This is a generally healthy, established package with more than seven years of release history, a stable major release, a current non-archived repository, repository tests, clear licensing, read-only CI permissions, Dependabot scanning, and no install-time lifecycle scripts. The main concerns are slow release cadence, no recorded commits or active maintainers in the last three months, low repository adoption, no security policy, and a single registry publisher, though the organization-owned repository, recent push, merged pull requests, and current release provide meaningful compensating evidence. It appears reasonable to depend on, with normal review of upstream activity recommended.
78%
Total Score
88
100
89
90
The package has existed since August 2019 with 14 releases, but only 2 releases in the last 12 months and a median interval of about 6.7 months indicate a slow cadence.
No commits and no active maintainers were recorded in the last three months, which raises a maintenance-continuity concern; the recent repository push and two merged pull requests partially compensate.
Four stars, zero forks, and one watcher indicate limited external adoption; this is supporting caution rather than a decisive health failure for a specialized extension.
No repository security policy was found, leaving vulnerability-reporting guidance less transparent for dependents.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpstan/phpstan Version ^2.0 | — | — |
nikic/php-parser Version ^4.13.2 || ^v5.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.