The dependency set is small and install-time scripts are absent. The repository is not archived and the release is stable, but prolonged inactivity limits confidence in future fixes.
55%
Total Score
50
100
83
83
The repository owner is an individual account rather than an organization, so there is no provided evidence of organizational backing. This offers less visible maintenance capacity than organization-backed projects, while the maintainer list and repository linkage provide some continuity.
The package has had no releases in the last 12 months, and its latest release was published on January 2, 2020. This is a substantial maintenance concern, although the package has 21 releases and is not deprecated.
There were no new or closed issues or pull requests in the last month, and no pull requests were open. Combined with the old repository push, this suggests little visible recent activity.
The repository has zero stars, forks, and watchers, providing no meaningful evidence of a broad support or review community. Popularity is supporting evidence, so this lowers confidence modestly rather than determining the verdict.
Composer is used as the build tool, but no security scanning tools are present in the repository. The missing scanning is a hygiene gap rather than evidence that the release is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/lexer Version 1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.