The package includes a clear MIT license, a substantial README, tests, and a changelog. Its single maintainer, minimal repository activity, absent security policy, and unpinned workflow actions leave limited evidence of ongoing care.
58%
Total Score
50
86
67
Only one account has registry publishing access, leaving a thin publishing base. This is not proof of poor maintenance, but there is no organizational backing signal to compensate for it.
The latest release was published in November 2023, with no releases in the last 12 months and only three releases overall. This is meaningful maintenance caution for a dependency, though the package is not deprecated.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and raising abandonment risk.
The repository has zero stars and forks and one watcher, so there is little visible community adoption or review activity. Popularity is supporting evidence rather than a verdict, but it provides no compensating assurance here.
The linked repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version 6.3.8 | — | — |
nikic/php-parser Version 4.17.1 | — | — |
aminnairi/string-extra Version 0.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.