The repository is organized, licensed, tested, and backed by an organization with a security policy. Its small audience and single-maintainer publishing model provide limited evidence of resilience if development remains paused.
61%
Total Score
63
100
81
100
One registry publishing account is a limited publishing safeguard, but the organization-backed repository provides context that this is not necessarily a one-person project.
The project has 11 releases over more than five years, but it has made no release in the last 12 months; this weakens evidence of current maintenance.
The repository had zero commits and zero active maintainers in the last three months, indicating a current maintenance pause despite the later recorded push date.
There are no open issues or pull requests, and no recent issue or pull-request activity; this is neutral for a small project but provides little evidence of active support.
Composer is used for builds, but no security scanning tools were detected, leaving a modest repository hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
aphiria/io Version 1.x-dev | — | — |
aphiria/reflection Version 1.x-dev | — | — |
aphiria/collections Version 1.x-dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.