Package Health

nikic/php-parser

Healthy and suitable to depend on. It has a long release history, current stable releases, active work from seven contributors, and a well-matched repository; only modest repository security-hygiene gaps remain.

Latest v5.9.0PackagistPackagist

92%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Are you affected? Scan for Free

Health Score Breakdown

Repo toolingcaution

The repository uses Make and Composer for builds, but no security scanning tools were detected. The missing scanning is a modest transparency gap rather than a severe risk because other maintenance evidence is strong.

Security policycaution

No security policy was found in the repository, leaving vulnerability-reporting expectations less explicit. This is a genuine but limited transparency gap for an actively maintained library.

Token permissionscaution

The single workflow does not declare top-level token permissions. No write permissions were detected, but explicit least-privilege configuration would provide stronger CI security hygiene.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-862723 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
nikic/php-parser is vulnerable to Code Injection in versions 5.6.0 - 5.7.0.
5.6.0 - 5.7.0
Medium

Package versions

Maintainers

Nikita Popov

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
10 days ago
Created
14 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform