Repository tests and regular releases add useful reassurance. The project still relies on one active contributor and has no security policy or scanning, so continuity and transparency are weaker.
72%
Total Score
67
89
83
The repository is owned by an individual user rather than an organization, so there is no visible organizational handoff capacity to offset the concentrated contributor activity.
All 3 recent commits came from one contributor, leaving no demonstrated recent contributor redundancy. This increases continuity risk if that maintainer becomes unavailable.
The repository has 0 stars and 1 fork. Popularity is only supporting evidence, but these counts provide little external evidence of broad review or adoption.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest transparency and assurance gap rather than evidence of unsafe code.
The repository has no security policy. For a package that processes configuration files, this makes vulnerability reporting and disclosure expectations less clear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
a9f/fractor Version ^1.1 | — | — |
nette/utils Version ^4.0 | — | — |
webmozart/assert Version ^1.11 || ^2.0 | — | — |
tivie/htaccess-parser Version ^0.4.0 | — | — |
a9f/fractor-extension-installer Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.