No commits have landed in the past three months, and the README calls the project beta. It has clear documentation and MIT licensing, but one person publishes it and no security policy is present.
58%
Total Score
50
86
50
Only one registry publishing account is listed. That is a modest bus-factor concern for a young package, with no organizational backing shown by the provided ownership data.
There have been only 3 releases, all clustered within minutes on the first release day, leaving little evidence of a sustained release cadence.
The repository recorded 0 commits and 0 active maintainers in the past three months, despite the package being only about five months old; this weakens confidence in ongoing maintenance.
The linked repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
Version v0.1.2 is an early 0.x release, and the package README explicitly describes the project as usable but beta, so behavior and support may still change.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpstan/phpstan Version ^2.1 | — | — |
symfony/console Version ^8.0 | — | — |
helgesverre/toon Version ^1.0 || ^3.1 | — | — |
nikic/php-parser Version ^5.7 | — | — |
ineersa/call-graph Version ^0.1.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.