The metapackage has a clear purpose, a matching organizational repository, a license, and no install-time scripts. Its single implementation dependency is explicit, but the project has little operational history to establish long-term maintenance.
70%
Total Score
75
100
88
75
The package is brand new: it has only 2 releases, both within minutes, and no established release cadence. This limits maturity evidence but does not by itself indicate abandonment for a newly published package.
There were 0 commits and 0 active maintainers in the last 3 months. Because the package is only 0 days old, this is primarily a lack of maintenance history rather than evidence of a collapsed project, but it lowers confidence.
The repository uses Composer, appropriate for this package, but no security scanning tool was detected. This is a modest transparency and hygiene gap rather than a severe risk.
The repository has no security policy. For a small type-definition metapackage this is a limited governance gap, but it provides no documented vulnerability-reporting path.
No GitHub Actions workflows were present, so there are no audited workflow risks or pinned-action evidence. For this small metapackage, the absence of automation is a minor maturity gap rather than a supply-chain danger.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/squizlabs-php_codesniffer-impl Version ~4.0.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.