Clear documentation, MIT licensing, and a matching source repository make the package easy to inspect. The very small release history and prolonged inactivity leave maintenance uncertain, while no security policy adds a smaller transparency gap.
55%
Total Score
75
100
78
83
The package has had only three releases, with the latest published over two years ago and none in the last 12 months. This is a meaningful maintenance concern for a dependency, despite its initially regular release spacing.
There were no commits and no active maintainers in the last three months, consistent with the latest release being over two years ago. This materially increases the risk that compatibility or defects will not be addressed.
The repository has one star and no forks, indicating very limited adoption. Popularity is only supporting evidence, but this provides little external confidence to offset the maintenance concerns.
The repository uses Composer for its build but reports no security-scanning tools. The build tooling is appropriate, while the missing scanning adds a modest transparency and maintenance gap.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This is a smaller transparency concern rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
swisnl/bitbucket-reports Version ^0.1 | — | — |
friendsofphp/php-cs-fixer Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.