A PHP parser written in PHP
78%
Total Score
healthy
Healthy, with recent maintenance and a clear, licensed package; workflow pinning and security documentation are the main gaps.
The registry namespace and repository are owned by the same individual account, so the package has clear ownership linkage. It does not provide organizational backing to offset maintainer concentration.
Three contributors were active in the last three months, but the leading contributor made 75% of commits. The presence of two additional active contributors partly offsets the concentration, leaving only a mild resilience concern.
The project uses Make and Composer for builds, which supports repeatable development. No security scanning tools were detected, leaving a modest security-process gap.
No repository security policy was detected. This does not show unsafe code, but it reduces transparency about vulnerability reporting and response.
Both workflows were analyzed successfully and had no untrusted checkouts, script injection, or high-severity findings. However, all 14 action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.