It has a stable major release, matching repository, and a clear license, but no commits in the last 3 months or security policy. The package is not archived and was recently released, yet its registry status makes adoption unsuitable.
20%
Total Score
75
81
88
Packagist marks the entire package as abandoned, with no replacement named. This is a severe adoption risk even though the assessed release is recent.
The repository recorded zero commits and zero active maintainers in the last 3 months. This indicates little current maintenance capacity, despite the recent release.
Composer is used for builds, but no security-scanning tools were detected. The missing scanning is a modest hygiene gap rather than a standalone adoption blocker.
The repository has no security policy. This reduces transparency for reporting and handling vulnerabilities, although it is secondary to the package-level abandonment status.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
rector/rector Version ^2.0 | — | — |
phpstan/phpstan Version ^2.1 | — | — |
larastan/larastan Version ^3.5 | — | — |
phpstan/phpstan-mockery Version ^2.0 | — | — |
symplify/easy-coding-standard Version ^12.4.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.