The package is small, focused, documented, and tested, with only three runtime dependencies. Its main limitation is that ongoing care rests with one active contributor, while the repository has no security policy or scanning tooling.
68%
Total Score
50
100
89
83
The repository is owned by an individual user rather than an organization, so there is no visible organizational maintenance handoff beyond the single-contributor activity shown.
One contributor made all recent commits, so maintenance and release continuity depend on a single person.
One commit in the last three months shows some ongoing activity, but the low volume provides only limited evidence of sustained development.
The repository has zero stars and forks and one watcher. Popularity is supporting evidence rather than a verdict, but these counts provide little independent adoption signal.
Composer build tooling is present, but no security-scanning tools were detected, leaving security-review practices less transparent.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
alcamo/xml Version ^0.1 | — | — |
alcamo/collection Version ^0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.