Clear documentation, tests, and licensing support a straightforward integration. Install-time scripts and unpinned workflow actions add operational risk, so pin the version and review upgrades carefully.
58%
Total Score
50
75
50
post-install-cmd and post-update-cmd scripts run during Composer operations to download or check the shared library, increasing installation-time execution and supply-chain exposure.
The package and repository are owned by the same individual account, providing alignment but not organizational maintenance redundancy.
The package is 317 days old with only 3 releases, released about every 75 days on average; this shows limited production history and cadence.
One contributor made all 2 commits in the last 3 months, leaving maintenance dependent on a single active person.
Only 2 commits were recorded in the last 3 months, indicating light recent maintenance despite the repository remaining active.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
satur.io/duckdb Version ^2.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.