Healthy and suitable to depend on. It has regular releases, recent repository activity, tests and a changelog in the source project, with matching package identity and security tooling; maintenance is concentrated in two contributors and no security policy is published.
86%
Total Score
75
100
80
The registry namespace and repository owner match, but the project is owned by an individual rather than an organization, so there is less visible organizational redundancy.
Two contributors were active, but one made 41 of 45 recent commits, so continuity depends heavily on the primary maintainer.
The repository has no published security policy, leaving vulnerability-reporting expectations unclear despite the presence of security scanning tools.
Two workflows declare read-only permissions and none declare top-level write access; one CI workflow lacks top-level permissions, which is a small transparency gap rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nikic/php-parser Version ^4.18 || ^5 | — | — |
voku/simple-cache Version ~6.0 | — | — |
phpstan/phpdoc-parser Version ~2.0 | — | — |
fidry/cpu-core-counter Version ^1.3 | — | — |
phpdocumentor/type-resolver Version ~1.7.2 || ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.