This is a usable but very new package with reasonable transparency: it has an MIT license, a substantial README, a matching repository with source tests, Composer-based build tooling, and safe read-only workflow permissions. However, the release history is only one day old with a single release, and repository activity consists of just one commit from one contributor, so maintenance maturity and abandonment risk are not yet established. The absence of a security policy and security-scanning tooling are additional hygiene gaps, though the workflows show no detected dangerous patterns. Dependence is reasonable with caution, especially if the package is not yet proven in production.
62%
Total Score
50
100
88
90
Only one registry account has publish access. This is a limited publishing base, and the available project backing is a user-owned repository rather than an organization that could clearly provide handoff capacity.
The repository is owned by the user account zero-to-prod rather than an organization, so there is no provided evidence of institutional maintenance capacity beyond the current contributor.
The package is effectively brand new: it has one release and is 0 days old, so there is no demonstrated release consistency or long-term maintenance record.
All recent commits come from one contributor, with a 100% top-contributor share and no demonstrated contributor redundancy, increasing continuity risk.
Only one commit by one active maintainer is recorded over the last 3 months. Recent activity exists, but the volume is too small to demonstrate sustained maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
rector/rector Version ^2.5 | — | — |
phpstan/phpstan Version ^2.2 | — | — |
nikic/php-parser Version ^5.8 | — | — |
illuminate/support Version ^13.0 | — | — |
symplify/rule-doc-generator-contracts Version ^11.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.