A clear README, tests, MIT license, and a matching source repository support adoption. The package has a small maintainer base and no security scanning, so ongoing oversight is limited.
68%
Total Score
75
100
94
83
Only one registry account has publish access, leaving a thin publishing base and increasing continuity risk if that maintainer becomes unavailable.
The repository recorded zero commits and zero active maintainers in the last three months, a meaningful sign of currently weak maintenance momentum despite recent releases.
Composer build tooling is present, but no security scanning tools were detected, leaving security-process coverage limited.
The repository has no security policy, reducing transparency about how consumers should report vulnerabilities and how issues are handled.
Both workflows were analyzed cleanly with no injection or high-confidence audit findings, but all four action references are unpinned, so workflow inputs can change without a repository change.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
giann/trunk Version ^1.5.1 | — | — |
nikic/php-parser Version ^4.19.1 || ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.