The package is well documented, tested, licensed, and has no install-time scripts. However, all 13 releases arrived on one day and the repository has had no commits in three months, while security scanning and a security policy are absent.
60%
Total Score
63
100
89
50
One registry publishing account is present. Because the repository is user-owned rather than organization-backed, this leaves a relatively thin publishing base, though it does not by itself show abandonment.
All 13 releases were published on the same day, with a median interval of 0 days, so the release history shows little evidence of sustained maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, a concrete sign that maintenance may have slowed or stopped.
There were no new or merged pull requests and no issue activity in the last month. With open issue count unknown, this is limited evidence of inactivity rather than proof of abandonment.
The project uses Make and Composer, but no security-scanning tools were detected, leaving a modest transparency and maintenance-hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/finder Version ^4|^5|^6|^7 | — | — |
nikic/php-parser Version ^4|^5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.