The package is clearly documented, tested, licensed, and has a small dependency footprint. Its workflows use unpinned actions and the repository lacks a security policy, so pin this exact version and watch for maintenance.
58%
Total Score
67
100
81
75
Only one registry maintainer is listed. Because the repository is user-owned rather than organization-owned, this leaves a relatively thin publishing base.
Only one release exists, and the package has been published for about 162 days. The limited history provides little evidence of sustained maintenance.
There were no commits and no active maintainers in the last three months, despite the package being about 162 days old. This is the strongest evidence of uncertain ongoing maintenance.
The repository uses Composer, but no security scanning tool was detected. That is a modest transparency and hygiene gap, not evidence that the package is unsafe.
No repository security policy was found. This weakens the project's disclosure and response transparency, although it is not by itself a dependency blocker.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nikic/php-parser Version ^4.18|^5.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.