Usable with caveats: the package is actively published and has solid tests, licensing, CI, and repository hygiene. Adoption should account for only one release in the last 12 months, no recent commit activity, and the absence of a security policy.
72%
Total Score
67
100
89
90
The package and repository share the same user owner, so the source linkage is consistent; the user-owned project does not provide organizational redundancy.
The package has existed for about 2 years and 11 months with 10 releases, but only one release in the last 12 months indicates a slower current release cadence.
No commits and no active maintainers were recorded in the last three months, which weakens evidence of ongoing maintenance even though the repository was recently pushed and pull requests were merged.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
Version 0.4.0 is not a prerelease, but the package remains below a stable 1.0 major version, so its public API may still change materially.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/php-structure-discoverer Version ^1.2 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.