The package is straightforward to evaluate and integrate, with tests in the repository and matching MIT licensing. Its small maintenance base and lack of a security policy leave more continuity risk than a mature project.
68%
Total Score
50
88
83
The repository is owned by an individual account rather than an organization, so the single-contributor concentration is not visibly offset by broader organizational backing.
All three recent commits came from one contributor, so maintenance continuity depends heavily on a single active developer.
Three commits in the last 3 months show some current activity, but the volume is modest for a package with ongoing releases.
The repository has no stars and one fork, indicating limited external adoption and review; popularity is supporting evidence, so this lowers confidence more than it determines the verdict.
Composer is used for builds, but no security-scanning tool was detected; this is a hygiene gap without evidence of a security failure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
a9f/fractor Version ^1.1 | — | — |
nette/utils Version ^4.0 | — | — |
webmozart/assert Version ^1.11 || ^2.0 | — | — |
a9f/fractor-extension-installer Version ^1.1 | — | — |
symplify/rule-doc-generator-contracts Version ^11.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.