Clear documentation and a lightweight dependency set make integration straightforward. Recent commits, two active contributors, tested release notes, and a non-archived repository indicate ongoing maintenance; workflow permissions and the missing security policy are minor gaps.
86%
Total Score
90
100
100
67
One registry publisher account is a modest concentration risk, but repository activity shows two active contributors, partly compensating for the narrow publishing base.
The repository has no published security policy, leaving vulnerability reporting guidance less transparent for users and maintainers.
The only workflow lacks top-level token permissions, so its effective permission scope is less explicit than recommended, though no top-level write permission was detected.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nikic/php-parser Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.