The package includes tests, a README, an MIT license, and a non-archived repository. Its only release was over three years ago, with no recent commits, and the repository does not identify the package in its name or README.
45%
Total Score
0
75
50
This is the package's only release, published over three years ago, with no releases in the last 12 months. That is a substantial maintenance concern for a dependency.
The repository recorded no commits and no active maintainers in the last three months, consistent with the long gap since its only release. No provided signal shows renewed maintenance.
The package runs post-install and post-update scripts. These add installation complexity and warrant caution for dependency adoption, although the signal alone does not establish that the scripts are harmful.
The repository name does not match the package name and its README does not mention the package, which raises concern that the linked source may not clearly belong to this release.
The repository has no security policy, reducing the transparency of vulnerability reporting for a package that translates and executes parser-related build logic. This is a secondary concern because the package has a README and tests.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/finder Version ^5.4 | — | — |
symfony/console Version ^5.4 | — | — |
symfony/process Version ^5.4 | — | — |
nikic/php-parser Version ^4.13 | — | — |
symfony/event-dispatcher Version ^5.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.