The small artifact has clear usage guidance and release notes, while organization backing provides some continuity. Its single runtime dependency is straightforward, but the repository has no tests or security scanning and attracts little community attention.
58%
Total Score
70
50
The package has had three releases, all by May 31, 2021, with no release in more than five years. That long period without registry updates is a meaningful abandonment concern.
The linked repository has only 1 star, 0 forks, and 1 watcher, providing little evidence of broad adoption or community support. Low popularity is supporting caution rather than proof of poor quality.
Composer is used for the build, but no security-scanning tooling is reported. For a compiler-like package, that is a modest transparency and maintenance gap, not a severe risk by itself.
The repository has no security policy. This weakens vulnerability-reporting transparency, although the package is not deprecated or archived and the absence alone does not indicate unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nikic/php-parser Version ^4.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.