PHP Matcher enables you to match values with patterns
70%
Total Score
caution
Usable with caveats: maintenance has recently slowed and CI workflow hygiene needs attention.
Composer post-install and post-update scripts are present. They add installation-time behavior that consumers should understand, but this signal alone does not establish a health or abandonment problem.
No commits and no active maintainers were recorded in the last three months. Although the recent release and repository push provide some counterevidence, this is a real sign that maintenance activity has slowed.
The repository has no published security policy. This is a transparency gap for reporting vulnerabilities, though it does not by itself indicate abandonment.
All 14 analyzed action references are unpinned, and the audit found a high-confidence bot-conditions issue in the Dependabot auto-merge workflow. There are no untrusted checkouts or script-injection findings, limiting the severity to workflow hygiene concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/lexer Version ^3.0 | — | — |
aeon-php/calendar Version ^1.0.6 | — | — |
coduo/php-to-string Version ^3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.