The repository has only one active contributor, no security policy, and both workflow actions are unpinned. A recent release, release notes, tests, and a matching documented repository provide useful maintenance and transparency evidence.
72%
Total Score
70
100
89
75
Two registry publishing accounts are listed, but this is administrative access rather than evidence of active maintenance, so it does not offset the concentrated repository activity.
The repository is owned by a GitHub user rather than an organization, so the single-contributor concentration is not compensated by visible organizational backing.
One contributor made all 10 commits in the last three months, creating a concentrated maintenance risk for a user-owned project with no organization backing.
The repository has only 2 stars and no forks or watchers. Popularity is supporting evidence rather than a verdict, but these counts provide little external validation.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest security-process gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nikic/php-parser Version ^5.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.