Its focused artifact is documented, licensed under MIT, and backed by a matching repository with recent release notes. Maintenance is narrow, with one active contributor, no security policy, and two unpinned workflow actions.
72%
Total Score
67
100
67
One contributor made all commits in the last three months. Organization ownership provides some handoff capacity, but no second recently active contributor is shown.
Only one commit was recorded in the last three months, so ongoing maintenance activity is limited even though it includes the current release.
The repository has no security policy. For a small configuration package this is a transparency gap, though it does not by itself indicate abandonment.
The complete audit found no dangerous triggers, untrusted checkouts, script injection, or high-severity findings. However, both analyzed action references are unpinned, leaving workflow dependencies less reproducible.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
larastan/larastan Version ^3.10 | — | — |
phpstan/phpstan-mockery Version ^2.0 | — | — |
ekino/phpstan-banned-code Version ^3.0 | — | — |
phpstan/phpstan-deprecation-rules Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.