MIT licensing, tests, and a matching repository make the package transparent to inspect. The registry marks it abandoned, and its repository is archived with no recent commits or releases. Its workflow also uses 9 unpinned actions.
15%
Total Score
0
50
100
Packagist marks the entire package as abandoned, with no replacement specified. This is a direct warning against taking a new dependency on this release.
The package has had no releases in nearly five years, despite a historical median release interval of about 26 days. The long release gap supports the abandonment signals.
The repository recorded zero commits and zero active maintainers in the last three months. This confirms there is no current development activity.
The linked repository is archived and was last pushed in February 2022, so active maintenance is not expected. This strongly increases abandonment risk.
The single workflow was fully analyzed with no detected dangerous sinks or audit findings, but all 9 action references are unpinned. That is a modest reproducibility and update-integrity concern, not a severe risk on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpactor/container Version ^2.0.0 | — | — |
phpactor/text-document Version ^1.2.3 | — | — |
phpactor/language-server Version ^1.1.1 | — | — |
phpactor/console-extension Version ^0.1.6 | — | — |
phpactor/logging-extension Version ^0.3.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.