Usable with caveats: Packagist marks this package as abandoned, even though the repository is active and the release cadence remains strong. Verify the replacement situation before adopting it, and prefer a maintained successor if one is available.
56%
Total Score
83
100
89
80
Packagist marks the package as abandoned at package scope and names the same package as its replacement, creating a significant publishing and continuity concern despite the absence of a clear replacement.
The registry namespace is rector while the repository is owned by the driftingly user account, so the package does not show organization-owned repository backing; this makes the abandonment flag more consequential.
The repository has no security policy, leaving reporting and response expectations undocumented; active maintenance and Dependabot provide some compensating hygiene but do not replace a policy.
All three workflows omit top-level token permissions declarations. No workflow declares top-level write access, but explicit least-privilege configuration is still missing.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
rector/rector Version ^2.6.4 | — | — |
webmozart/assert Version ^1.11 || ^2.0 | — | — |
symplify/rule-doc-generator-contracts Version ^11.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.