This release is usable but carries meaningful maturity and maintenance uncertainty. It is licensed under MIT, has a matching repository with tests, changelog, GitHub Releases, Composer tooling, Dependabot, and no detected dangerous workflow patterns. However, it is brand new with only one release, version 0.2.0, no commits or active maintainers in the past 3 months, no repository stars or forks, no security policy, and several workflows with broad write permissions or no top-level permissions. Install and update lifecycle scripts also increase operational complexity. The evidence supports caution rather than a conclusion that the package is unfit, but adoption should be accompanied by monitoring and review of the repository's future activity.
58%
Total Score
67
100
83
70
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nikic/php-parser Version ^5.0 | — | — |
illuminate/process Version ^10.20|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.