PHPStan rules: unnecessary named arguments, one mirrored coverage target per test, no class constants in tests
62%
Total Score
caution
A brand-new package has no established release or commit history, with all workflow actions left unpinned.
The package and repository are owned by the same individual account rather than an organization, so continuity depends on a single visible project owner.
This is the first release and the package is 0 days old, so there is no release track record or cadence yet. The repository was pushed shortly before publication, which partly reflects its newness rather than abandonment.
There were zero commits and zero active maintainers in the preceding 3 months, but the repository was created or updated immediately before this first release. This leaves maintenance capacity unproven rather than demonstrating long-term abandonment.
The repository uses Composer build tooling, but no security scanning tools were detected. The build setup is present, while security-process transparency is limited.
No repository security policy was found. This is a modest transparency gap for a new package, though it is not evidence of unsafe code by itself.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
phpstan/phpstan Version ^2.1.13 | — | — |
steevanb/php-collection Version ^6.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.