The package is tiny, clearly licensed, and has no install-time scripts. Its release and commit activity has stopped, so future compatibility fixes may be slow.
61%
Total Score
63
100
83
83
One registry maintainer is consistent with an individually owned package. It limits the visible publishing base but does not by itself show abandonment.
The package has had five releases since March 2021, but none in the last 12 months and the latest was released nearly two years ago. This indicates a mature but inactive project.
There were no commits and no active maintainers in the last three months. For a small configuration package this may reflect stability, but it leaves little evidence of ongoing maintenance.
The repository has one open issue and no recent issue or pull-request activity. This is limited evidence of maintenance rather than a severe concern.
Composer is used for builds, but no security-scanning tools are reported. The missing scanning is a modest transparency gap for supply-chain maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spaze/phpstan-disallowed-calls Version ^4.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.