Its README and matching seven-file repository make the configuration easy to understand, and it has no install-time scripts. The single maintainer, absent security policy, and nine runtime dependencies leave little evidence of ongoing support.
38%
Total Score
0
50
72
83
The package has 38 releases since March 2019, but its latest release was in June 2022 and it had no releases in the following 12 months, indicating prolonged abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's long release gap and limited evidence of current maintenance.
This focused configuration package declares nine runtime dependencies, including several analysis and linting tools, increasing maintenance exposure even though the dependencies fit its stated purpose.
Neither the package nor the linked repository provides a license declaration or license file, leaving the terms for using this dependency unclear.
The repository has only 1 star and 2 forks, providing little supporting evidence of broad review or community maintenance; this is secondary to the stronger inactivity signals.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^2.0 | — | — |
drupal/coder Version ^8.3 | — | — |
phpro/grumphp Version ^1.1 | — | — |
phpstan/phpstan Version ^1.7.8 | — | — |
friendsoftwig/twigcs Version ^6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.