Clear documentation, repository tests, and release notes make adoption practical. Releases are infrequent and all recent work comes from one maintainer, while security process and workflow permissions need stronger safeguards. The MIT license and stable major version are reassuring.
65%
Total Score
67
100
88
50
Composer post-install and post-update scripts run during dependency operations. This adds execution during installation and updates, although the signal does not show that the scripts are harmful.
The repository is owned by an individual rather than an organization, so the single-maintainer concentration is not offset by visible organizational backing.
The package has only 3 releases across 948 days, with 1 release in the last 12 months and a median interval of about 474 days. The recent release and active repository work partly offset the slow cadence, but maintenance continuity is still a concern.
All 11 recent commits came from one contributor, giving the project a single-person maintenance dependency and increasing abandonment or handoff risk.
The repository uses Make and Composer build tooling, but no security-scanning tools were detected. That is a transparency and review gap rather than evidence of a defect.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nikic/php-parser Version ^5.6.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.