This release appears usable and reasonably established: it has been maintained since 2021, has 27 releases, a current stable version, a recent release, an unarchived organization-owned repository, and no install-time lifecycle scripts. The main risks are a very thin recent activity base—only 2 commits from 1 contributor in the last 3 months, with all recent commits attributed to one contributor—along with the absence of repository security scanning, a security policy, tests, and a changelog. The package is transparent enough for a code-quality tooling module because its README and source tree clearly expose its rules and scripts, but dependency adoption should account for its concentrated maintenance capacity.
74%
Total Score
75
83
90
The artifact and repository include a substantial README, but neither includes tests or a changelog. For a small tooling package, the clear usage documentation partly compensates for the missing tests, but the lack of both tests and changelog remains a maintenance-transparency gap.
All recent commits came from one contributor, whose commit share is 100%. Although the repository is organization-owned, the observed recent activity still shows concentrated individual maintenance and creates a continuity risk.
The repository recorded 2 commits in the last 3 months, with 1 active maintainer. This is ongoing but sparse activity, lowering confidence in sustained maintenance capacity.
The repository has 5 stars, 8 forks, and 12 watchers. This is limited visibility, but popularity is supporting evidence only and does not outweigh the maintenance signals.
The repository uses Composer and Make for build or project operations, which is appropriate for this PHP tooling package, but it reports no security-scanning tools. The build setup is positive while the missing scanning is a modest hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpmd/phpmd Version ^2 | — | — |
phpro/grumphp Version ^2.18 | — | — |
symfony/dom-crawler Version ^7 | — | — |
squizlabs/php_codesniffer Version ^3 | — | — |
magento/magento-coding-standard Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.