The package is focused, documented, and easy to trace to its matching source repository. Its license is clear, but there are no tests or security scanning, limiting confidence in long-term maintenance.
58%
Total Score
0
70
50
The repository recorded 0 commits and 0 active maintainers in the last 3 months, while its last push was about 10 months before collection. This is the strongest evidence of stalled maintenance.
All five releases arrived within roughly 11 days, and no later registry release is shown despite the package being about 11 months old. This suggests an early burst followed by limited ongoing maintenance.
Composer build tooling is present, but no security-scanning tool was detected. For a small PHP generator package this is a meaningful hygiene gap, though it does not by itself make the release unfit.
The linked repository has no security policy. This weakens vulnerability-reporting transparency, although the package is small and its source is available for inspection.
Version v0.1.5 is not marked as a prerelease, but the 0.x major version indicates an API that may still change substantially. That is a moderate adoption concern rather than a release-blocking problem.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
alex-no/field-lingo Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.