This release appears healthy and suitable for dependency use: it is a stable, non-deprecated release with an unusually active recent release cadence, a current non-archived organization-backed repository, substantial repository activity, tests, changelog, clear documentation, and a license file. The main reservations are its large runtime dependency profile, install-time Composer lifecycle scripts, absence of a security policy, and one workflow with top-level write permissions; these warrant normal review and controlled installation, but are not evidence of abandonment or unfitness.
86%
Total Score
100
50
94
70
The package declares 36 runtime dependencies, including extensive testing, linting, static-analysis, WordPress, and deployment tooling. That breadth is consistent with a shared development workspace, but it increases transitive dependency and update surface.
The package declares five Composer lifecycle scripts, including pre-install, post-install, pre-update, and post-update hooks. Because this is a Composer plugin that provides development automation, such hooks may be functional requirements, but they increase installation and update complexity and should be reviewed.
The repository uses Composer build tooling, but no security-scanning tools were detected. Build tooling is appropriate, while the missing automated security scanning is a modest transparency and assurance gap.
No SECURITY.md or equivalent security policy was detected. For a package containing deployment and automation tooling, this is a genuine transparency gap, although it does not by itself indicate abandonment.
Both workflows declare top-level permissions; one is read-only and one Dependabot-triage workflow has top-level write permissions. The explicit permissions are preferable to an undeclared default, but write access increases workflow-impact risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spatie/ray Version ^1.41 | — | — |
behat/behat Version ^3.14 | — | — |
nyholm/psr7 Version ^1.8 | — | — |
phpmd/phpmd Version ^2.15 | — | — |
phpstan/phpstan Version ^1.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.