The project has had no commits or releases for more than 11 years, and its single maintainer leaves little evidence of ongoing support. Clear licensing, documentation, tests, and release notes improve transparency but do not offset the age of the dependencies and project.
38%
Total Score
0
50
75
50
The latest release was published more than 11 years ago, with no releases in the last 12 months; this is strong evidence that the package is no longer maintained.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the long release gap and indicating no current maintenance capacity.
The package bundles six runtime requirements, including several development and reporting tools, but provides no newer release evidence to show those dependencies remain current.
The repository is not marked as archived, but its last push was more than 11 years ago; the lack of archival status does not compensate for the observed inactivity.
The repository has no security policy or security-scanning tooling. For an old package with no current activity, this leaves vulnerability reporting and review practices unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpmd/phpmd Version ~2.0 | — | — |
phpunit/phpunit Version ~4.1 | — | — |
phpunit/php-invoker Version ~1.1 | — | — |
satooshi/php-coveralls Version ~0.6 | — | — |
squizlabs/php_codesniffer Version ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.