Package Health

vix/phpstan-rules

The project includes tests, a clear README, MIT licensing, and automated security scanning. Maintenance has gone quiet for about three months, while all 10 workflow actions are unpinned and the release workflow has a low-confidence cache warning.

Latest v0.1.2PackagistPackagist

65%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Project backingcaution

The repository is owned by an individual account rather than an organization, so the single registry maintainer provides limited visible backing for continuity.

Release historycaution

This is a young package, about 123 days old, with three releases and a median interval of about 3 days. Its latest release was about four months before collection, so the short history limits maturity evidence.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months. Although it was pushed about three months ago and the package is young, this is meaningful evidence of currently quiet maintenance.

Repo popularitycaution

The repository has zero stars, forks, and watchers. Low popularity is supporting context rather than a health verdict, especially for a young specialist package.

Security policycaution

No security policy was found, which weakens vulnerability-reporting transparency. The repository's Dependabot configuration partly compensates by providing automated dependency scanning.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Anton Vix

Direct Dependencies

DependencyLast ReleaseScore
phpstan/phpstan
Version ^2.1.54
nikic/php-parser
Version ^5.7

Weekly Downloads

Info

Last Published
4 months ago
Created
4 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform