roave/better-reflection 6.73.0 presents a strong overall dependency-health profile: it is a mature package with more than 10 years of history, 127 releases, 11 releases in the last 12 months, stable versioning, a non-deprecated registry status, an organization-backed repository, and a current repository push. The repository contains tests, extensive source and documentation, Composer build tooling, and Psalm security scanning, while the artifact has an MIT license and no install-time lifecycle scripts. The main concern is that repository commit activity shows zero commits and zero active maintainers over the last 3 months, despite recent releases and merged pull requests, which creates some uncertainty about ongoing development continuity. Missing security-policy metadata and workflow-level token permissions are additional hygiene gaps, but there is no observed dangerous workflow pattern.
82%
Total Score
88
100
100
80
The repository reports zero commits and zero active maintainers over the last 3 months, a meaningful continuity concern; recent releases, a current push, and merged pull requests partly offset but do not eliminate this uncertainty.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations; this is a hygiene gap rather than evidence of unsafe code.
Neither workflow declares top-level token permissions, leaving least-privilege intent less explicit; no workflow has declared top-level write access, so the concern is limited to configuration hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nikic/php-parser Version ^5.8.0 | — | — |
jetbrains/phpstorm-stubs Version 2026.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.