The small release history and zero commits in the last three months limit confidence in ongoing maintenance. Tests, a matching README, a recent release, and a clean license partly offset concerns about one maintainer, no security policy, and unpinned workflow actions.
65%
Total Score
50
100
88
67
Only one registry publishing maintainer is listed, leaving a thin publishing base. This is a modest continuity concern for a small user-owned project, though repository activity shows the project is not abandoned outright.
The package and repository are owned by the same individual account rather than an organization, so there is no visible organizational backing to offset the thin maintainer base.
The package is nearly eight years old but has only four releases, with a median interval of about two years and three months. One release in the last year and the recent latest release provide some evidence of continued ownership, but cadence is sparse.
There were zero commits and zero active maintainers in the last three months. The recent repository push and release provide some compensation, but ongoing development activity is currently absent.
Composer build tooling is present, but no security scanning tools were detected. For a small library this is a hygiene gap rather than evidence of abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
squizlabs/php_codesniffer Version ^3.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.