The package includes a README, changelog, tests in its repository, and matching MIT licensing, with no install-time scripts. Its small footprint and absent security scanning leave limited extra assurance, despite organization backing and a stable dependency set.
48%
Total Score
50
100
71
75
The last release was over 6 years ago, with no releases in the past 12 months. That is strong evidence of an inactive release stream for a dependency consumers may need maintained.
The repository recorded 0 commits and 0 active maintainers in the past 3 months, consistent with the long release gap and indicating current maintenance capacity is absent.
The repository has 0 stars, 0 watchers, and 2 forks. Popularity is supporting evidence rather than a verdict, but these counters provide little evidence of a broad active user or maintainer community.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a hygiene gap that adds limited assurance risk.
The repository has no security policy. This reduces transparency about vulnerability reporting and handling, though it is less consequential than the lack of recent maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/lexer Version 1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.