Usable with caveats: the repository is active, clearly backs the package, and the release is stable, but the project has a sparse release history, no recent recorded commits, and no license file or declaration. Confirm the licensing and maintenance expectations before adopting it broadly.
62%
Total Score
75
100
75
75
Neither the registry metadata nor the package or repository contains a license file. This creates a real legal and transparency concern for a dependency.
The package has existed for about 5 years but only has 4 releases, with a median interval of about 444 days and just 1 release in the last 12 months. This suggests slow maintenance rather than abandonment, so it is a caution.
No commits and no active maintainers were recorded in the last 3 months, despite the repository being recently pushed. This weakens evidence of ongoing development and warrants caution.
The repository has 0 stars and 0 forks, providing little independent evidence of community adoption. Popularity is only supporting evidence, so this is a caution rather than a severe risk.
The repository uses Composer for builds, but no security scanning tools were detected. For this small helper, the missing scanning is a hygiene gap rather than evidence of unfitness.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
friendsofphp/php-cs-fixer Version >=3.94 | — | — |
squizlabs/php_codesniffer Version >=3.13 | — | — |
phpcompatibility/php-compatibility Version >=9.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.