Frequent releases and current commits show active maintenance. Tests, a clear README, and licensing support adoption, but the project relies on one contributor and has no security policy or scanning.
70%
Total Score
75
81
75
All 11 recent commits came from one contributor, leaving maintenance highly dependent on a single person with no demonstrated handoff capacity.
The repository has zero stars, forks, and watchers; for a young, specialized package this is weak supporting evidence rather than a decisive health problem.
Composer build tooling is present, but no security-scanning tools were detected, leaving security-maintenance practices less visible.
The repository has no security policy, so there is no documented process for reporting and handling vulnerabilities.
Version 0.1.15 is not a prerelease, but the package remains before 1.0, so compatibility guarantees are less mature than for a stable-major release.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
alcamo/uri Version ^0.2 | — | — |
alcamo/xml Version ^0.1 | — | — |
alcamo/time Version ^0.2 | — | — |
alcamo/collection Version ^0.2 | — | — |
alcamo/binary-data Version ^0.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.