The repository includes tests, release notes, and active recent pull requests. MIT licensing and pinned workflow actions help, while broad workflow write permissions and install scripts warrant care.
65%
Total Score
63
100
88
63
post-install-cmd and post-update-cmd scripts run during dependency operations, adding supply-chain exposure even though this signal alone does not show harmful behavior.
The repository is owned by an individual rather than an organization, so the single-maintainer and concentrated-contributor risks are not offset by visible organizational backing.
The package is only 44 days old and has one release, so its maintenance track record is not yet established.
One contributor made all two recent commits, leaving maintenance dependent on a single active person.
There were two commits in the last 3 months, so activity is present but still too sparse to demonstrate a mature maintenance cadence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
rector/rector Version ^2.6.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.