The repository has only two stars, no security policy, and no security scanning, limiting independent review. The MIT license, release notes, README, and non-deprecated stable version provide useful adoption context, but they do not offset the maintenance and ownership concerns.
48%
Total Score
25
100
81
83
There were zero commits and zero active maintainers in the last 3 months. For a package less than a year old, that is a concrete sign that maintenance may have stalled.
The package and repository are owned by the same individual account, so there is no organization backing to compensate for a thin maintainer base.
The package made six releases over roughly 12 days, then had no recorded release for about 7 months and 3 weeks. That concentrated burst followed by a long pause weakens evidence of ongoing maintenance.
The repository name does not match the package name and its README does not mention the package. A name mismatch can be normal for a subpackage, but the missing README reference makes package ownership less transparent.
Composer build tooling is present, but the repository reports no security scanning tools. That limits automated review and is a modest transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nikic/php-parser Version ^5.7 | — | — |
laravel/framework Version ^11.0 | ^12.0 | — | — |
illuminate/support Version ^11.0 | ^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.