Minimizes PHP opcodes without changing behavior: counts opcodes per function, applies Rector and LLM rewrites, verifies behavior on every step.
65%
Total Score
caution
A one-day-old 0.x package has one maintainer and a high-confidence workflow permission issue, despite strong documentation and active release work.
The release declares 11 runtime dependencies, including substantial analysis and transformation components, which adds integration and maintenance surface but is consistent with the package's tooling role.
The artifact includes MIT and BSD-3-Clause license texts while the manifest declares MIT, so the detected-license mismatch needs clarification. Both the artifact and repository contain license files.
Only one registry publishing maintainer is listed, and the repository is user-owned rather than organization-backed, leaving a thin apparent publishing and succession base.
The registry namespace and repository are owned by the same individual account, confirming ownership alignment but providing no organizational backing to offset the single-maintainer profile.
The package is only 1 day old with 3 releases and a median interval of about 23 hours, so its long-term maintenance record is not established.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^7.3 || ^8 | — | — |
internal/path Version ^1.4 | — | — |
psr/container Version 1 - 2 | — | — |
rector/rector Version ~2.7.0 | — | — |
symfony/console Version ^7.3 || ^8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.