This release appears safe to depend on from a supply-chain health perspective: it is a stable major release from an established package with 7 releases in the last 12 months, an active non-archived organization-owned repository, recent commits from two maintainers, repository tests, a clear MIT license, and no registry deprecation. The main weaknesses are the absence of packaged tests and a changelog, lack of configured security-scanning tooling, and a workflow without explicit top-level token permissions; these are meaningful hygiene gaps but are partly offset by repository-level tests, GitHub Releases, a security policy, safe workflow analysis results, and ongoing maintenance. Popularity is modest, but that is supporting evidence rather than a decisive concern.
86%
Total Score
100
100
94
90
Composer build tooling is present, but no security-scanning tools were detected. The missing scanner is a hygiene gap, though the repository does provide a security policy and workflow-risk analysis found no dangerous patterns.
The only workflow lacks top-level token permissions, so its effective permissions are less explicit than preferred; it does not declare top-level write permissions, which limits the severity of this gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
rector/rector Version ^2.6 | — | — |
rector/extension-installer Version ~0.11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.