The project has a small user base and no security policy. The latest release is documented, licensed, and tied to an organization-owned repository.
67%
Total Score
75
100
88
75
The package has existed for about 7 years with 21 releases, but only 1 release in the last 12 months; this suggests slower ongoing maintenance rather than abandonment.
The repository recorded 0 commits and 0 active maintainers in the last three months, which is a meaningful maintenance concern despite the November 2025 release.
The repository has only 3 stars and 2 forks, indicating limited adoption evidence. Popularity is supporting evidence, so this lowers confidence in maturity without being decisive.
The linked repository has no security policy, reducing transparency for reporting and handling security issues.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but all 3 action references are unpinned and the workflow has no top-level permissions block.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
squizlabs/php_codesniffer Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.