Healthy and suitable to depend on. It has a long release history, a current release, active contributions from four people, strong package and repository structure, and organizational backing; the main gaps are the missing security policy and undeclared workflow token permissions.
88%
Total Score
100
100
94
80
No security policy is present in the repository, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap, but it does not outweigh the package's active maintenance and organizational backing.
The one workflow does not declare top-level token permissions. Although no write permissions were explicitly observed, least-privilege intent is not documented, creating a modest CI security-hygiene concern.
Version 0.44.0 is not a stable-major release, so compatibility guarantees may be weaker than for a 1.x package. It is nevertheless a normal, non-prerelease version with no recent prerelease releases.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/finder Version ^3.0 || ^4.0 || ^5.0 || ^6.0 || ^7.0 | — | — |
phpstan/phpstan Version ^2.0 | — | — |
laminas/laminas-code Version ~3.3.0 || ~3.4.1 || ~3.5.1 || ^4.5 || ^4.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.