A clear README, tests, matching license, and no install-time scripts make adoption easier. The dependency set is substantial for a young package, while repository security documentation and scanning are absent.
62%
Total Score
50
88
83
The repository is owned by an individual account rather than an organization, so the concentrated recent activity is not offset by visible organizational backing.
The package is only 2 days old with 5 releases, so it shows active initial development but offers almost no long-term maintenance track record.
One contributor made 100% of the single recent commit, leaving no demonstrated contributor redundancy for this user-owned project.
Only 1 commit was recorded in the last 3 months, although the repository was updated recently; this is too little history to establish sustained maintenance.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
rector/rector Version ^2.0 | — | — |
symfony/finder Version ^7.0 || ^8.0 | — | — |
symfony/process Version ^7.0 || ^8.0 | — | — |
nikic/php-parser Version ^5.0 | — | — |
vlucas/phpdotenv Version ^5.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.