Its README clearly explains the metapackage layout and how consumers should install it, with a minimal dependency surface and no install-time scripts. Organization backing, matching repository metadata, and a declared Apache-2.0 license help offset the lack of security-policy and scanning evidence.
70%
Total Score
75
100
88
88
This package is newly published, with one release and no established release cadence; that leaves maintenance maturity unproven.
There were no commits or active maintainers in the last three months, but the repository was only just created; this is mainly an absence of historical evidence rather than demonstrated neglect.
Composer is used as the build tool, which fits the package ecosystem. No security-scanning tool is configured, leaving a modest transparency gap for supply-chain maintenance.
The repository has no security policy. For a tiny type-definition metapackage this is a hygiene gap, but it does not by itself indicate unsafe maintenance.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/phpstan-phpstan-phpunit-impl Version ~2.0.18.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.