Release notes, licensing, tests, and security documentation are present, but they do not offset the project's lack of ongoing ownership signals. The workflow audit also found a high-confidence condition-check problem and all actions are unpinned.
12%
Total Score
25
57
100
Packagist marks the entire package as abandoned, with no replacement listed. This is a direct warning against taking a new dependency on the package.
There have been no releases in nearly four years, despite 19 releases before that. The earlier cadence shows the project was once active but does not compensate for the prolonged release gap.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with abandonment rather than ongoing maintenance.
The source repository is archived and was last pushed in January 2023, so it is no longer an actively maintained home for the package.
Only one registry account has publish access. That is a limited publishing base for a user-owned project and increases continuity risk alongside the archived repository.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpro/grumphp Version ^1.13 | — | — |
rector/rector Version ^0.15 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.