Healthy and suitable to depend on. It has a long release history, a current stable release, active recent development, strong repository backing, and documented release notes; the main caveat is that recent commits are concentrated in one contributor and workflow permissions are not explicitly restricted.
92%
Total Score
88
100
94
90
One contributor made 16 of 17 recent commits, creating a real concentration risk; however, a second contributor remained active, so this is a caution rather than a severe abandonment signal.
The project uses Make and Composer build tooling, but no security scanning tools were detected. The missing scanning is a transparency gap, partially offset by the repository's active testing and maintenance.
Neither workflow declares top-level token permissions, so the repository does not visibly enforce least-privilege defaults; no workflow requests top-level write access, limiting the concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpoption/phpoption Version ^1.10 | — | — |
symfony/polyfill-ctype Version ^1.26 | — | — |
symfony/polyfill-php80 Version ^1.26 | — | — |
symfony/polyfill-mbstring Version ^1.26 | — | — |
graham-campbell/result-type Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.