The artifact includes tests, an Apache-2.0 license, and no install-time scripts. Its organization-backed repository is new, so there is not yet enough release or contributor history to establish long-term maintenance.
64%
Total Score
75
100
88
83
This package has only one release and is 0 days old, so its release discipline and long-term maintenance cannot yet be demonstrated.
The repository has 0 commits and 0 active maintainers in the last 3 months. Because it is 0 days old, this mainly shows that sustained maintenance has not yet been established rather than proving abandonment.
Composer build tooling is present, but no security scanning tool was detected. This is a modest transparency and hygiene gap, not a severe dependency risk on its own.
The repository has no security policy. That weakens vulnerability-reporting transparency, although the package's small, newly created repository limits how strongly this should affect the score.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
rector/rector Version ^2.0 | — | — |
tyhpdef/nikic-php-parser Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.