The repository has no security policy or scanning, and its small single-owner footprint limits visible maintenance capacity. The MIT declaration, focused file tree, and detailed README provide useful transparency.
42%
Total Score
50
88
50
Only one registry publisher is listed, which leaves limited visible publishing redundancy. The repository is owned by the same individual, so the narrow maintainer base remains relevant rather than being explained by organizational backing.
The latest release was about three years ago, with no releases in the last 12 months. That prolonged release gap is a meaningful abandonment concern, although the package has 13 releases and is on a stable major version.
The repository recorded no commits and no active maintainers in the last three months, consistent with the long release gap and indicating little current maintenance capacity.
Composer build tooling is present, but no security-scanning tool was detected. This is a hygiene gap that adds concern alongside the lack of recent maintenance.
No security policy was found in the repository. For a library that processes application data, this weakens transparency around vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
didix16/php-grammar Version ^1.0 | — | — |
didix16/php-hydrator Version ^1.0 | — | — |
didix16/php-interpreter Version ^1.0 | — | — |
didix16/php-apidataobject Version >= 1.0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.