Usable with caveats: it is licensed, stable, documented, tested, and backed by a non-archived organization repository. Maintenance has gone quiet since the January release, and the repository README does not explicitly mention the package.
74%
Total Score
75
81
75
The package has existed since June 2021 with 13 releases, but only one release appeared in the last 12 months, indicating a slow maintenance cadence.
There were no commits and no active maintainers in the three months measured; the recent release partly compensates, but the lack of ongoing activity raises abandonment risk.
The repository name matches the package, but its README does not mention the package explicitly, leaving a small transparency gap about the artifact-to-repository link.
Composer build tooling is present, but no security-scanning tool was detected; this is a modest supply-chain hygiene gap rather than evidence the release is unsafe.
No security policy was found. This is a transparency gap, although the package is a coding-standards configuration rather than a service handling application data.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
automattic/vipwpcs Version ^3.0 | — | — |
wp-coding-standards/wpcs Version ^3.3 | — | — |
squizlabs/php_codesniffer Version ^3.13 | — | — |
sirbrillig/phpcs-variable-analysis Version ^2.13 | — | — |
phpcompatibility/phpcompatibility-wp Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.