The package is clearly licensed, includes tests, and has a matching organization-owned repository. Its single release and zero recent commits leave too little evidence of sustained maintenance; pin it and reassess future releases.
67%
Total Score
75
100
88
75
This package was first released 0 days ago and has only one release, so there is no track record for maintenance or release reliability yet. Its newness limits confidence but does not by itself show abandonment.
The repository reports zero commits and zero active maintainers in the last 3 months. Because the repository is brand new, this is partly explained by its age, but it still provides no evidence of sustained maintenance.
Composer build tooling is present, but no security scanning tools were detected. This is a modest supply-chain hygiene gap rather than evidence that the package is unsafe.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
slevomat/coding-standard Version 8.31.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.