The MIT license, README, repository tests, and Composer security scanning support adoption. Unpinned workflow actions and all recent commits coming from one contributor leave build reproducibility and maintenance capacity as concerns.
67%
Total Score
67
86
75
The latest registry release was over two years ago, with no releases in the last 12 months; the repository was pushed recently, which partly offsets but does not remove the release-cadence concern.
One contributor made all two recent commits, concentrating current maintenance responsibility in a single person; organization backing provides some handoff capacity but does not eliminate the concern.
Two commits were recorded in the last three months, showing some current activity, but the volume is low relative to the long gap since the last registry release.
No security policy was found, leaving vulnerability-reporting guidance undocumented; this is a transparency gap rather than evidence that the package is unsafe.
Version 0.1.12 is not a stable major release, so compatibility expectations are lower even though it is not marked as a prerelease.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/process Version ^5.4|^6.0|^7.0 | — | — |
nikic/php-parser Version ^4.16|^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.