The workflow setup needs tightening, and there is no published security policy. Recent releases, repository tests, and release notes provide useful maintenance evidence, but ongoing support rests with one contributor.
72%
Total Score
67
94
50
A post-autoload-dump install script runs during Composer operations, increasing install-time behavior that consumers must trust, though the signal does not show a destructive or suspicious action.
The repository owner is a user account rather than an organization, so the single-contributor maintenance concentration is not visibly compensated by organizational backing.
One contributor made all 37 commits in the last 3 months, leaving maintenance highly dependent on a single person with no demonstrated handoff capacity.
No security policy was found in the repository, reducing transparency about how vulnerabilities should be reported and handled.
Version v0.4.0 is not a stable major release, but it is not a prerelease and recent versions have had no prerelease share, so this is a moderate maturity caveat rather than a severe concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
squizlabs/php_codesniffer Version ^4.0.1 | — | — |
dealerdirect/phpcodesniffer-composer-installer Version ^1.2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.