The package has clear documentation, tests, licensing, and a matching maintained repository. Its recent release and commit activity are quiet, while workflow dependencies are not pinned, so ongoing maintenance and build reproducibility deserve attention.
70%
Total Score
67
100
81
75
The package has 11 releases over roughly 6 years, but no releases in the last 12 months despite the latest release being in May 2025. That indicates a slower maintenance cadence, though not abandonment by itself.
There were zero commits and zero active maintainers in the last three months. The January 2026 push and 2025 release provide some compensating evidence, but current development activity remains limited.
Only three issues are open and there are no open pull requests, but there was no issue or pull-request activity in the last month. This is a mild maintenance concern rather than a severe warning.
The project uses Composer and Box for its build, which supports structured packaging. No repository security-scanning tool was detected, leaving a modest transparency gap.
The repository has no security policy. This weakens vulnerability-reporting transparency, although it does not by itself indicate that the package is unsafe to depend on.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nikic/php-parser Version ^5.0 | — | — |
ulrichsg/getopt-php Version ^4.0 | — | — |
nikic/include-interceptor Version ^0.1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.