Recent repository activity is absent, and every analyzed workflow dependency is unpinned. Clear licensing, release notes, organization backing, and a matching repository provide useful transparency.
65%
Total Score
75
93
50
The package has made no release in nearly two years despite 30 releases overall, indicating a meaningful maintenance concern for a dependency tied to evolving Rector versions.
There were no commits and no active maintainers in the last three months. The repository is not archived, but the recent activity gap still raises abandonment risk.
The repository has no security policy. This is a transparency gap, though the project does use Dependabot and the package is a small development-time configuration.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but all 4 of 4 action references are unpinned, leaving avoidable build-integrity risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
rector/rector Version 1.2.10 | — | — |
driftingly/rector-laravel Version 1.2.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.