A single contributor and no documented security process leave limited resilience if maintenance stops. The package is small, tested, licensed, and has a clear README with no install-time scripts or declared deprecation.
80%
Total Score
50
100
89
75
All recent commits came from one contributor, giving the project a complete short-term single-maintainer concentration. The user-owned repository offers no organizational backing shown by the provided evidence.
There was one commit by one active maintainer in the last three months. That confirms recent activity but indicates limited maintenance capacity.
The repository has zero stars and forks and one watcher, indicating little public adoption. Popularity is supporting evidence rather than a health verdict, so this is only a minor concern.
Composer build tooling is present, but no security-scanning tool was detected. For a small library this is a modest transparency and maintenance gap, not evidence of unsafe code.
No security policy is present, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
alcamo/exception Version ^0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.