The Apache-2.0 license, organization-backed repository, and focused Composer dependency are reassuring. Its minimal metapackage structure is appropriate, but there is not yet evidence of sustained maintenance or security processes.
78%
Total Score
75
100
88
88
This package is newly published, with one release and no prior cadence, so sustained maintenance cannot yet be demonstrated. The lack of history is a caution rather than evidence of abandonment at this age.
There were no commits or active maintainers in the preceding three months, but the package is only hours old and the repository was pushed at publication. This limits evidence of ongoing maintenance without indicating abandonment yet.
The repository uses Composer, appropriate for this package, but no security-scanning tools were detected. For a tiny type-definition metapackage this is a modest hygiene gap, not a severe risk.
No repository security policy was found. This reduces transparency for reporting vulnerabilities, though the package's narrow metapackage role limits the significance of the gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/rector-rector-impl Version ~2.6.7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.