The tested source tree and explicit AGPL-3.0-only license improve day-to-day confidence. A single maintainer and no commits in three months make ongoing support less certain, so pin this version carefully.
62%
Total Score
50
100
79
50
A post-update-cmd lifecycle script runs during dependency updates. This is a modest operational concern because package updates can execute project-defined commands, though it is not evidence of abandonment.
One registry maintainer is consistent with a small, individually owned project, but it leaves limited visible support capacity when combined with the lack of recent commit activity.
The package and repository include tests, and the repository uses GitHub Releases. The missing package README and changelog are minor transparency gaps for a small PHP library.
The package has four releases over about four years, with one release in the last 12 months and a median gap of about 18 months. This shows continued publishing but a slow cadence that raises maintenance uncertainty.
The repository recorded no commits and no active maintainers in the last three months, despite a release about 11 months earlier. That weakens evidence of active maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
dmitryrechkin/php-numberparser Version ^1.0 | — | — |
dmitryrechkin/php-namingconverter Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.