Healthy and suitable to use, with minor transparency caveats. It has regular releases, recent activity from three contributors, tests in the repository, and a clear license; the package artifact lacks a README and the repository has no security policy or scanning tooling.
84%
Total Score
80
100
94
90
Only one registry account has publish access, which is a modest publishing continuity concern. However, repository activity shows three active contributors, providing some compensation.
The top contributor made two-thirds of recent commits, creating some concentration risk, but two other contributors remained active and the repository is user-owned rather than organization-owned.
Composer build tooling is present, but no security scanning tools were detected. This is a transparency and assurance gap, though it is not severe given the repository's active development and test suite.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented. This is a minor transparency gap for a maintained package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
a9f/fractor Version ^1.0 | — | — |
a9f/fractor-xml Version ^1.0 | — | — |
a9f/fractor-yaml Version ^1.0 | — | — |
a9f/fractor-fluid Version ^1.0 | — | — |
a9f/fractor-xliff Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.