Recent releases and a maintained source repository support continued use. However, the repository recorded no commits or active maintainers in the last three months, and its workflow uses 15 unpinned actions without security scanning or a security policy.
68%
Total Score
50
100
94
75
The repository is owned by a user account rather than an organization, so the three registry maintainers provide some publishing capacity but not strong institutional backing. This modestly limits confidence in long-term continuity.
The repository recorded zero commits and zero active maintainers during the last three months. This is a meaningful maintenance warning, though the recent release and September push show the project is not clearly abandoned.
The project uses Composer and Make, but no security-scanning tools were detected. For a small PHPStan extension this is a hygiene gap rather than evidence of immediate unfitness.
The repository has no security policy. That weakens vulnerability-reporting transparency, but it is a moderate governance gap rather than a standalone dependency risk.
The single workflow was fully analyzed with no untrusted checkouts, script injections, or audit findings, but all 15 action references are unpinned. The missing top-level permissions block is acceptable on its own; unpinned actions remain a supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpstan/phpstan Version ^2.1.37 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.