The README and release notes make the upgrade rules clear, and the organization-backed repository remains intact. No tests or security scanning reduce confidence, while the lack of recent commits suggests maintenance may have paused.
65%
Total Score
75
100
81
75
The package has six releases since April 2022, but none in the last 12 months; the latest release was over a year ago. This indicates a potentially paused maintenance cycle for a tool that may be intentionally stable.
There were no commits and no active maintainers in the last three months. Although the package may be stable, this materially raises the risk that compatibility fixes will not arrive promptly.
The repository has zero stars and one fork, indicating limited external adoption and review. Popularity is supporting evidence rather than a verdict, so this is a modest concern only.
Composer is used as the build tool, but no security scanning tools were detected. The missing scanning is a hygiene weakness, not evidence that the package is unsafe.
The repository has no security policy. For a small upgrade-rules package this limits disclosure transparency but does not by itself indicate abandonment or severe dependency risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
rector/rector Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.