_codesniffer Version ^3.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.