Clear documentation, tests, and release notes make the package easier to adopt. Recent commit activity is absent and workflow actions are not pinned, so ongoing maintenance and build reproducibility remain concerns.
72%
Total Score
50
100
81
50
The package has existed for about 14 years with 16 releases, but only one release in the last 12 months indicates a modest maintenance cadence.
The repository recorded no commits and no active maintainers during the past three months, weakening evidence of ongoing maintenance despite the recent release.
The project uses Make and Composer, but no security-scanning tooling was detected. This is a modest transparency and maintenance gap, not evidence of an unsafe package.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
Version 0.6.0 is a stable, non-prerelease release, although the pre-1.0 major version signals that compatibility expectations may be less mature.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/lexer Version ^1.2.1 || ^2 | — | — |
doctrine/collections Version ^1.6.5 | — | — |
symfony/polyfill-mbstring Version ^1.20.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.