Tolerant PHP-to-AST parser designed for IDE usage scenarios
68%
Total Score
caution
Usable with caveats: releases are concentrated, but current repository activity is absent and workflow pinning is incomplete.
The package is about 337 days old and has 27 releases, all within the last 12 months, with a median interval of 0 days. This shows active publishing but an unusually concentrated cadence, so it is mildly cautionary rather than proof of instability.
The repository recorded zero commits and zero active maintainers in the last 3 months, despite the latest push being associated with the assessed release. This weakens evidence of ongoing maintenance.
Composer is used for builds, but no security-scanning tools were detected. The missing scanning is a hygiene gap, not a standalone dependency blocker.
Version v0.2.0 is not a stable major release, although it is not marked as a prerelease and recent releases are not prereleases. The pre-1.0 status limits maturity confidence.
The sole workflow was fully analyzed with no audit findings or untrusted checkout and script-injection patterns. Its one action use is unpinned, which is a modest reproducibility and supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.