The project has a long release history, a current stable release, working repository tests, and clear release notes. Workflow references are all unpinned and the repository reports no security scanning, leaving moderate hygiene concerns.
78%
Total Score
50
100
94
83
The registry lists one publishing account. That is a limited publishing base, but the repository and release history provide evidence of ongoing project activity, so this is only a minor concern.
The registry namespace and repository are owned by the same individual account rather than an organization. This indicates limited formal backing, but the matching repository and release activity provide compensating evidence.
There were zero commits and zero active maintainers in the three months measured, despite a recent package release and repository push. The release history compensates for some of this, but the current development cadence is less clear.
The repository has only 2 open issues and 3 open pull requests, although none were opened or closed in the last month. The small backlog is fine, but the recent inactivity limits evidence of responsive maintenance.
The repository uses Make and Composer for builds, but no security-scanning tool was detected. Build tooling is present; the missing scanner is a modest transparency and hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpstan/phpstan Version ^2.1.55 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.