Usable with caveats: the package is licensed, clearly backed by its organization, tested in the repository, and not deprecated or archived. However, the registry has had no release in nearly two years and repository activity shows no commits or merged pull requests in the last three months.
68%
Total Score
67
100
94
88
The package has existed since 2018 with 28 releases, but it has had no registry release in nearly two years, which raises maintenance and compatibility concerns.
No commits or active maintainers were recorded in the last three months, a meaningful maintenance concern despite the repository's recent push timestamp.
There are open issues and pull requests, but none were opened, closed, or merged during the last month, indicating limited recent activity.
No workflow declares top-level write permissions, and three declare read-only permissions; four omit a top-level permissions block, leaving some least-privilege settings implicit.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
phpstan/phpstan Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.