Its license is present, and the release includes tests, documentation, and release notes. Choose rector/rector instead, since this package is no longer maintained.
12%
Total Score
25
43
50
Packagist marks the entire package as abandoned and names rector/rector as its replacement. This is a direct warning against taking a new dependency on this package.
The latest registry release was published about 11 years ago, and there were no releases in the last 12 months. This strongly indicates abandonment despite earlier release activity.
The repository had no commits and no active maintainers in the last 3 months, consistent with its archived status and the package deprecation.
The source repository is archived, with its last push about 9 years ago. An archived project is no longer an actively maintained dependency.
The artifact and repository contain a license file, so the release is licensed, but the manifest declares Apache2 while the detected license is MIT. That mismatch reduces transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/finder Version ~2.4@stable | — | — |
beberlei/assert Version @stable | — | — |
symfony/console Version ~2.4@stable | — | — |
nikic/php-parser Version @stable | — | — |
tomphp/patch-builder Version ~0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.