The package is a small, clearly licensed Composer metapackage with an exact matching organization-owned repository. Its dependency is explicit, and no install scripts or workflow findings add operational risk.
70%
Total Score
75
100
88
88
The package was published today and has only one release, so its maintenance record and release continuity are not yet established; this is an early-stage concern rather than evidence of abandonment.
There were no commits and no active maintainers in the last three months, but the repository and package were created today, so this is best treated as unproven continuity rather than collapsed maintenance.
The repository uses Composer, which fits the package ecosystem, but no security scanning tool was detected; for this tiny metapackage that is a modest transparency gap.
The repository has no security policy. This limits documented vulnerability-reporting guidance, though the package's small metapackage scope reduces the practical impact.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/phpstan-phpdoc-parser-impl Version ~2.3.5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.