Usable with caveats: it is actively developed and well documented, with tests, a matching repository, and an organization behind it. The package is very new, all recent commits come from one contributor, and it lacks a security policy and automated security scanning.
68%
Total Score
83
100
88
90
The package is only 89 days old and has just two releases, with 89 days between them. This is limited evidence of long-term maintenance and release maturity.
All 236 recent commits came from one contributor, creating a meaningful continuity risk. Organization ownership partly compensates because maintenance can potentially be handed off, but no second active contributor is shown.
Composer build tooling is present, but no security-scanning tools were detected. This is a modest supply-chain hygiene gap rather than evidence of abandonment.
No repository security policy was found. That weakens vulnerability-reporting transparency for a package intended to process and generate executable PHP expressions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nikic/php-parser Version ^5.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.