The release is clearly documented through version notes, and the package is licensed with no install-time scripts. Recent pull-request activity supports continued maintenance despite the narrow contributor base.
79%
Total Score
67
100
75
One contributor made all recorded commits in the last three months, giving the project a narrow maintenance base under individual ownership.
Only one commit was recorded in the last three months, which is thin direct commit activity. The recent releases and 11 merged pull requests partly compensate for that gap.
The repository has no published security policy. This is a transparency gap, though it is less severe for a small static-analysis rules package.
The single workflow was fully analyzed with no injection or high-severity findings, and its one action reference is pinned. It grants top-level write permissions, a mild concern because no untrusted trigger or sink was detected.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpstan/phpstan Version ^2.2.14 | — | — |
staabm/phpstan-psr3 Version ^1.0.3 | — | — |
ergebnis/phpstan-rules Version ^2.13.1 | — | — |
shipmonk/phpstan-rules Version ^4.4.0 | — | — |
phpstan/phpstan-mockery Version ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.