Package Health

vaclavvanik/coding-standard

This release appears usable and reasonably transparent, with an explicit BSD-3-Clause license, a matching repository, a documented README, no deprecation, no install-time lifecycle scripts, and a small dependency profile appropriate for a PHP coding-standard package. However, maintenance evidence is limited: the repository has had no commits in the last 3 months, has no tests or changelog, has no security scanning or security policy, and shows no community activity or popularity. The package is not archived and was recently pushed and released, which partially offsets the inactivity concern, but the single-maintainer, low-visibility project remains a meaningful long-term maintenance risk.

Latest 0.10.0PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Maintainerscaution

Only one registry publishing maintainer is listed. This is consistent with the individual-owned repository, but it creates limited publishing and maintenance redundancy.

Package scaffoldingcaution

A substantive README documents requirements, installation, configuration, and usage, but neither the artifact nor repository contains tests or a changelog. For a coding-standard ruleset this is a real verification and change-history gap, though the usage documentation is useful compensation.

Project backingcaution

The repository is owned by an individual user rather than an organization, so the single-maintainer concern is not offset by visible organizational backing.

Release historycaution

The package has existed for about 5 years with 10 releases and a release in the last 12 months, indicating some continuity, but the low recent release cadence provides only modest evidence of active maintenance.

Repo commit activitycaution

There were 0 commits and 0 active maintainers in the last 3 months. Although the recent push and release provide some compensating evidence, the current lack of observable development activity is a meaningful maintenance concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Václav Vaník

Direct Dependencies

DependencyLast ReleaseScore
slevomat/coding-standard
Version ^7.0.0
squizlabs/php_codesniffer
Version ^3.6.0
dealerdirect/phpcodesniffer-composer-installer
Version ^0.6.2 || ^0.7

Weekly Downloads

Info

Last Published
14 days ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform