The package includes tests, a clear Apache-2.0 license, and a repository owned by an organization. Its maintenance record is too short to establish dependable long-term support, so pinning this exact release is prudent.
62%
Total Score
75
100
83
83
This package was first released today and has only one release, so there is no track record for release continuity or maintenance maturity.
The repository records zero commits and zero active maintainers in the last three months; because the package is newly created, this is limited evidence rather than proof of abandonment, but support capacity is unproven.
The repository has zero stars, forks, and watchers. This is weak supporting evidence for maturity, although a newly created implementation repository would naturally have little audience.
Composer is used as the build tool, but no security-scanning tools were detected. The missing scanning is a hygiene gap, not evidence of unsafe code by itself.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented. This is a transparency gap, though the package's very short history limits how much weight it should carry.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
friendsofphp/php-cs-fixer Version 3.95.25 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.