The source project still has a README and changelog, and its organization backing is reassuring. Recent repository commit activity is absent, while security scanning and a security policy are also missing.
55%
Total Score
75
50
88
83
Eight runtime dependencies, including analysis and build tools, make the package dependency-heavy for a coding-standard package and increase maintenance surface.
The package has had no release since February 2021, despite being a mature package first released in June 2019; this materially raises staleness and abandonment risk.
No commits or active maintainers were recorded during the last three months, which weakens evidence of ongoing maintenance despite the repository having been pushed in April 2025.
Composer build tooling is present, but no security-scanning tooling was detected; this is a modest transparency and maintenance gap rather than a standalone blocker.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpmd/phpmd Version ^2.8 | — | — |
vimeo/psalm Version ^4.0 | — | — |
phpro/grumphp Version ^1.0 | — | — |
phpstan/phpstan Version ^0.12 | — | — |
phpunit/phpunit Version ^9.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.