The repository matches the package and includes a license, tests, and Composer build metadata. Its one-release history, no recent commits, tiny audience, and misleading bundled README make long-term maintenance and package transparency uncertain.
38%
Total Score
0
50
64
67
This package has had only one release, published nearly two years ago, with no releases in the last 12 months. That is strong evidence of an immature or inactive project.
There were zero commits and zero active maintainers in the last three months. Combined with the single-release history, this materially raises abandonment risk.
The package declares three runtime dependencies and six development dependencies. This is not unusually broad for the available evidence, though the runtime dependency on vimeo/psalm is atypical and increases the dependency surface.
The package contains its own source files, but the artifact also bundles a very large vendor tree and the visible README belongs to amphp/parser. That makes the published contents harder to audit and suggests packaging hygiene problems.
The artifact has a README, tests, and a changelog, and the repository also has tests and a changelog. However, the included README describes amphp/parser rather than this package, which weakens consumer-facing transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
vimeo/psalm Version ^5.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.