Public record
Software health reportschema 0.27.0 · metrics 2.3.1 · 2026-07-29 10:48 UTC

infinum / eightshift-coding-standards

Eightshift coding standards for WordPress

PHPMIT★ 17 stars⑂ 3 forkssince Jul 2017View on GitHub ↗

infinum/eightshift-coding-standards holds a health index of 63 out of 100, placing it in the Moderate band. It scores highest on Sustainability & Governance (70/100) and lowest on AI Readiness (29/100). It was last updated today. A single contributor accounts for most of its recent work.

63
overall / 100
Moderate

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean, calibrated against the distribution of the public record so bands carry percentile meaning; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At Risk ceiling of 34.

63
Exceptional93-100The record's top tier (≈ top 5%); essentially all checked criteria met
Excellent80-92Strong across the board; minor gaps
Good65-79Healthy; gaps are limited and manageable
Moderate50-64Acceptable with notable gaps; review recommended
Weak35-49Material weaknesses across several areas
At Risk20-34Significant weaknesses; adoption warrants caution
Critical1-19Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

The weighted overall 59 is calibrated to 63 on the published index scale (record calibration 2026-08-02).

Ownership

InfinumOrganization
193 followers226 public repossince Jun 2009

This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publishTags
Packagistinfinum/eightshift-coding-standards4.0.22,0433862 days agowordpressstandardsphpcseightshift

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

66Good · 21% of overall
How it's scored
36/36Push recency — last push 0 days ago
4.8/36Commit cadence — 7/52 weeks with commits
11.1/18Commit volume — 16 commits in the last year
2/10OpenSSF Scorecard: Maintained — 3 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 2
Inputs used
commits_last_year16
human_commit_share1
days_since_last_push0
active_weeks_last_year7
How it's scored
27/27Ships releases — 38 releases published
36/36Release recency — latest release 62 days ago
12.6/27Release cadence — a release every ~170.3 days
0/10OpenSSF Scorecard: Signed-Releases — no data
Inputs used
releases_count38
latest_release_tag4.0.2
releases_from_tagsno
days_since_latest_release62
mean_days_between_releases170.3
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

54Moderate · 17% of overall
How it's scored
19.5/60Stars — 17 stars
2.5/25Forks — 3 forks
3.3/15Watchers — 5 watchers
Inputs used
forks3
stars17
watchers5
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

Community health

92Excellent
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (MIT)
18/18CONTRIBUTING guide
13.5/13.5Code of conduct
0/7.2Issue template
6.3/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
readme_badges
has_contributingyes
has_issue_templateno
has_code_of_conductyes
readme_badge_services
has_pull_request_templateyes
How it's scored
44.1/80Monthly downloads — 2,043 downloads/month across packagist
3.2/20Registry dependents — 2 packages depend on it
Inputs used
packagesinfinum/eightshift-coding-standards
dependents2
ecosystemspackagist
total_downloads92,715
monthly_downloads2,043

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

70Good · 23% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
2.5/22.5Commit distribution — top contributor authored 89% of commits
9.5/13.5Contributor breadth — 7 contributors
10/10OpenSSF Scorecard: Contributors — project has 9 contributing companies or organizations
Inputs used
bus_factor1
contributors_sampled7
top_contributor_share0.888
How it's scored
42/42Issue resolution — 100% of issues closed
26.3/30PR acceptance — 36/41 decided PRs merged
0/13Newcomer PR acceptance — no first-time contributor's PR decided in 30d
12/15OpenSSF Scorecard: Code-Review — Found 8/9 approved changesets -- score normalized to 8
Inputs used
merged_prs36
open_issues0
closed_issues28
prs_merged_7d
prs_decided_7d
prs_merged_30d
prs_decided_30d
issue_closed_ratio1
closed_unmerged_prs5
first_time_authors_30d
first_time_prs_merged_30d
first_time_prs_decided_30d
Excluded from scoring (no data or not applicable): newcomer_pr_acceptance. Remaining weights renormalized.
How it's scored
30/30Ownership backing — organization-owned
0/20Verified domain
16.4/25Owner reach — 193 followers of infinum
25/25Track record — 226 public repos, account ~17 yr old
Inputs used
followers193
owner_typeOrganization
is_verified
owner_logininfinum
public_repos226
account_age_days6,246

Package maintenance

100Exceptional
How it's scored
25/25Published & resolvable — 1 package(s) on packagist
35/35Publish recency — latest publish 62 days ago
20/20Version history — 38 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packagesinfinum/eightshift-coding-standards
ecosystemspackagist
any_deprecatedno
min_days_since_publish62

Engineering Quality

Are baseline engineering and documentation practices in place?

58Moderate · 19% of overall
How it's scored
24/24CI workflows — 1 workflow(s)
24/24Tests present
0/16Linter config
0/9.6Pre-commit hooks
0/6.4.editorconfig
6/20OpenSSF Scorecard: CI-Tests — 3 out of 9 merged PRs checked by a CI test -- score normalized to 3
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configno
has_precommit_configno
How it's scored
30/30README
0/25Documentation directory
15/15Documentation / homepage site — https://eightshift.com
10/10Repository description
10/10Topics — 4 topics
0/10Wiki
Inputs used
topicseightshift, wordpress, phpcs-linter, open-source
has_wikino
homepagehttps://eightshift.com
has_readmeyes
has_docs_dirno
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

50Moderate · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
3.8/7.5Branch-Protection — branch protection is not maximal on development and all release branches
0.8/2.5CI-Tests — 3 out of 9 merged PRs checked by a CI test -- score normalized to 3
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
6/7.5Code-Review — Found 8/9 approved changesets -- score normalized to 8
2.5/2.5Contributors — project has 9 contributing companies or organizations
0/10Dangerous-Workflow — no data
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
1.5/7.5Maintained — 3 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 2
0/5Packaging — no data
0/5Pinned-Dependencies — no data
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — no data
0/7.5Token-Permissions — no data
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated13
scorecard_versionv5.5.0
checks_inconclusive5
scorecard_aggregate4.6
Excluded from scoring (no data or not applicable): dangerous_workflow, packaging, pinned_dependencies, signed_releases, token_permissions. Remaining weights renormalized.
How it's scored
10.9/35Direct dependencies free of known advisories — 1 affected: wp-coding-standards/wpcs 3.3.0 (high 8.6)
0/25Indirect dependencies free of known advisories — transitive set not separable from development and test dependencies in this scope
40/40No advisories left outstanding — no advisory has been public longer than 90 days
Inputs used
sourceosv
advisories1
affected_packages1
assessed_packages2
unassessed_packages10
affected_by_severityhigh 1
direct_affected_packages1
Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories. Remaining weights renormalized. Matched 2 resolved dependencies against OSV. 10 could not be assessed — no resolved version, an unsupported ecosystem, or beyond the reported package list. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight (4%): agent tooling is a real maintenance signal, but a repository with none can still reach 100/100.

29At Risk · 4% of overall
How it's scored
0/45Agent instructions — no CLAUDE.md / AGENTS.md / editor rules
0/15Machine-readable docs (llms.txt)
20.3/40Legible commit history — 38 of 100 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share0.38
agent_instruction_files
agent_instruction_max_bytes
How it's scored
0/18One-command bootstrap
22/22Automated tests
0/11Lint / format config
0/11Static type checking
0/10Reproducible environment
2/10Demonstrated agent practice — 1 of the last 100 commits agent-authored or agent-credited
0/8Automated maintenance — no automated dependency updates observed
0/10OpenSSF Scorecard: Pinned-Dependencies — no data
Inputs used
has_nixno
has_testsyes
lockfiles
has_dockerfileno
typed_languageno
bootstrap_files
has_devcontainerno
has_linter_configno
typecheck_configs
agent_commit_share0.01
toolchain_manifests
dependency_bot_commit_share0
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Pinned-Dependencies. Remaining weights renormalized.
How it's scored
0/45Type-checkable code — PHP without a type-check config
55/55Manageable file sizes — 0/8 source files over 60KB
Inputs used
primary_languagePHP
largest_source_bytes9,183
source_files_sampled8
oversized_source_files0

Key facts

17GitHub stars
7contributors
16commits, last 12 months
0days since last push
38releases
1bus factor
0open issues
npm, Packagistpackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

More detail

Star and fork history 0 ★ / 3 ⇿
0Stars
3Forks
14Releases

When each star and fork was added, collected from GitHub and bucketed by day. Cumulative growth sits directly above the daily additions it is made of, so the two read against each other: steady organic accretion looks nothing like an abrupt, short-lived burst. Where that difference is measurable, it is reported as growth authenticity.

12233312020-052023-042026-03
Major 2Minor 5Patch 5

Each point covers 6 days.

OpenSSF Scorecard 4.6 / 10
4.6aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-29 10:48 UTC

10Binary-Artifactsno binaries found in the repo
5Branch-Protectionbranch protection is not maximal on development and all release branches
3CI-Tests3 out of 9 merged PRs checked by a CI test -- score normalized to 3
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
8Code-ReviewFound 8/9 approved changesets -- score normalized to 8
10Contributorsproject has 9 contributing companies or organizations
n/aDangerous-Workflowno workflows found
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
2Maintained3 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 2
n/aPackagingpackaging workflow not detected
n/aPinned-Dependenciesno dependencies found
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
n/aSigned-Releasesno releases found
n/aToken-PermissionsNo tokens found
10Vulnerabilities0 existing vulnerabilities detected
Direct dependencies 2
RegistryPackageVersion constraintManifest
Packagistwp-coding-standards/wpcs3.3.0composer.json
Packagistslevomat/coding-standard^8.22.1composer.json
All dependencies 12

Full resolved dependency set from the GitHub dependency graph: 2 direct and 10 indirect (transitive) packages. The transitive closure is complete when the repository commits a lockfile.

RegistryPackageVersionRelation
Packagistslevomat/coding-standarddirect
Packagistwp-coding-standards/wpcs3.3.0direct
npmhusky^9.1.7indirect
npmlint-staged^16.4.0indirect
Packagistphpindirect
Packagistphpcompatibility/phpcompatibility-wpindirect
Packagistphpcsstandards/phpcsdevtoolsindirect
Packagistphpstan/phpstan-deprecation-rulesindirect
Packagistphpunit/phpunitindirect
Packagistrector/rectorindirect
Packagistroave/security-advisoriesindirect
Packagistszepeviktor/phpstan-wordpress2.0.3indirect
Dependency advisories 1

This repository publishes no package the index resolves, so its own dependency graph was assessed — 2 packages, which also include development and test pins that never ship: 1 carry known advisories, of which 1 are direct. 10 could not be assessed — no resolved version, an unsupported ecosystem, or beyond the reported package list.

PackageVersionRelationSeverityAdvisoriesFixed in
wp-coding-standards/wpcs3.3.0directhigh13.4.1

An advisory means the version recorded in the dependency graph falls inside an advisory’s affected range. Reachability is not analysed, and the graph includes development and test pins — a finding may concern tooling rather than shipped software.

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [
        "eightshift",
        "wordpress",
        "phpcs-linter",
        "open-source"
      ],
      "is_fork": false,
      "size_kb": 438,
      "has_wiki": false,
      "homepage": "https://eightshift.com",
      "languages": {
        "PHP": 71979
      },
      "pushed_at": "2026-07-29T10:37:28Z",
      "created_at": "2017-07-05T10:33:29Z",
      "owner_type": "Organization",
      "updated_at": "2026-05-27T13:58:08Z",
      "description": "Eightshift coding standards for WordPress",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "PHP",
      "significant_languages": [
        "PHP"
      ]
    },
    "owner": {
      "blog": "https://infinum.com",
      "name": "Infinum",
      "type": "Organization",
      "login": "infinum",
      "company": null,
      "location": "New York, NY",
      "followers": 193,
      "avatar_url": "https://avatars.githubusercontent.com/u/97652?v=4",
      "created_at": "2009-06-21T23:57:40Z",
      "is_verified": null,
      "public_repos": 226,
      "account_age_days": 6246
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "4.0.2",
          "kind": "patch",
          "published_at": "2026-05-27T13:58:24Z"
        },
        {
          "tag": "4.0.1",
          "kind": "patch",
          "published_at": "2026-05-26T08:43:12Z"
        },
        {
          "tag": "4.0.0",
          "kind": "major",
          "published_at": "2026-05-25T13:25:34Z"
        },
        {
          "tag": "3.1.0",
          "kind": "minor",
          "published_at": "2026-04-08T08:29:38Z"
        },
        {
          "tag": "3.0.1",
          "kind": "patch",
          "published_at": "2026-02-26T08:50:47Z"
        },
        {
          "tag": "3.0.0",
          "kind": "major",
          "published_at": "2024-05-20T07:32:05Z"
        },
        {
          "tag": "2.0.0-beta",
          "kind": "prerelease",
          "published_at": "2023-09-22T13:45:15Z"
        },
        {
          "tag": "1.6.0",
          "kind": "minor",
          "published_at": "2022-07-05T14:22:39Z"
        },
        {
          "tag": "1.5.1",
          "kind": "patch",
          "published_at": "2022-05-10T12:15:43Z"
        },
        {
          "tag": "1.5.0",
          "kind": "minor",
          "published_at": "2022-03-16T16:16:40Z"
        },
        {
          "tag": "1.4.2",
          "kind": "patch",
          "published_at": "2022-03-10T12:02:07Z"
        },
        {
          "tag": "1.4.1",
          "kind": "patch",
          "published_at": "2022-03-10T11:39:42Z"
        },
        {
          "tag": "1.4.0",
          "kind": "minor",
          "published_at": "2022-03-09T11:09:50Z"
        },
        {
          "tag": "1.3.0",
          "kind": "minor",
          "published_at": "2021-05-04T15:41:07Z"
        },
        {
          "tag": "1.2.0",
          "kind": "minor",
          "published_at": "2021-04-15T15:42:47Z"
        },
        {
          "tag": "1.1",
          "kind": "other",
          "published_at": "2020-11-30T09:27:55Z"
        },
        {
          "tag": "1.0.1",
          "kind": "patch",
          "published_at": "2020-09-24T17:02:02Z"
        },
        {
          "tag": "1.0.0",
          "kind": "major",
          "published_at": "2020-09-18T12:07:04Z"
        },
        {
          "tag": "0.4.3",
          "kind": "patch",
          "published_at": "2020-01-29T07:05:34Z"
        },
        {
          "tag": "0.4.2",
          "kind": "patch",
          "published_at": "2020-01-24T14:28:34Z"
        },
        {
          "tag": "0.4.1",
          "kind": "patch",
          "published_at": "2018-11-15T12:51:18Z"
        },
        {
          "tag": "0.4.0",
          "kind": "minor",
          "published_at": "2018-10-24T14:12:07Z"
        },
        {
          "tag": "0.3.1",
          "kind": "patch",
          "published_at": "2018-07-27T15:43:23Z"
        },
        {
          "tag": "0.3.0",
          "kind": "minor",
          "published_at": "2018-07-26T14:33:15Z"
        },
        {
          "tag": "0.2.8",
          "kind": "patch",
          "published_at": "2018-06-21T07:45:43Z"
        },
        {
          "tag": "0.2.7",
          "kind": "patch",
          "published_at": "2018-02-20T12:38:10Z"
        },
        {
          "tag": "0.2.6",
          "kind": "patch",
          "published_at": "2017-10-28T09:26:44Z"
        },
        {
          "tag": "0.2.5",
          "kind": "patch",
          "published_at": "2017-10-28T08:56:25Z"
        },
        {
          "tag": "0.2.4",
          "kind": "patch",
          "published_at": "2017-10-28T07:53:59Z"
        },
        {
          "tag": "0.2.3",
          "kind": "patch",
          "published_at": "2017-09-19T07:41:12Z"
        },
        {
          "tag": "0.2.2",
          "kind": "patch",
          "published_at": "2017-07-25T13:53:53Z"
        },
        {
          "tag": "0.2.1",
          "kind": "patch",
          "published_at": "2017-07-18T13:48:37Z"
        },
        {
          "tag": "0.2.0",
          "kind": "minor",
          "published_at": "2017-07-14T09:43:18Z"
        },
        {
          "tag": "0.1.4",
          "kind": "patch",
          "published_at": "2017-07-14T08:55:24Z"
        },
        {
          "tag": "0.1.3",
          "kind": "patch",
          "published_at": "2017-07-14T08:32:06Z"
        },
        {
          "tag": "0.1.2",
          "kind": "patch",
          "published_at": "2017-07-14T07:41:14Z"
        },
        {
          "tag": "0.1.1",
          "kind": "patch",
          "published_at": "2017-07-14T06:17:53Z"
        },
        {
          "tag": "0.1.0",
          "kind": "minor",
          "published_at": "2017-07-07T14:50:58Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "cda006e26b93002647e4a86341a3f36b5c864033",
          "body": null,
          "is_bot": false,
          "headline": "Release 4.0.2: remove prettier, expand tooling scope (#69)",
          "author_name": "Ivan Ružević",
          "author_login": "iruzevic",
          "committed_at": "2026-05-27T13:57:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2a7d85269e661b1e314aad69a7f8ec29dbae1c4e",
          "body": "* updates",
          "is_bot": false,
          "headline": "updates (#68)",
          "author_name": "Ivan Ružević",
          "author_login": "iruzevic",
          "committed_at": "2026-05-26T08:42:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f89e17e9f69d1c59b224077475091c6dbfa2f234",
          "body": "* docs(plans): add PHP 8.3 minimum bump plan and follow-ups\n\n* build: require PHP >= 8.3\n\n* config(ruleset): bump PHPCompatibility testVersion to 8.3-\n\n* config(sample): bump PHPCompatibility testVersion to 8.3-\n\n* ci: target PHP 8.3 and 8.4, pin setup-php to v2.37.1\n\nDrops PHP 7.4-8.2 from the matr\n[…]\ninter\n\n* updating linter\n\n* updating linter\n\n* updating linter\n\n* updating linter\n\n* updating linter\n\n* updating linter\n\n---------\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat!: require PHP >= 8.4 (4.0.0) (#67)",
          "author_name": "Ivan Ružević",
          "author_login": "iruzevic",
          "committed_at": "2026-05-25T13:24:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "61100763a98362dfb73d23fdb1fc353aee123d24",
          "body": "3.1.0",
          "is_bot": false,
          "headline": "Merge pull request #65 from infinum/release/3.1.0",
          "author_name": "Ivan Ramljak",
          "author_login": "piqusy",
          "committed_at": "2026-04-08T08:28:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1cfb2491442ab3a9724d28990229f202718936d7",
          "body": "…niversal.ControlStructures.DisallowAlternativeSyntax\n\n- Remove custom DisallowAlternativeSyntaxSniff and its unit tests and docs\n- Enable Universal.ControlStructures.DisallowAlternativeSyntax from PHPCSExtra\n  (already a transitive dependency via WPCS, no new composer requirement)\n- Set allowWithInlineHTML=false for strict enforcement matching previous behavior\n- PHPCSExtra sniff adds auto-fixer, metrics, per-structure error codes, and docs",
          "is_bot": false,
          "headline": "refactor(ControlStructures): replace custom sniff with PHPCSExtra's U…",
          "author_name": "Ivan Ramljak",
          "author_login": "piqusy",
          "committed_at": "2026-04-08T07:45:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9f6c7d179fcd779aa4bab6b5a563ed119c05fc37",
          "body": null,
          "is_bot": false,
          "headline": "update(changelog): add 3.1.0 entry for PHPCS repo and schema URL update",
          "author_name": "Ivan Ramljak",
          "author_login": "piqusy",
          "committed_at": "2026-04-08T07:18:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5bf7c5df57b9c8b434d2d92c0d613e35436f2cc4",
          "body": "Update PHP_CodeSniffer repository link and schema URL",
          "is_bot": false,
          "headline": "Merge pull request #63 from rodrigoprimo/docs/update-phpcs-repo-link",
          "author_name": "Ivan Ramljak",
          "author_login": "piqusy",
          "committed_at": "2026-04-08T07:09:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7f5aa85120320ed188eb1889dc0d76609a143e1a",
          "body": "Disallow alternative control structure syntax",
          "is_bot": false,
          "headline": "Merge pull request #64 from infinum/feat/control-structures",
          "author_name": "Ivan Ramljak",
          "author_login": "piqusy",
          "committed_at": "2026-04-08T06:42:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d6e70c63e85d84e9deffb3c5bf23df129e68cb4a",
          "body": null,
          "is_bot": false,
          "headline": "fix: update 3.1.0 CHANGELOG with HelpersEscape test rename",
          "author_name": "Ivan Ramljak",
          "author_login": "piqusy",
          "committed_at": "2026-04-07T21:18:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f3fed60b84056ce7c799eab4f1fce1ec4412cef2",
          "body": "…h sniff name",
          "is_bot": false,
          "headline": "fix(Security): rename ComponentsEscape tests to HelpersEscape to matc…",
          "author_name": "Ivan Ramljak",
          "author_login": "piqusy",
          "committed_at": "2026-04-07T21:18:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9b0783f60a99f0b58202865b41cc17a4060c64d7",
          "body": null,
          "is_bot": false,
          "headline": "feat: prepare 3.1.0 release",
          "author_name": "Ivan Ramljak",
          "author_login": "piqusy",
          "committed_at": "2026-04-07T21:08:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "78649e10b1fa4cfb94d99c43a6503015251458a8",
          "body": null,
          "is_bot": false,
          "headline": "refactor: add PHP_CodeSniffer AllSniffs test to PHPUnit suite",
          "author_name": "Ivan Ramljak",
          "author_login": "piqusy",
          "committed_at": "2026-04-07T21:04:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "db7493b4741f28d519e3998e17c86c30b9254283",
          "body": null,
          "is_bot": false,
          "headline": "feat(ControlStructures): add sniff to disallow alternative syntax",
          "author_name": "Ivan Ramljak",
          "author_login": "piqusy",
          "committed_at": "2026-04-07T21:04:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9fe189aae813c37e8facc2dd9f6c868459d0fa92",
          "body": null,
          "is_bot": false,
          "headline": "Update PHP_CodeSniffer repository link and schema URL",
          "author_name": "Rodrigo Primo",
          "author_login": "rodrigoprimo",
          "committed_at": "2026-03-27T14:40:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "47c15871c65c0fe9c739676a93dbc481ac250821",
          "body": "Update PHPUnit",
          "is_bot": false,
          "headline": "Merge pull request #62 from infinum/feature/update-phpunit",
          "author_name": "Igor Obradović",
          "author_login": "iobrado",
          "committed_at": "2026-02-26T08:49:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c70ff6715ae8c7f3ab46cbfbb5950f5faafc4523",
          "body": null,
          "is_bot": false,
          "headline": "Update PHPUnit",
          "author_name": "Igor Obradović",
          "author_login": "iobrado",
          "committed_at": "2026-02-23T12:32:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aaceba336d7effefcbf6c29a3525d2b859ab0a6f",
          "body": "* initial setup",
          "is_bot": false,
          "headline": "Changes for Components helper (#60)",
          "author_name": "Ivan Ružević",
          "author_login": "iruzevic",
          "committed_at": "2024-05-20T07:30:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "57719e1c758e48129b5fd03a88859b7f4afa2dd9",
          "body": "Update wpcs 3.0.0",
          "is_bot": false,
          "headline": "Merge pull request #58 from dingo-d/update-wpcs-3.0.0",
          "author_name": "Goran Alković",
          "author_login": "goranalkovic-infinum",
          "committed_at": "2023-09-22T13:43:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "859cebba1775dbcd0ad1e7eb75edb2f7f955ea7c",
          "body": null,
          "is_bot": false,
          "headline": "Update checkout action to v4",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2023-09-15T09:57:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3cf15ac3dc6188055a9f8d772c0e63748216aba8",
          "body": null,
          "is_bot": false,
          "headline": "Update readme and changelog",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2023-09-14T13:43:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c1ae0d0b49debb2d37d09bf0fdb455a1a4eacf92",
          "body": null,
          "is_bot": false,
          "headline": "Update bootstrap to work with phpstan",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2023-09-14T13:43:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9efcd8f67aac14256d7fbd62fe37285f8d6722ab",
          "body": null,
          "is_bot": false,
          "headline": "Fix the wrong config name for the minimum wp version",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2023-09-14T13:43:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fd8a3142db0841b25c0dbdcc28433aaabfe4b1b9",
          "body": null,
          "is_bot": false,
          "headline": "Fix the test case with overriden class",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2023-09-14T13:43:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "907c072e74957be89d8b5acdcb8ebe3feb2241ee",
          "body": null,
          "is_bot": false,
          "headline": "Fix the ruleset check",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2023-09-14T13:43:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3429acf5bfd987b60d5d0a12139ff9aeeabbc9bf",
          "body": null,
          "is_bot": false,
          "headline": "Update phpdocs, add phpstan config, remove old workflows",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2023-09-14T13:42:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "94bb713dc7ba635c4410db4edd90a57e7663f881",
          "body": null,
          "is_bot": false,
          "headline": "Remove old CI workflows and replace with just one",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2023-09-14T13:41:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "834bf77c0fa021d7d245fbfbb4650f92030e3ecc",
          "body": null,
          "is_bot": false,
          "headline": "Update phpstan config",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2023-09-14T13:41:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c73711ba48d2102025c5d7f99d557a3761d3edd9",
          "body": null,
          "is_bot": false,
          "headline": "pdate phpcs and phpunit configs",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2023-09-14T13:41:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "645c3ddc8a0a4e01450961eb743da1edf7fcc1e1",
          "body": null,
          "is_bot": false,
          "headline": "Add phpstan config",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2023-09-14T13:41:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b1d7dfdc58de308c2c6703f8b8dea2e129837bcc",
          "body": "PHP8 compabitbility",
          "is_bot": false,
          "headline": "Add bootstrap file",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2023-09-14T13:41:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e003a61be7c20ffb389b06148b7bab48f2b9cdbe",
          "body": null,
          "is_bot": false,
          "headline": "Update docs",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2023-09-14T13:41:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "52609c90dce743c6bfdcdeab95474a7bcac3599a",
          "body": "The inside of a 'bad' static method won't get checked, because we only stop at the method name. What is inside is not important if the method itself is not safe.",
          "is_bot": false,
          "headline": "Fix the tests",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2023-09-14T13:41:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "98f951decf2fe5f1bd9a48d8711481e41ae7dcb4",
          "body": null,
          "is_bot": false,
          "headline": "Update the tokens, and fix the phpcs issues in the sniff",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2023-09-14T13:41:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a07bcf53b9e648d2a33815c95195acdc8c7961b8",
          "body": null,
          "is_bot": false,
          "headline": "Replaced removed methods from the WPCS 3.0.0 with dedicated helpers",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2023-09-14T13:41:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "663d2f6fd41c9879c3750cc8715dd0390013189e",
          "body": "Still need to test this out. Also the sniff throws errors due to an upstream bug, this needs to be addressed first.",
          "is_bot": false,
          "headline": "Add a public property so that the allowed methods can be extended",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2023-09-14T13:41:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "814a458e8d635802b3582519439284022f12e43b",
          "body": "Raised the minimum WP version to 6.0, replaced outdated and deprecated sniffs.",
          "is_bot": false,
          "headline": "Update ruleset",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2023-09-14T13:41:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d2194e5db49f0b60ef38a75d32123a64e2a7a63a",
          "body": null,
          "is_bot": false,
          "headline": "Minor coverage improvements in phpunit config",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2023-09-14T13:41:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9f29db75b7db3b050655e9b4cbd4346d1b714d75",
          "body": "This will be bumped to 3.1.0 once the fix of the upstream sniff is merged.\nRemove autoload dev part from the composer.json - conflicted with phpstan,\nand didn't do anything else for the standard.",
          "is_bot": false,
          "headline": "Update composer.json file",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2023-09-14T13:39:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "37b38f86f8c23b242f3ba62a73596b05b638e311",
          "body": null,
          "is_bot": false,
          "headline": "Update issue templates",
          "author_name": "Ivan Ružević",
          "author_login": "iruzevic",
          "committed_at": "2023-08-11T10:45:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7d3cfd043abd6f1f7d8d5a170733792628285d0b",
          "body": null,
          "is_bot": false,
          "headline": "updating issue template",
          "author_name": "Ivan Ružević",
          "author_login": "iruzevic",
          "committed_at": "2023-08-11T10:40:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c9c6f99a7df8b69f39cd0aadbb4aa047cb56f6fc",
          "body": null,
          "is_bot": false,
          "headline": "updating docs link",
          "author_name": "Ivan Ružević",
          "author_login": "iruzevic",
          "committed_at": "2022-09-30T09:39:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9441a91fe334258886a443e2236f6f07b1f5c17d",
          "body": "Add new parameter to the function comment sniff",
          "is_bot": false,
          "headline": "Merge pull request #54 from infinum/update-comment-sniff",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-07-05T14:21:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d8d32ab92941a550f68cddc2390e16ab3e1e86b1",
          "body": null,
          "is_bot": false,
          "headline": "Add new parameter to the function comment sniff",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-07-05T14:15:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e205370734c752756911e413bc923a5934a94d2c",
          "body": "Update changelog",
          "is_bot": false,
          "headline": "Merge pull request #52 from infinum/ci-cd-fixes",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-05-10T12:14:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cca2658bc586d7ae3f8b7e057f84aa9c99ae12d0",
          "body": null,
          "is_bot": false,
          "headline": "Update changelog",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-05-10T12:13:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e72745a97b1380936c215049763ba85a1dda92fb",
          "body": "Fix issues in the sniff and ruleset",
          "is_bot": false,
          "headline": "Merge pull request #51 from infinum/ci-cd-fixes",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-05-10T12:11:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2a55ed075261471be981066005880f12bd6f580b",
          "body": null,
          "is_bot": false,
          "headline": "Fix issues in the sniff and ruleset",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-05-10T12:08:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b982008295ddb3063bb997c65b843d1bb9bcaf03",
          "body": null,
          "is_bot": false,
          "headline": "Update bug_report.yml",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-05-10T10:12:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "44dde4214d712e195f33fc783325bea117c6022f",
          "body": null,
          "is_bot": false,
          "headline": "Update feature_request.yml",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-05-10T10:12:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bbed2b247660647eb12745ef6cacc0784347931d",
          "body": "Fix edgecase security sniff",
          "is_bot": false,
          "headline": "Merge pull request #50 from infinum/fix-edgecase-security-sniff",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-16T16:16:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9c785725ea5bebfa9e81ac708b9ed83bf5f63555",
          "body": null,
          "is_bot": false,
          "headline": "Update Changelog",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-16T16:06:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "17cf08e721449bc7b9f89ffad06c1a074132a1e9",
          "body": null,
          "is_bot": false,
          "headline": "Update ruleset",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-16T16:06:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ef5a6b76fbf1c2198205cabc848d4423c48e8210",
          "body": null,
          "is_bot": false,
          "headline": "Update changelog",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-16T16:03:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "925d9c82b998f8019e935a6fe9e8c8a9b8cc0bb7",
          "body": null,
          "is_bot": false,
          "headline": "Add additional test case",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-16T16:03:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e7ace168a689ae2692b3032d2703d1fec62d7cb3",
          "body": null,
          "is_bot": false,
          "headline": "Fix the edge case when Components class is overridden",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-16T16:03:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cf7a49aeff1d442b07af253ff90a57b302d2b6e4",
          "body": "Exclude original commenting sniff",
          "is_bot": false,
          "headline": "Merge pull request #49 from infinum/exclude-original-commenting-sniff",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-10T12:01:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0fd6f24f46b9a704a1715aeced82e35accf390ee",
          "body": null,
          "is_bot": false,
          "headline": "Update changelog",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-10T12:00:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9b27cd08ea1c45d6ba42d17796ad58dddd10a2e3",
          "body": null,
          "is_bot": false,
          "headline": "Update the ruleset to exclude the WP native escape sniff",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-10T11:59:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8ade500fa7b36fa4dc516bc495a1a7b960b8c18c",
          "body": "Phpcbf bugfix",
          "is_bot": false,
          "headline": "Merge pull request #48 from infinum/phpcbf-bugfix",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-10T11:39:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "32598512fccd21d2599cb43fe595079cd155898c",
          "body": null,
          "is_bot": false,
          "headline": "Update changelog",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-10T11:35:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b33692767e8e3479e5161feca08d27d44bf011e5",
          "body": "The wrapper code exposed another issue with the components sniff, this commit fixes it.",
          "is_bot": false,
          "headline": "Add additional guard clause check",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-10T11:32:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e851ec53b1e8eeb4e832d44c3aea5b696a948dbf",
          "body": "Covers a breaking edge case",
          "is_bot": false,
          "headline": "Add additional test case",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-10T11:29:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aa1a503e8f409c3f83cc0d6157266225ea17cf4a",
          "body": "Workshop session fixes",
          "is_bot": false,
          "headline": "Merge pull request #47",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-09T11:07:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0aceb1e0b26abcff754ed50828c31d012c0cf72c",
          "body": null,
          "is_bot": false,
          "headline": "Update release date",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-09T11:05:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ac8cf4eec6b9469e4d5b71730eb511d2909fb1c3",
          "body": "We only want to filter the Components string (or FQCN)",
          "is_bot": false,
          "headline": "Add a fix for when the next token after echo is not a string token",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-08T09:46:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "be71422a20d12e8de282200f096e48636fcf3fe8",
          "body": null,
          "is_bot": false,
          "headline": "Update changelog date",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-08T07:49:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "48f4652f46c474108626511c5566ee72a3187770",
          "body": null,
          "is_bot": false,
          "headline": "Update the .gitattributes",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-07T21:39:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "150d9d78afcb79d28580ec691efbb5e20d6daa31",
          "body": "Added issue templates, PR templates, code of conduct and security report instructions.",
          "is_bot": false,
          "headline": "Add commmunity standards features",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-07T21:36:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d03435d8140535a06328b034b5c543d2ec0bae7b",
          "body": null,
          "is_bot": false,
          "headline": "Update the tab to 4 spaces instead of 2",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-07T21:34:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c7721011d8db7862f3df45b5eee75ccaf41f9781",
          "body": null,
          "is_bot": false,
          "headline": "Update the readme",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-07T21:32:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9ca1682a93ca7642decf6da8114e5a050753e00d",
          "body": null,
          "is_bot": false,
          "headline": "Update the changelog",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-07T21:31:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b83051db29f3d076019e7dcfb5461a8f4d6a6215",
          "body": null,
          "is_bot": false,
          "headline": "Comment fix",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-07T20:26:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0909954164971a36bda56234ea19cd5d62af19bb",
          "body": "Slevomat requires phpcs v3.6.0, so we cannot test against 3.5.0. Plus the composer requirements are set to at least 3.6.0, so it's ok to remove this test.",
          "is_bot": false,
          "headline": "Workflow update",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-07T20:26:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "142f2169cf02a17a8938d0153284bf8811be7111",
          "body": null,
          "is_bot": false,
          "headline": "Fix ruleset violations in the test files",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-07T20:26:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2ce86b5ae8dc8ea9fb73be5e924b2a91312a1de1",
          "body": "…file\n\nFix for indefinite hanging of the sniff processing.",
          "is_bot": false,
          "headline": "Add the fix for the case where we don't have Components class in the …",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-07T20:26:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bb35473dcb287eb1e5f07901557d9160c4de5760",
          "body": "Added case that caused the sniff to hang indefinitely where there are no Components classes in the file any more. In that case we want to continue with the regular sniff.",
          "is_bot": false,
          "headline": "Update test cases",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-07T20:26:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1bda9b1599b7ec1df01aafd841a6dae01efe7f22",
          "body": null,
          "is_bot": false,
          "headline": "Fix phpcs issues in the sniff",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-07T20:26:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1d6b65a0148e3924c382528dd6543aff81e12811",
          "body": null,
          "is_bot": false,
          "headline": "Fix the components escape sniff",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-07T20:26:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "72a5b5e0e92b5ff3c09e1882a47884dbd6643360",
          "body": "There is one caveat to the test cases, I'm not sure if this is a bug in the sniff, or phpcs or what.\n\nWhen I put the following code as the test case:\n\necho (new Components())->render( // Bad\n\t'accordion',\n\tComponents::props('accordion', $attributes, [\n\t\t'accordionContent' => $innerBlockContent\n\t])\n)\n[…]\nops call. The same construct is not reported when it's used when\nComponents::render call is echoed out.\n\nSo this odd test case was written with just an array instead.\nThis should be reported upstream.",
          "is_bot": false,
          "headline": "Update the test cases",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-07T20:26:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "456d4bce8622c3fa5a546ead4927902765051f2d",
          "body": "It picks up on certain static methods that it shouldn't and has a memory leak that I need to identify (tests crash)",
          "is_bot": false,
          "headline": "Rewrite the sniff for components methods",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-07T20:26:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c1fb85136f8ea752ee97361c28eb698d3cbdbf5e",
          "body": null,
          "is_bot": false,
          "headline": "Add additional test cases",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-07T20:26:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "78f6e3b2067f678be7be683854198e5d2680023b",
          "body": null,
          "is_bot": false,
          "headline": "Update packages",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-07T20:26:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a9ab839b5166e021aaeaffdd33c4c96423980ea8",
          "body": null,
          "is_bot": false,
          "headline": "Fix the typo in the commenting sniff",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-07T20:26:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "088c4c147e2bc490825ffbe1cf47073be463e89f",
          "body": null,
          "is_bot": false,
          "headline": "Add documentation for the security sniff",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-07T20:26:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a4afe02a7e800e3d54c9f0cd1a8c988a97266482",
          "body": null,
          "is_bot": false,
          "headline": "Fix phpcs issues in the component escape sniff and test",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-07T20:26:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f1da08ae1c8915c81d52121fc32c9b67ab0b2b18",
          "body": null,
          "is_bot": false,
          "headline": "Update coding standards to exclude sniffing test cases",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-07T20:26:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2025e30dfe81bba50215bbe576330931ff9138bd",
          "body": null,
          "is_bot": false,
          "headline": "Update test to account for the multiple test cases",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-07T20:25:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6a83ca66759838a7243baf054e4a4f1e77165be6",
          "body": null,
          "is_bot": false,
          "headline": "Bump PHP version and tab width in the ruleset",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-07T20:25:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0d74bb5420916183435772c0a897696be6b60956",
          "body": null,
          "is_bot": false,
          "headline": "Rename test",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-07T20:25:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9f79d1b10261df1aeba2261ef9bac2a7c70ea9f2",
          "body": "Ruleset checks are examples of code that should fail, so that's expected. It shouldn't be checked on the CI because it will always fail a build.",
          "is_bot": false,
          "headline": "Exclude the Ruleset checks so that the CI passes",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-07T20:25:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "59c9880fa814927e73c450509e72c9c5550ab00f",
          "body": "Add concurrency check to save resources.",
          "is_bot": false,
          "headline": "Update the GH actions",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-07T20:25:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "423ea2f4c51bc3a3e2747c8bfa7bed09c3ef029c",
          "body": "Update composer install action to v2",
          "is_bot": false,
          "headline": "Workflow update",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-07T20:25:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b3e2c430338035938e4dd0148d06489f65807730",
          "body": null,
          "is_bot": false,
          "headline": "Add the function commenting documentation",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-07T20:25:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "adc2eaf63bde9821577548cb4963e1e8dbfd9992",
          "body": "The sniff is updated so that it extends the WPCS Sniff class. This class has two super useful helpers: is_token_namespaced and is_class_object_call. They allow super quick checks for namespaced functions and static functions named do_shortcode which would otherwise trigger a false positive result.",
          "is_bot": false,
          "headline": "Update the disallow do_shortcode sniff",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-07T20:25:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cf7a11cb59b10429d8d468b8b676debb26155c98",
          "body": null,
          "is_bot": false,
          "headline": "Update composer to add the allow-plugins",
          "author_name": "Denis Žoljom",
          "author_login": "dingo-d",
          "committed_at": "2022-03-07T20:25:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "929644f0452f04b7f46e3d5006c40e6632ebadf2",
          "body": "This sniff overloads the `Squiz.Commenting.FunctionComment` sniff which normally comes included via the `WordPress-Docs` ruleset and makes an allowance for the __invoke method in the CLI classes.\n\nIncludes:\n* Unit tests.\n* Adjusting the ruleset to maintain the same excludes as WPCS had from the `Squiz` ruleset.\n* Adjusting the ruleset to maintain the previous exclude for parameter alignment.",
          "is_bot": false,
          "headline": "Add new EightShift FunctionComment sniff",
          "author_name": "jrfnl",
          "author_login": "jrfnl",
          "committed_at": "2022-03-07T20:25:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fc49bae0841659eb11b9d917b2a0910fcdb1ecf0",
          "body": null,
          "is_bot": false,
          "headline": "DisallowDoShortcodeUnitTest: add @covers tag",
          "author_name": "jrfnl",
          "author_login": "jrfnl",
          "committed_at": "2022-03-07T20:25:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "076121d24316053b64b0d2db6adac1b3c56d0f59",
          "body": "... as it already is a dependency of both PHPCSExtra as well as SlevomatCodingStandards, so we'll inherit it anyway.",
          "is_bot": false,
          "headline": "Composer: remove the Composer PHPCS plugin dependency",
          "author_name": "jrfnl",
          "author_login": "jrfnl",
          "committed_at": "2022-03-07T20:25:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "55ebaab3d698f781c391e826b467bca30dac3ac3",
          "body": "... for improved compatibility with PHP 8.1.\n\nRef: https://github.com/php-parallel-lint/PHP-Parallel-Lint/releases",
          "is_bot": false,
          "headline": "Composer: update the PHP Parallel Lint version constraint",
          "author_name": "jrfnl",
          "author_login": "jrfnl",
          "committed_at": "2022-03-07T20:25:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "54e6c5a8459e8713d0116e8d1610745f0505bd0a",
          "body": "This commit:\n* Adds a new dependency on the Slevomat Coding Standard library.\n* Adds four sniffs from this coding standard to the ruleset:\n    1. Forbidding unused `use` statements.\n    2. Enforcing fully qualified global functions and constants.\n    3. Enforcing import `use` statements for everything else.\n\nIncludes fixing up the EightShift coding standards code base for these new rules.\n\nRef: https://github.com/slevomat/coding-standard",
          "is_bot": false,
          "headline": "EightShift ruleset: add rules for use statements",
          "author_name": "jrfnl",
          "author_login": "jrfnl",
          "committed_at": "2022-03-07T20:24:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 38,
      "commits_last_year": 16,
      "latest_release_at": "2026-05-27T13:58:24Z",
      "latest_release_tag": "4.0.2",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 7,
      "days_since_latest_release": 62,
      "mean_days_between_releases": 170.3
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 87,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "infinum/eightshift-coding-standards",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "wordpress",
            "standards",
            "phpcs",
            "Eightshift"
          ],
          "ecosystem": "packagist",
          "matches_repo": true,
          "registry_url": "https://packagist.org/packages/infinum/eightshift-coding-standards",
          "is_deprecated": false,
          "latest_version": "4.0.2",
          "repository_url": "https://github.com/infinum/eightshift-coding-standards",
          "versions_count": 38,
          "total_downloads": 92715,
          "dependents_count": 2,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 2043,
          "first_published_at": null,
          "latest_published_at": "2026-05-27T13:57:27Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 62
        }
      ]
    },
    "popularity": {
      "forks": 3,
      "stars": 17,
      "watchers": 5,
      "fork_history": {
        "days": [
          {
            "date": "2020-05-20",
            "count": 1
          },
          {
            "date": "2023-08-22",
            "count": 1
          },
          {
            "date": "2026-03-27",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 3,
        "total_forks": 3
      },
      "star_history": null,
      "open_issues_and_prs": 1
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [],
      "largest_source_bytes": 9183,
      "source_files_sampled": 8,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "composer.json",
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [
          {
            "name": "wp-coding-standards/wpcs",
            "direct": true,
            "version": "3.3.0",
            "severity": "high",
            "ecosystem": "packagist",
            "cvss_score": 8.6,
            "advisory_ids": [
              "GHSA-3pwp-g2mj-5p3v"
            ],
            "fixed_version": "3.4.1",
            "advisory_count": 1,
            "oldest_advisory_days": 0
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "high": 1
        },
        "advisory_count": 1,
        "affected_count": 1,
        "assessed_count": 2,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 10,
        "direct_affected_count": 1
      },
      "ecosystems": [
        "npm",
        "packagist"
      ],
      "dependencies": [
        {
          "name": "wp-coding-standards/wpcs",
          "manifest": "composer.json",
          "ecosystem": "packagist",
          "version_constraint": "3.3.0"
        },
        {
          "name": "slevomat/coding-standard",
          "manifest": "composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^8.22.1"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "slevomat/coding-standard",
            "direct": true,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "wp-coding-standards/wpcs",
            "direct": true,
            "version": "3.3.0",
            "ecosystem": "packagist"
          },
          {
            "name": "husky",
            "direct": false,
            "version": "^9.1.7",
            "ecosystem": "npm"
          },
          {
            "name": "lint-staged",
            "direct": false,
            "version": "^16.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "php",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "phpcompatibility/phpcompatibility-wp",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "phpcsstandards/phpcsdevtools",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "phpstan/phpstan-deprecation-rules",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "phpunit/phpunit",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "rector/rector",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "roave/security-advisories",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "szepeviktor/phpstan-wordpress",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "packagist"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 12,
        "direct_count": 2,
        "indirect_count": 10
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 1,
        "merged_prs": 36,
        "open_issues": 0,
        "closed_ratio": 1,
        "closed_issues": 28,
        "closed_unmerged_prs": 5
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "dingo-d",
          "commits": 239,
          "avatar_url": "https://avatars.githubusercontent.com/u/8638515?v=4"
        },
        {
          "type": "User",
          "login": "piqusy",
          "commits": 10,
          "avatar_url": "https://avatars.githubusercontent.com/u/22823970?v=4"
        },
        {
          "type": "User",
          "login": "jrfnl",
          "commits": 8,
          "avatar_url": "https://avatars.githubusercontent.com/u/663378?v=4"
        },
        {
          "type": "User",
          "login": "iruzevic",
          "commits": 8,
          "avatar_url": "https://avatars.githubusercontent.com/u/23283324?v=4"
        },
        {
          "type": "User",
          "login": "iobrado",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/23059501?v=4"
        },
        {
          "type": "User",
          "login": "goranalkovic-infinum",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/77000136?v=4"
        },
        {
          "type": "User",
          "login": "rodrigoprimo",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/77215?v=4"
        }
      ],
      "contributors_sampled": 7,
      "top_contributor_share": 0.888
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 5,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 3,
            "reason": "3 out of 9 merged PRs checked by a CI test -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 8,
            "reason": "Found 8/9 approved changesets -- score normalized to 8",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 9 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": null,
            "reason": "no workflows found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 2,
            "reason": "3 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 2",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": null,
            "reason": "no dependencies found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": null,
            "reason": "No tokens found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "cda006e26b93002647e4a86341a3f36b5c864033",
        "ran_at": "2026-07-29T10:48:29Z",
        "aggregate_score": 4.6,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-05-27T13:58:37Z",
      "oldest_open_prs": [
        {
          "number": 70,
          "created_at": "2026-07-29T10:39:01Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-05-27T13:57:27Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/infinum/eightshift-coding-standards",
    "host": "github.com",
    "name": "eightshift-coding-standards",
    "owner": "infinum"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": "The weighted overall 59 is calibrated to 63 on the published index scale (record calibration 2026-08-02).",
      "notes": [
        {
          "code": "overall_calibration",
          "params": {
            "raw": 59,
            "calibrated": 63,
            "calibration": "2026-08-02"
          }
        }
      ],
      "value": 63,
      "inputs": {
        "security": 50,
        "vitality": 66,
        "community": 54,
        "governance": 70,
        "calibration": "2026-08-02",
        "engineering": 58,
        "ai_readiness": 29,
        "weighted_overall_raw": 59
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 66,
        "weight": 0.21,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 54,
            "inputs": {
              "commits_last_year": 16,
              "human_commit_share": 1,
              "days_since_last_push": 0,
              "active_weeks_last_year": 7
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "7/52 weeks with commits",
                "points": 4.8,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 7
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "16 commits in the last year",
                "points": 11.1,
                "status": "partial",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 16
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "3 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 2",
                "points": 2,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 84,
            "inputs": {
              "releases_count": 38,
              "latest_release_tag": "4.0.2",
              "releases_from_tags": false,
              "days_since_latest_release": 62,
              "mean_days_between_releases": 170.3
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "38 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 38
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 62 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 62
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~170.3 days",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 170.3
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "exceptional",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 67,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 67 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 67
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 54,
        "weight": 0.17,
        "metrics": [
          {
            "key": "popularity",
            "band": "at_risk",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 25,
            "inputs": {
              "forks": 3,
              "stars": 17,
              "watchers": 5,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "17 stars",
                "points": 19.5,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 17
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "3 forks",
                "points": 2.5,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "5 watchers",
                "points": 3.3,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "readme_badges": null,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "readme_badge_services": [],
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "weak",
            "name": "Ecosystem adoption (downloads)",
            "note": null,
            "notes": [],
            "value": 47,
            "inputs": {
              "packages": [
                "infinum/eightshift-coding-standards"
              ],
              "dependents": 2,
              "ecosystems": "packagist",
              "total_downloads": 92715,
              "monthly_downloads": 2043
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "2,043 downloads/month across packagist",
                "points": 44.1,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 2043,
                      "ecosystems": "packagist"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "2 packages depend on it",
                "points": 3.2,
                "status": "partial",
                "details": [
                  {
                    "code": "registry_dependents",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "good",
        "name": "Sustainability & Governance",
        "value": 70,
        "weight": 0.23,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "at_risk",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 31,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 7,
              "top_contributor_share": 0.888
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 89% of commits",
                "points": 2.5,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 89
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "7 contributors",
                "points": 9.5,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 9 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "excellent",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Newcomer PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "newcomer_pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 92,
            "inputs": {
              "merged_prs": 36,
              "open_issues": 0,
              "closed_issues": 28,
              "prs_merged_7d": null,
              "prs_decided_7d": null,
              "prs_merged_30d": null,
              "prs_decided_30d": null,
              "issue_closed_ratio": 1,
              "closed_unmerged_prs": 5,
              "first_time_authors_30d": null,
              "first_time_prs_merged_30d": null,
              "first_time_prs_decided_30d": null
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "100% of issues closed",
                "points": 42,
                "status": "met",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 42
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "36/41 decided PRs merged",
                "points": 26.3,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 36,
                      "decided": 41
                    }
                  }
                ],
                "max_points": 30
              },
              {
                "key": "newcomer_pr_acceptance",
                "name": "Newcomer PR acceptance",
                "detail": "no first-time contributor's PR decided in 30d",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_newcomer_prs",
                    "params": {
                      "days": 30
                    }
                  }
                ],
                "max_points": 13
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 8/9 approved changesets -- score normalized to 8",
                "points": 12,
                "status": "partial",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "good",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 71,
            "inputs": {
              "followers": 193,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "infinum",
              "public_repos": 226,
              "account_age_days": 6246
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "193 followers of infinum",
                "points": 16.4,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 193,
                      "login": "infinum"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "226 public repos, account ~17 yr old",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 226
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 17
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "exceptional",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "infinum/eightshift-coding-standards"
              ],
              "ecosystems": "packagist",
              "any_deprecated": false,
              "min_days_since_publish": 62
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on packagist",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "packagist"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 62 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 62
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "38 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 38
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 58,
        "weight": 0.19,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 54,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "1 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "3 out of 9 merged PRs checked by a CI test -- score normalized to 3",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 65,
            "inputs": {
              "topics": [
                "eightshift",
                "wordpress",
                "phpcs-linter",
                "open-source"
              ],
              "has_wiki": false,
              "homepage": "https://eightshift.com",
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://eightshift.com",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "4 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 50,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "weak",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Dangerous-Workflow, Packaging, Pinned-Dependencies, Signed-Releases, Token-Permissions. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "dangerous_workflow",
                    "packaging",
                    "pinned_dependencies",
                    "signed_releases",
                    "token_permissions"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 46,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 13,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 5,
              "scorecard_aggregate": 4.6
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 3.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "3 out of 9 merged PRs checked by a CI test -- score normalized to 3",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 8/9 approved changesets -- score normalized to 8",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 9 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no workflows found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "3 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 2",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "no dependencies found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "No tokens found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "good",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories. Remaining weights renormalized. Matched 2 resolved dependencies against OSV; 10 could not be assessed (no resolved version, an unsupported ecosystem, or beyond the reported package list). This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 2
                }
              },
              {
                "code": "advisories_unassessed",
                "params": {
                  "count": 10
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 68,
            "inputs": {
              "source": "osv",
              "advisories": 1,
              "affected_packages": 1,
              "assessed_packages": 2,
              "unassessed_packages": 10,
              "affected_by_severity": "high 1",
              "direct_affected_packages": 1
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "1 affected: wp-coding-standards/wpcs 3.3.0 (high 8.6)",
                "points": 10.9,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 1,
                      "packages": "wp-coding-standards/wpcs 3.3.0 (high 8.6)"
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory has been public longer than 90 days",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "advisories_none_stale",
                    "params": {
                      "days": 90
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "exceptional",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 2,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "exceptional",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "commit_weight_rule": {
                "min_commits": 50,
                "min_commit_share": 0.1
              },
              "review_only_matches": 0,
              "below_threshold_exposures": [],
              "assessed_self_published_locations": 9
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "at_risk",
        "name": "AI Readiness",
        "value": 29,
        "weight": 0.04,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 20,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.38,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "38 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 20.3,
                "status": "partial",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 38,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "at_risk",
            "name": "Verify loop (build / test / typecheck)",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Pinned-Dependencies. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_pinned_dependencies"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 27,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [],
              "has_dockerfile": false,
              "typed_language": false,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0.01,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "1 of the last 100 commits agent-authored or agent-credited",
                "points": 2,
                "status": "partial",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 1,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "no dependencies found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "moderate",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 55,
            "inputs": {
              "primary_language": "PHP",
              "largest_source_bytes": 9183,
              "source_files_sampled": 8,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "PHP without a type-check config",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_typecheck_config_language",
                    "params": {
                      "language": "PHP"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/8 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 8,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight: agent tooling is a real maintenance signal, but its absence must never gate the top of the scale (calibration saturates at raw 91, so 100/100 remains reachable with AI Readiness at zero)."
      }
    ],
    "classification": {
      "labels": [
        "library"
      ],
      "scores": {
        "library": 6
      },
      "primary": "library",
      "evidence": [
        {
          "tier": "distribution",
          "label": "library",
          "source": "registry:packagist",
          "weight": 6
        }
      ],
      "artifacts": [],
      "confidence": "medium",
      "host_extension": false,
      "runs_as_process": false,
      "consumed_by_code": true
    },
    "metrics_version": "2.3.1"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-29T10:48:47.231626Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/i/infinum/eightshift-coding-standards.svg",
  "full_name": "infinum/eightshift-coding-standards",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v2.3.1, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsPackagist.